Files
OTRF-OSSEM-DM/relationships/process_executed_script.yml
Jose Rodriguez ed1cbddce4 General update on relationships
- updated numerical event_id to string.
- alignment with OSSEM-DD and readme description
2022-09-22 13:07:27 -04:00

57 lines
1.3 KiB
YAML

relationship_id: REL-2022-0066
name: Process executed Script
contributors:
- Jose Rodriguez @Cyb3rPandaH
- Roberto Rodriguez @Cyb3rWard0g
- Olaf Hartong @olafhartong
attack:
data_source: script
data_component: script execution
behavior:
source: process
relationship: executed
target: script
security_events:
- event_id: '4103'
name: Module logging.
platform: windows
channel: Microsoft-Windows-PowerShell/Operational
log_source: Microsoft-Windows-PowerShell
event_version:
- '1'
- event_id: '4104'
name: Script Block Logging.
platform: windows
channel: Microsoft-Windows-PowerShell/Operational
log_source: Microsoft-Windows-PowerShell
event_version:
- '1'
- event_id: DeviceEvents
name: DeviceEvents
platform: windows
log_source: Microsoft Defender for Endpoint
filter_in:
- ActionType: ScriptContent
event_version:
- '0'
- '1'
- event_id: DeviceEvents
name: DeviceEvents
platform: windows
log_source: Microsoft Defender for Endpoint
filter_in:
- ActionType: PowerShellCommand
event_version:
- '0'
- '1'
- event_id: DeviceEvents
name: DeviceEvents
platform: windows
log_source: Microsoft Defender for Endpoint
filter_in:
- ActionType: AmsiScriptDetection
event_version:
- '0'
- '1'
references: null