Commit Graph

301 Commits

Author SHA1 Message Date
Roberto Rodriguez 158daca821 Create sysmonv11.0.xml 2020-04-28 16:44:59 -04:00
Roberto Rodriguez 00b2dc38ee Merge pull request #75 from hunters-forge/aws-datadictionary
Datadictionary for AWS Cloud Data sources
2020-04-14 13:16:48 -04:00
ashwin-patil c675cf480c adding ELB and route 53 datasources 2020-04-14 05:15:08 -07:00
ashwin-patil b3ded2e481 markdown formatting and yaml additions 2020-04-14 03:18:23 -07:00
ashwin-patil 00b1352b4d updated readme to add SFF 2020-04-06 03:28:13 -07:00
ashwin-patil 9352c47fbf added s3 and security hub formats 2020-03-31 02:02:07 -07:00
ashwin-patil 25882d3306 VPC Flow log schema 2020-03-24 03:42:22 -07:00
ashwin-patil 4c815ef577 Folder structure and cloudtrail schema 2020-03-24 02:22:51 -07:00
Roberto Rodriguez 59f371f6c2 Merge pull request #73 from hunters-forge/fix_etw_security
fixed description of etw windows security auditing events
2020-02-24 17:45:55 -05:00
Ricardo Dias d89e9e50bd fixed description of etw windows security auditing events 2020-02-22 11:26:28 +00:00
Roberto Rodriguez 9087983162 Update README.md 2020-02-21 12:05:52 -05:00
Roberto Rodriguez d3dc043ab9 Merge pull request #72 from hxnoyd/yaml_poc
OSSEM conversion to YAML
2020-02-21 09:57:27 -05:00
Ricardo Dias b5cbfcf15d fixed paths 2020-02-20 22:06:43 +00:00
Ricardo Dias 778a200f1c fixed paths 2020-02-20 22:02:25 +00:00
Ricardo Dias df8d0033be added guidelines 2020-02-20 21:57:39 +00:00
Ricardo Dias c3fe1af66e updated windows security auditing readme 2020-02-20 21:48:28 +00:00
Ricardo Dias ffff4aea57 improved readme files readability 2020-02-20 21:34:08 +00:00
Ricardo Dias 88d2626ac6 markdown readme entries are now sorted 2020-02-20 17:06:22 +00:00
Ricardo Dias 10daf66ccf removed whitespace from etw source folder, updated markdown 2020-02-20 16:54:17 +00:00
Ricardo Dias 556f6bbcfc removed windows securit events, as they are now undert etw-providers 2020-02-18 16:53:24 +00:00
Ricardo Dias 49e5239df2 powershell dictionary cleanup 2020-02-18 16:41:25 +00:00
Ricardo Dias 40ac2f32e1 markdown update 2020-02-18 16:18:41 +00:00
Ricardo Dias 4f25ee35b1 merged existing windows security events into Microsoft-Windows-Security-Auditing 2020-02-18 16:07:13 +00:00
Ricardo Dias 84ded3ecea event code in etw are now strings. markdown updated. 2020-02-17 19:25:52 +00:00
Ricardo Dias 4291a8165b updated Microsoft-Windows-WMI-Activity event 2020-02-16 19:31:04 +00:00
Ricardo Dias 1b0994bd57 fixed osquery typo 2020-02-09 21:16:03 +00:00
Ricardo Dias 2d22b25cdc added osquery 4.1.2 schema 2020-02-09 21:05:28 +00:00
Ricardo Dias c314d0b6db applied latest schema branch changes 2020-02-09 15:53:43 +00:00
Ricardo Dias 16803f4a15 applied latest schema branch changes 2020-02-09 15:15:17 +00:00
Ricardo Dias 7f3adb1508 resources renamed to references 2020-02-08 23:11:32 +00:00
Ricardo Dias 16098ae690 resources renamed to references 2020-02-08 23:07:06 +00:00
Ricardo Dias 42305e65e3 minor readme fix 2020-02-08 13:23:00 +00:00
Ricardo Dias db7ee2ca8b sysmon yml cleanup and minor readme template fixes 2020-02-08 13:02:21 +00:00
Ricardo Dias b707554821 fixed dd markdown template 2020-02-08 09:51:34 +00:00
Ricardo Dias 2148e2a686 yaml proof of concept 2020-02-07 18:10:32 +00:00
Nate Guagenti 0cbc54b51e Schema & Data Dictionary Additions & Cleanup (#70)
* define flow to point to correct schemas

* make values code style

* add definitions of ambiguity for url/http

* stage TLS

* just domain

* correct domain terminology to match current OSSEM as well as HELK



* define community id to match HELK.  layer7 and layer 3 implementation

* add PR from https://github.com/hunters-forge/OSSEM/pull/54

* update destination further, especially with dst_host_name and hostname vs fqdn vs domain

* documentation/information to delineate domain vs fqdn vs hostname

* update to support dst_host_name

* make implementation intro more clear

* small url schema verbiage updates

* still staging, but cleanup verbiage for now

* toward dns

* host_name schema for searching all

* towards event

* create etl schema

* staging host name (domain) enrichment


* correct flow from master branch

* not necessary to revert lowercase


* update url_host_name


* markdown cleanup

* match guid names

* add link names/paths that are in data dictionaries

 filename

* correct AccessReason

* add application generated auditing

* add 4907

* add event XML

* add event XML



* add 4670

* missing AccessReason

* fix SD naming

* match CIM for src and dst ip addresses

* add 4696 xml

* process cleanups, corrections, and HELK<>OSSEM

* add 4797

* add sysmon 255

* update match HELK

* - [x] group schema (name, domain, sid, etc)
- [x] Audit Security Group Management
    - [x] Security:4727
    - [x] Security:4728
    - [x] Security:4729
    - [x] Security:4730
    - [x] Security:4731
    - [x] Security:4732
    - [x] Security:4733
    - [x] Security:4734
    - [x] Security:4735
    - [x] Security:4737
    - [x] Security:4754
    - [x] Security:4755
    - [x] Security:4756
    - [x] Security:4757
    - [x] Security:4758
    - [x] Security:4764
    - [x] Security:4799

* update .gitignore

* begin adding zeek data dictionaries

* begin adding zeek data dictionaries

* begin adding zeek data dictionaries

* begin adding zeek data dictionaries

* JSpieldenner Moving Forward

* JS102919

* JS102519

* match SidHistory for group to be group_sid_history

* Audit Distribution Group Management

* begin adding zeek data dictionaries



* add VLANs

* add event duration for length of time/event

* add network history/connection states

* complete zeek conn log

* set network protocols

* complete zeek conn log

* zeek event_uid and network proto

* zeek progress on DHCP

* event uid

* duplicate line

* add 4670 from main and fix typo and field to what helk has

 for logon_transmitted_services

* use current reporter logon id field, pending confirmation until then

* field type is string NOT ip

* add 4649

* correct field names. update description and correct ordering of reference

* update description and correct ordering of reference

* correct minimum OS, fix and add relative paths

* DnsName to dst_host_name, fix multiple typo's and update description and correct ordering of reference

* correct session id field name. also typo

* conform with similar field types.. like UPN to user_identity. also update description

* add 4825, even though not on microsoft's website :)

* field name typos and update field descriptions a bit

* finish Account Logon/Other Logon/Logoff

* fix typo, update description and match to HELK https://github.com/Cyb3rWard0g/HELK/issues/314

* fill out the rest for object/registry

* update all Zeek categories' descriptions/README's.

* schema

* zeek log examples

* finish dns schema

* add dhcp ip

* finish dns schema

* finish schema

* add user_password

* update etl schema

* forward http

* add src/dst file info



* add ja3/ja3s

* forward ssl/tls

* update example

 in "task"

* event example json cleanup

* TransactionId should be transaction_guid

* readme ordering

* missing Service standardized field name

* correct description

* correct object_access_mask value type

* correct object_access_list value type to string

* correct descriptions

* add event id 4659

* add event id 4665, 4666, 4667, 4668

* add event id 5051

* fix relative path links

* directory service changes HELK <> OSSEM

* add network_direction

* HELK <> OSSEM

* scheduled tasks HELK <> OSSEM

* network_direction

* add etl_versioning

* because potential of 3 process ID's, note field just in case

* HELK <> OSSEM user_target_ is target_user_

* directory service object HELK <> OSSEM

* HELK <> OSSEM audit policy change

* 4777

* add 4774 and  4775

* HELK <> OSSEM dpapi

* clean, add error and status codes and network application name



* forward movement

* finish the start of HTTP schema



* hex as string, identify decimal separately

* add sha512 hash

* begin adding x509/certificate info for tls/signed things



* Combine Kerberos TGS and AS as one such a lot of overlap and makes for a better schema
2020-01-31 23:59:21 -05:00
Roberto Rodriguez 52aaec7bf2 Update ETWtsv2json.py
unused variable - oops ;)
2020-01-23 13:28:06 -05:00
Roberto Rodriguez 9f6c0f2989 ETWtsv2json docs 2020-01-23 12:49:04 -05:00
Ricardo Dias addbada963 Update object_relationships.md
Renamed 'win registry' data objects to 'registry'.
2020-01-22 16:49:23 +00:00
Roberto Rodriguez 9db3dfb122 Merge pull request #67 from hxnoyd/windows_security
new windows security data dictionaries
2019-12-10 14:57:59 -05:00
Ricardo Dias 00beca9559 new windows security data dictionaries 2019-12-08 17:54:07 +00:00
Roberto Rodriguez ce4384958e Merge pull request #64 from hxnoyd/cim_kerberos
added kerberos cim entities
2019-11-30 22:55:12 -05:00
Roberto Rodriguez ec204f2517 Merge pull request #65 from hxnoyd/ddm_kerberos
updated kerberos entity names
2019-11-30 22:47:52 -05:00
Roberto Rodriguez b2f8db9d01 Merge pull request #66 from hxnoyd/ddm_registry
updated registry entity names
2019-11-30 22:47:02 -05:00
Ricardo Dias ac6e46b072 updated registry entity names 2019-11-30 01:09:52 +00:00
Ricardo Dias 4cd4ff3085 updated kerberos entity names 2019-11-30 00:57:06 +00:00
Ricardo Dias c9a06d39d6 added kerberos cim entities 2019-11-30 00:49:36 +00:00
Roberto Rodriguez 42ecba4ed6 Merge pull request #63 from hxnoyd/new_data_dictionaries_2
Added multiple windows security events
2019-11-23 21:07:07 -05:00
Roberto Rodriguez 411f4b71dc Merge pull request #62 from hxnoyd/audit_directory
Added audit directory service changes events
2019-11-23 21:05:29 -05:00
Roberto Rodriguez a56b8b60ea Merge pull request #61 from hxnoyd/audit_registry
updated audit registry events
2019-11-23 21:04:15 -05:00