Updated TAs

This commit is contained in:
patel-bhavin
2025-06-07 06:57:43 +00:00
committed by github-actions[bot]
parent 1b81186d5c
commit f77751098e
23 changed files with 272 additions and 271 deletions
+4 -4
View File
@@ -71,9 +71,9 @@ apps:
- uid: 5709
title: Splunk Add-on for Sysmon
appid: Splunk_TA_microsoft_sysmon
version: 4.0.2
version: 4.0.3
description: description of app
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-sysmon_402.tgz
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-sysmon_403.tgz
- uid: 833
title: Splunk Add-on for Unix and Linux
appid: Splunk_TA_nix
@@ -185,9 +185,9 @@ apps:
- uid: 6207
title: Splunk Add-on for Microsoft Security
appid: Splunk_TA_MS_Security
version: 2.5.0
version: 2.5.1
description: description of app
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-microsoft-security_250.tgz
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-microsoft-security_251.tgz
- uid: 2734
title: URL Toolbox
appid: URL_TOOLBOX
@@ -16,7 +16,7 @@ sourcetype: ms365:defender:incident:alerts
supported_TA:
- name: Splunk Add-on for Microsoft Security
url: https://splunkbase.splunk.com/app/6207
version: 2.5.0
version: 2.5.1
fields:
- actorName
- alertId
+1 -1
View File
@@ -16,7 +16,7 @@ sourcetype: ms:defender:atp:alerts
supported_TA:
- name: Splunk Add-on for Microsoft Security
url: https://splunkbase.splunk.com/app/6207
version: 2.5.0
version: 2.5.1
fields:
- column
- accountName
+41 -40
View File
@@ -18,7 +18,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
url: https://splunkbase.splunk.com/app/5709
version: 4.0.2
version: 4.0.3
fields:
- _time
- Channel
@@ -118,26 +118,26 @@ fields:
- user_id
- vendor_product
output_fields:
- action
- dest
- original_file_name
- parent_process
- parent_process_exec
- parent_process_guid
- parent_process_id
- parent_process_name
- parent_process_path
- process
- process_exec
- process_guid
- process_hash
- process_id
- process_integrity_level
- process_name
- process_path
- user
- user_id
- vendor_product
- action
- dest
- original_file_name
- parent_process
- parent_process_exec
- parent_process_guid
- parent_process_id
- parent_process_name
- parent_process_path
- process
- process_exec
- process_guid
- process_hash
- process_id
- process_integrity_level
- process_name
- process_path
- user
- user_id
- vendor_product
field_mappings:
- data_model: cim
data_set: Endpoint.Processes
@@ -178,22 +178,23 @@ convert_to_log_source:
User: UserSid
ParentProcessId: ParentProcessId
ParentImage: ParentBaseFileName
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Sysmon' Guid='{5770385F-C22A-43E0-BF4C-06F5698FFBD9}'/><EventID>1</EventID><Version>5</Version><Level>4</Level><Task>1</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated
SystemTime='2020-10-08T11:03:46.617920300Z'/><EventRecordID>4522</EventRecordID><Correlation/><Execution
ProcessID='2912' ThreadID='3424'/><Channel>Microsoft-Windows-Sysmon/Operational</Channel><Computer>win-dc-6764986.attackrange.local</Computer><Security
UserID='S-1-5-18'/></System><EventData><Data Name='RuleName'>-</Data><Data Name='UtcTime'>2020-10-08
11:03:46.615</Data><Data Name='ProcessGuid'>{96128EA2-F212-5F7E-E400-000000007F01}</Data><Data
Name='ProcessId'>2296</Data><Data Name='Image'>C:\Windows\System32\cmd.exe</Data><Data
Name='FileVersion'>10.0.14393.0 (rs1_release.160715-1616)</Data><Data Name='Description'>Windows
Command Processor</Data><Data Name='Product'>Microsoft® Windows® Operating System</Data><Data
Name='Company'>Microsoft Corporation</Data><Data Name='OriginalFileName'>Cmd.Exe</Data><Data
Name='CommandLine'>"C:\Windows\system32\cmd.exe" /c "reg save HKLM\sam %%temp%%\sam
&amp; reg save HKLM\system %%temp%%\system &amp; reg save HKLM\security %%temp%%\security"
</Data><Data Name='CurrentDirectory'>C:\Users\ADMINI~1\AppData\Local\Temp\</Data><Data
Name='User'>ATTACKRANGE\Administrator</Data><Data Name='LogonGuid'>{96128EA2-F210-5F7E-ACD4-080000000000}</Data><Data
Name='LogonId'>0x8d4ac</Data><Data Name='TerminalSessionId'>0</Data><Data Name='IntegrityLevel'>High</Data><Data
Name='Hashes'>MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A</Data><Data
Name='ParentProcessGuid'>{96128EA2-F211-5F7E-DF00-000000007F01}</Data><Data Name='ParentProcessId'>4624</Data><Data
Name='ParentImage'>C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe</Data><Data
Name='ParentCommandLine'>"powershell.exe" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADAAMwAuADAAMAAyACIAIAAtAEMAbwBuAGYAaQByAG0AOgAkAGYAYQBsAHMAZQAgAC0AVABpAG0AZQBvAHUAdABTAGUAYwBvAG4AZABzACAAMwAwADAAIAAtAEUAeABlAGMAdQB0AGkAbwBuAEwAbwBnAFAAYQB0AGgAIABDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAYQB0AGMAXwBlAHgAZQBjAHUAdABpAG8AbgAuAGMAcwB2AA==</Data></EventData></Event>
example_log: "<Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider\
\ Name='Microsoft-Windows-Sysmon' Guid='{5770385F-C22A-43E0-BF4C-06F5698FFBD9}'/><EventID>1</EventID><Version>5</Version><Level>4</Level><Task>1</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated\
\ SystemTime='2020-10-08T11:03:46.617920300Z'/><EventRecordID>4522</EventRecordID><Correlation/><Execution\
\ ProcessID='2912' ThreadID='3424'/><Channel>Microsoft-Windows-Sysmon/Operational</Channel><Computer>win-dc-6764986.attackrange.local</Computer><Security\
\ UserID='S-1-5-18'/></System><EventData><Data Name='RuleName'>-</Data><Data Name='UtcTime'>2020-10-08\
\ 11:03:46.615</Data><Data Name='ProcessGuid'>{96128EA2-F212-5F7E-E400-000000007F01}</Data><Data\
\ Name='ProcessId'>2296</Data><Data Name='Image'>C:\\Windows\\System32\\cmd.exe</Data><Data\
\ Name='FileVersion'>10.0.14393.0 (rs1_release.160715-1616)</Data><Data Name='Description'>Windows\
\ Command Processor</Data><Data Name='Product'>Microsoft\xAE Windows\xAE Operating\
\ System</Data><Data Name='Company'>Microsoft Corporation</Data><Data Name='OriginalFileName'>Cmd.Exe</Data><Data\
\ Name='CommandLine'>\"C:\\Windows\\system32\\cmd.exe\" /c \"reg save HKLM\\sam\
\ %%temp%%\\sam &amp; reg save HKLM\\system %%temp%%\\system &amp; reg save HKLM\\\
security %%temp%%\\security\" </Data><Data Name='CurrentDirectory'>C:\\Users\\ADMINI~1\\\
AppData\\Local\\Temp\\</Data><Data Name='User'>ATTACKRANGE\\Administrator</Data><Data\
\ Name='LogonGuid'>{96128EA2-F210-5F7E-ACD4-080000000000}</Data><Data Name='LogonId'>0x8d4ac</Data><Data\
\ Name='TerminalSessionId'>0</Data><Data Name='IntegrityLevel'>High</Data><Data\
\ Name='Hashes'>MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A</Data><Data\
\ Name='ParentProcessGuid'>{96128EA2-F211-5F7E-DF00-000000007F01}</Data><Data Name='ParentProcessId'>4624</Data><Data\
\ Name='ParentImage'>C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe</Data><Data\
\ Name='ParentCommandLine'>\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADAAMwAuADAAMAAyACIAIAAtAEMAbwBuAGYAaQByAG0AOgAkAGYAYQBsAHMAZQAgAC0AVABpAG0AZQBvAHUAdABTAGUAYwBvAG4AZABzACAAMwAwADAAIAAtAEUAeABlAGMAdQB0AGkAbwBuAEwAbwBnAFAAYQB0AGgAIABDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAYQB0AGMAXwBlAHgAZQBjAHUAdABpAG8AbgAuAGMAcwB2AA==</Data></EventData></Event>"
+11 -11
View File
@@ -18,7 +18,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
url: https://splunkbase.splunk.com/app/5709
version: 4.0.2
version: 4.0.3
fields:
- _time
- CallTrace
@@ -101,16 +101,16 @@ fields:
output_fields:
- dest
- user_id
- parent_process_name
- parent_process_guid
- process_name
- process_guid
- process_id
- signature
- SourceImage
- TargetImage
- GrantedAccess
- CallTrace
- parent_process_name
- parent_process_guid
- process_name
- process_guid
- process_id
- signature
- SourceImage
- TargetImage
- GrantedAccess
- CallTrace
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Sysmon' Guid='{5770385F-C22A-43E0-BF4C-06F5698FFBD9}'/><EventID>10</EventID><Version>3</Version><Level>4</Level><Task>10</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated
SystemTime='2022-02-01T21:01:44.672666100Z'/><EventRecordID>150624412</EventRecordID><Correlation/><Execution
+9 -9
View File
@@ -19,7 +19,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
url: https://splunkbase.splunk.com/app/5709
version: 4.0.2
version: 4.0.3
fields:
- _time
- Channel
@@ -93,14 +93,14 @@ fields:
- user_id
- vendor_product
output_fields:
- action
- dest
- file_name
- file_path
- process_guid
- process_id
- user
- vendor_product
- action
- dest
- file_name
- file_path
- process_guid
- process_id
- user
- vendor_product
field_mappings:
- data_model: cim
data_set: Endpoint.Filesystem
+10 -10
View File
@@ -18,7 +18,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
url: https://splunkbase.splunk.com/app/5709
version: 4.0.2
version: 4.0.3
fields:
- _time
- Channel
@@ -95,15 +95,15 @@ fields:
- user_id
- vendor_product
output_fields:
- action
- dest
- process_guid
- process_id
- registry_hive
- registry_path
- registry_key_name
- status
- user
- action
- dest
- process_guid
- process_id
- registry_hive
- registry_path
- registry_key_name
- status
- user
- vendor_product
field_mappings:
- data_model: cim
+12 -12
View File
@@ -18,7 +18,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
url: https://splunkbase.splunk.com/app/5709
version: 4.0.2
version: 4.0.3
fields:
- _time
- Channel
@@ -102,17 +102,17 @@ fields:
- user_id
- vendor_product
output_fields:
- action
- dest
- process_guid
- process_id
- registry_hive
- registry_path
- registry_key_name
- registry_value_data
- registry_value_name
- status
- user
- action
- dest
- process_guid
- process_id
- registry_hive
- registry_path
- registry_key_name
- registry_value_data
- registry_value_name
- status
- user
- vendor_product
field_mappings:
- data_model: cim
+2 -2
View File
@@ -11,7 +11,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
url: https://splunkbase.splunk.com/app/5709
version: 4.0.2
version: 4.0.3
fields:
- _time
example_log: |-
example_log: ''
+14 -14
View File
@@ -19,7 +19,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
url: https://splunkbase.splunk.com/app/5709
version: 4.0.2
version: 4.0.3
fields:
- _time
- Channel
@@ -98,19 +98,19 @@ fields:
- user_id
- vendor_product
output_fields:
- dest
- dvc
- file_hash
- file_name
- file_path
- process_exec
- process_guid
- process_id
- process_name
- process_path
- signature
- signature_id
- user_id
- dest
- dvc
- file_hash
- file_name
- file_path
- process_exec
- process_guid
- process_id
- process_name
- process_path
- signature
- signature_id
- user_id
- vendor_product
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Sysmon' Guid='{5770385F-C22A-43E0-BF4C-06F5698FFBD9}'/><EventID>15</EventID><Version>2</Version><Level>4</Level><Task>15</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated
+12 -12
View File
@@ -14,7 +14,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
url: https://splunkbase.splunk.com/app/5709
version: 4.0.2
version: 4.0.3
fields:
- _time
- Channel
@@ -86,17 +86,17 @@ fields:
- user_id
- vendor_product
output_fields:
- dest
- dvc
- pipe_name
- process_exec
- process_guid
- process_id
- process_name
- process_path
- signature
- signature_id
- user_id
- dest
- dvc
- pipe_name
- process_exec
- process_guid
- process_id
- process_name
- process_path
- signature
- signature_id
- user_id
- vendor_product
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Sysmon' Guid='{5770385F-C22A-43E0-BF4C-06F5698FFBD9}'/><EventID>17</EventID><Version>1</Version><Level>4</Level><Task>17</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated
+12 -12
View File
@@ -18,7 +18,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
url: https://splunkbase.splunk.com/app/5709
version: 4.0.2
version: 4.0.3
fields:
- _time
- Channel
@@ -90,17 +90,17 @@ fields:
- user_id
- vendor_product
output_fields:
- dest
- dvc
- pipe_name
- process_exec
- process_guid
- process_id
- process_name
- process_path
- signature
- signature_id
- user_id
- dest
- dvc
- pipe_name
- process_exec
- process_guid
- process_id
- process_name
- process_path
- signature
- signature_id
- user_id
- vendor_product
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Sysmon' Guid='{5770385F-C22A-43E0-BF4C-06F5698FFBD9}'/><EventID>18</EventID><Version>1</Version><Level>4</Level><Task>18</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated
+12 -12
View File
@@ -17,7 +17,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
url: https://splunkbase.splunk.com/app/5709
version: 4.0.2
version: 4.0.3
fields:
- _time
- Channel
@@ -92,17 +92,17 @@ fields:
- user_name
- vendor_product
output_fields:
- dest
- dvc
- object
- object_category
- object_path
- signature
- signature_id
- src
- status
- user
- user_id
- dest
- dvc
- object
- object_category
- object_path
- signature
- signature_id
- src
- status
- user
- user_id
- vendor_product
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Sysmon' Guid='{5770385F-C22A-43E0-BF4C-06F5698FFBD9}'/><EventID>20</EventID><Version>3</Version><Level>4</Level><Task>20</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated
+13 -13
View File
@@ -18,7 +18,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
url: https://splunkbase.splunk.com/app/5709
version: 4.0.2
version: 4.0.3
fields:
- _time
- Channel
@@ -95,18 +95,18 @@ fields:
- user_name
- vendor_product
output_fields:
- dest
- dvc
- object
- object_attrs
- object_category
- object_path
- signature
- signature_id
- src
- status
- user
- user_id
- dest
- dvc
- object
- object_attrs
- object_category
- object_path
- signature
- signature_id
- src
- status
- user
- user_id
- vendor_product
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Sysmon' Guid='{5770385F-C22A-43E0-BF4C-06F5698FFBD9}'/><EventID>21</EventID><Version>3</Version><Level>4</Level><Task>21</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated
+7 -7
View File
@@ -19,7 +19,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
url: https://splunkbase.splunk.com/app/5709
version: 4.0.2
version: 4.0.3
field_mappings:
- data_model: cim
data_set: DNS
@@ -96,12 +96,12 @@ fields:
- user_id
- vendor_product
output_fields:
- answer
- answer_count
- query
- query_count
- reply_code_id
- src
- answer
- answer_count
- query
- query_count
- reply_code_id
- src
- vendor_product
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Sysmon' Guid='{5770385F-C22A-43E0-BF4C-06F5698FFBD9}'/><EventID>22</EventID><Version>5</Version><Level>4</Level><Task>22</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated
+17 -17
View File
@@ -19,7 +19,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
url: https://splunkbase.splunk.com/app/5709
version: 4.0.2
version: 4.0.3
fields:
- _time
- Archived
@@ -101,22 +101,22 @@ fields:
- user_id
- vendor_product
output_fields:
- action
- dest
- dvc
- file_path
- file_hash
- file_name
- file_modify_time
- process_exec
- process_guid
- process_id
- process_name
- process_path
- signature
- signature_id
- user
- user_id
- action
- dest
- dvc
- file_path
- file_hash
- file_name
- file_modify_time
- process_exec
- process_guid
- process_id
- process_name
- process_path
- signature
- signature_id
- user
- user_id
- vendor_product
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Sysmon' Guid='{5770385F-C22A-43E0-BF4C-06F5698FFBD9}'/><EventID>23</EventID><Version>5</Version><Level>4</Level><Task>23</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated
+18 -18
View File
@@ -11,25 +11,25 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
url: https://splunkbase.splunk.com/app/5709
version: 4.0.2
version: 4.0.3
fields:
- _time
output_fields:
- action
- dest
- dvc
- file_path
- file_hash
- file_name
- file_modify_time
- process_exec
- process_guid
- process_id
- process_name
- process_path
- signature
- signature_id
- user
- user_id
- action
- dest
- dvc
- file_path
- file_hash
- file_name
- file_modify_time
- process_exec
- process_guid
- process_id
- process_name
- process_path
- signature
- signature_id
- user
- user_id
- vendor_product
example_log: |-
example_log: ''
+15 -15
View File
@@ -19,7 +19,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
url: https://splunkbase.splunk.com/app/5709
version: 4.0.2
version: 4.0.3
fields:
- _time
- Channel
@@ -115,20 +115,20 @@ fields:
- user_id
- vendor_product
output_fields:
- action
- app
- dest
- dest_ip
- dest_port
- direction
- dvc
- protocol
- protocol_version
- src
- src_ip
- src_port
- transport
- user
- action
- app
- dest
- dest_ip
- dest_port
- direction
- dvc
- protocol
- protocol_version
- src
- src_ip
- src_port
- transport
- user
- vendor_product
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Sysmon' Guid='{5770385F-C22A-43E0-BF4C-06F5698FFBD9}'/><EventID>3</EventID><Version>5</Version><Level>4</Level><Task>3</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated
+10 -10
View File
@@ -18,7 +18,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
url: https://splunkbase.splunk.com/app/5709
version: 4.0.2
version: 4.0.3
fields:
- _time
- Channel
@@ -87,15 +87,15 @@ fields:
- user_id
- vendor_product
output_fields:
- dest
- process
- process_exec
- process_guid
- process_id
- process_name
- process_path
- signature
- signature_id
- dest
- process
- process_exec
- process_guid
- process_id
- process_name
- process_path
- signature
- signature_id
- user_id
- vendor_product
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
+8 -8
View File
@@ -18,7 +18,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
url: https://splunkbase.splunk.com/app/5709
version: 4.0.2
version: 4.0.3
fields:
- _time
- Channel
@@ -89,13 +89,13 @@ fields:
- user_id
- vendor_product
output_fields:
- dest
- dvc
- process_hash
- process_path
- signature
- signature_id
- user_id
- dest
- dvc
- process_hash
- process_path
- signature
- signature_id
- user_id
- vendor_product
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Sysmon' Guid='{5770385F-C22A-43E0-BF4C-06F5698FFBD9}'/><EventID>6</EventID><Version>4</Version><Level>4</Level><Task>6</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated
+17 -17
View File
@@ -19,7 +19,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
url: https://splunkbase.splunk.com/app/5709
version: 4.0.2
version: 4.0.3
fields:
- _time
- Channel
@@ -109,22 +109,22 @@ fields:
- user_id
- vendor_product
output_fields:
- Image
- ImageLoaded
- dest
- loaded_file
- loaded_file_path
- process_exec
- process_guid
- process_hash
- process_id
- process_name
- process_path
- service_dll_signature_exists
- service_dll_signature_verified
- signature
- signature_id
- user_id
- Image
- ImageLoaded
- dest
- loaded_file
- loaded_file_path
- process_exec
- process_guid
- process_hash
- process_id
- process_name
- process_path
- service_dll_signature_exists
- service_dll_signature_verified
- signature
- signature_id
- user_id
- vendor_product
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Sysmon' Guid='{5770385F-C22A-43E0-BF4C-06F5698FFBD9}'/><EventID>7</EventID><Version>3</Version><Level>4</Level><Task>7</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated
+15 -15
View File
@@ -18,7 +18,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
url: https://splunkbase.splunk.com/app/5709
version: 4.0.2
version: 4.0.3
fields:
- _time
- Channel
@@ -101,20 +101,20 @@ fields:
- user_id
- vendor_product
output_fields:
- dest
- parent_process_exec
- parent_process_guid
- parent_process_id
- parent_process_name
- parent_process_path
- process_exec
- process_guid
- process_id
- process_name
- process_path
- signature
- signature_id
- user_id
- dest
- parent_process_exec
- parent_process_guid
- parent_process_id
- parent_process_name
- parent_process_path
- process_exec
- process_guid
- process_id
- process_name
- process_path
- signature
- signature_id
- user_id
- vendor_product
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Sysmon' Guid='{5770385F-C22A-43E0-BF4C-06F5698FFBD9}'/><EventID>8</EventID><Version>2</Version><Level>4</Level><Task>8</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated
+11 -11
View File
@@ -19,7 +19,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config
supported_TA:
- name: Splunk Add-on for Sysmon
url: https://splunkbase.splunk.com/app/5709
version: 4.0.2
version: 4.0.3
fields:
- _time
- Channel
@@ -88,16 +88,16 @@ fields:
- user_id
- vendor_product
output_fields:
- dest
- dvc
- process_exec
- process_guid
- process_id
- process_name
- process_path
- signature
- signature_id
- user_id
- dest
- dvc
- process_exec
- process_guid
- process_id
- process_name
- process_path
- signature
- signature_id
- user_id
- vendor_product
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Sysmon' Guid='{5770385F-C22A-43E0-BF4C-06F5698FFBD9}'/><EventID>9</EventID><Version>2</Version><Level>4</Level><Task>9</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated