mirror of
https://github.com/socfortress/Wazuh-Rules.git
synced 2025-10-23 08:12:16 +00:00
Update and rename 700100-socfortress_added.xml to 800100-socfortress_added.xml
This commit is contained in:
committed by
GitHub
parent
9ea52b133c
commit
8642120fda
@@ -1,12 +1,12 @@
|
|||||||
<group name="socfortress,">
|
<group name="socfortress,">
|
||||||
<!-- ETW Tampering https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63 -->
|
<!-- ETW Tampering https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63 -->
|
||||||
<rule id="700100" level="13">
|
<rule id="800100" level="13">
|
||||||
<if_sid>100541</if_sid>
|
<if_sid>100541</if_sid>
|
||||||
<field name="win.eventdata.scriptBlockText" type="pcre2">(?i)^Remove-EtwTraceProvider|^Set-EtwTraceProvider|^logman update</field>
|
<field name="win.eventdata.scriptBlockText" type="pcre2">(?i)^Remove-EtwTraceProvider|^Set-EtwTraceProvider|^logman update</field>
|
||||||
<description>ETW Tampering Technique was ran.</description>
|
<description>ETW Tampering Technique was ran.</description>
|
||||||
<group>powershell,etw_tampering,</group>
|
<group>powershell,etw_tampering,</group>
|
||||||
</rule>
|
</rule>
|
||||||
<rule id="700101" level="13">
|
<rule id="800101" level="13">
|
||||||
<if_sid>100127</if_sid>
|
<if_sid>100127</if_sid>
|
||||||
<field name="win.eventdata.commandLine" type="pcre2">(?i)^Remove-EtwTraceProvider|^Set-EtwTraceProvider|^logman update</field>
|
<field name="win.eventdata.commandLine" type="pcre2">(?i)^Remove-EtwTraceProvider|^Set-EtwTraceProvider|^logman update</field>
|
||||||
<description>ETW Tampering Technique was ran.</description>
|
<description>ETW Tampering Technique was ran.</description>
|
Reference in New Issue
Block a user