mirror of
https://github.com/socfortress/Wazuh-Rules.git
synced 2025-11-02 12:53:15 +00:00
Create MITRE_TECHNIQUES_FROM_SYSMON_EVENT22.xml
This commit is contained in:
35
Windows_Sysmon/MITRE_TECHNIQUES_FROM_SYSMON_EVENT22.xml
Normal file
35
Windows_Sysmon/MITRE_TECHNIQUES_FROM_SYSMON_EVENT22.xml
Normal file
@@ -0,0 +1,35 @@
|
||||
<group name="windows,sysmon,">
|
||||
<!-- Sysmon - Event 22: DNS Request by $(win.eventdata.image) -->
|
||||
<rule id="121101" level="3">
|
||||
<if_sid>61644</if_sid>
|
||||
<description>Sysmon - Event 22: DNS Request by $(win.eventdata.image)</description>
|
||||
<mitre>
|
||||
<id>T1071</id>
|
||||
</mitre>
|
||||
<options>no_full_log</options>
|
||||
<group>sysmon_event_22,</group>
|
||||
</rule>
|
||||
<!-- Rule ID 121101 Override if Hostname = AlienVault -->
|
||||
<rule id="121102" level="1">
|
||||
<if_sid>121101</if_sid>
|
||||
<field name="win.eventdata.queryName">^otx\.alienvault\.com$</field>
|
||||
<description>Sysmon - Event 22: DNS Request by $(win.eventdata.image)</description>
|
||||
<mitre>
|
||||
<id>T1071</id>
|
||||
</mitre>
|
||||
<options>no_full_log</options>
|
||||
<group>sysmon_event_22,</group>
|
||||
</rule>
|
||||
<!-- Rule ID 121101 Override if Hostname = Local Hostnames -->
|
||||
<rule id="121103" level="1">
|
||||
<if_sid>121101</if_sid>
|
||||
<field name="win.eventdata.queryName">myorg\.org$</field>
|
||||
<description>Sysmon - Event 22: DNS Request by $(win.eventdata.image)</description>
|
||||
<mitre>
|
||||
<id>T1071</id>
|
||||
</mitre>
|
||||
<options>no_full_log</options>
|
||||
<group>sysmon_event_22,</group>
|
||||
</rule>
|
||||
|
||||
</group>
|
||||
Reference in New Issue
Block a user