Skip to content

Commit 8011420

Browse files
w0rk3rgithub-actions[bot]
authored andcommitted
Update discovery_privileged_localgroup_membership.toml (#2046)
(cherry picked from commit 853f8db)
1 parent b47e763 commit 8011420

File tree

1 file changed

+23
-21
lines changed

1 file changed

+23
-21
lines changed

rules/windows/discovery_privileged_localgroup_membership.toml

Lines changed: 23 additions & 21 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
[metadata]
22
creation_date = "2020/10/15"
33
maturity = "production"
4-
updated_date = "2022/04/21"
4+
updated_date = "2022/06/20"
55

66
[rule]
77
author = ["Elastic"]
@@ -93,27 +93,29 @@ type = "eql"
9393
query = '''
9494
iam where event.action == "user-member-enumerated" and
9595
96-
/* noisy and usual legit processes excluded */
97-
not winlog.event_data.CallerProcessName:
98-
("?:\\Windows\\System32\\VSSVC.exe",
99-
"?:\\Windows\\System32\\SearchIndexer.exe",
100-
"?:\\Windows\\System32\\CompatTelRunner.exe",
101-
"?:\\Windows\\System32\\oobe\\msoobe.exe",
102-
"?:\\Windows\\System32\\net1.exe",
103-
"?:\\Windows\\System32\\svchost.exe",
104-
"?:\\Windows\\System32\\Netplwiz.exe",
105-
"?:\\Windows\\System32\\msiexec.exe",
106-
"?:\\Windows\\System32\\CloudExperienceHostBroker.exe",
107-
"?:\\Windows\\System32\\wbem\\WmiPrvSE.exe",
108-
"?:\\Windows\\System32\\SrTasks.exe",
109-
"?:\\Windows\\System32\\lsass.exe",
110-
"?:\\Windows\\System32\\diskshadow.exe",
111-
"?:\\Windows\\System32\\dfsrs.exe",
112-
"?:\\Program Files\\*.exe",
113-
"?:\\Program Files (x86)\\*.exe") and
96+
/* noisy and usual legit processes excluded */
97+
not winlog.event_data.CallerProcessName:
98+
("?:\\Windows\\System32\\VSSVC.exe",
99+
"?:\\Windows\\System32\\SearchIndexer.exe",
100+
"?:\\Windows\\System32\\CompatTelRunner.exe",
101+
"?:\\Windows\\System32\\oobe\\msoobe.exe",
102+
"?:\\Windows\\System32\\net1.exe",
103+
"?:\\Windows\\System32\\svchost.exe",
104+
"?:\\Windows\\System32\\Netplwiz.exe",
105+
"?:\\Windows\\System32\\msiexec.exe",
106+
"?:\\Windows\\System32\\CloudExperienceHostBroker.exe",
107+
"?:\\Windows\\System32\\wbem\\WmiPrvSE.exe",
108+
"?:\\Windows\\System32\\SrTasks.exe",
109+
"?:\\Windows\\System32\\lsass.exe",
110+
"?:\\Windows\\System32\\diskshadow.exe",
111+
"?:\\Windows\\System32\\dfsrs.exe",
112+
"?:\\Program Files\\*.exe",
113+
"?:\\Program Files (x86)\\*.exe",
114+
"?:\\WindowsAzure\\*\\WaAppAgent.exe") and
115+
114116
/* privileged local groups */
115-
(group.name:("admin*","RemoteDesktopUsers") or
116-
winlog.event_data.TargetSid:("S-1-5-32-544","S-1-5-32-555"))
117+
(group.name:("admin*","RemoteDesktopUsers") or
118+
winlog.event_data.TargetSid:("S-1-5-32-544","S-1-5-32-555"))
117119
'''
118120

119121

0 commit comments

Comments
 (0)