|
1 | 1 | [metadata]
|
2 | 2 | creation_date = "2020/10/15"
|
3 | 3 | maturity = "production"
|
4 |
| -updated_date = "2022/04/21" |
| 4 | +updated_date = "2022/06/20" |
5 | 5 |
|
6 | 6 | [rule]
|
7 | 7 | author = ["Elastic"]
|
@@ -93,27 +93,29 @@ type = "eql"
|
93 | 93 | query = '''
|
94 | 94 | iam where event.action == "user-member-enumerated" and
|
95 | 95 |
|
96 |
| - /* noisy and usual legit processes excluded */ |
97 |
| - not winlog.event_data.CallerProcessName: |
98 |
| - ("?:\\Windows\\System32\\VSSVC.exe", |
99 |
| - "?:\\Windows\\System32\\SearchIndexer.exe", |
100 |
| - "?:\\Windows\\System32\\CompatTelRunner.exe", |
101 |
| - "?:\\Windows\\System32\\oobe\\msoobe.exe", |
102 |
| - "?:\\Windows\\System32\\net1.exe", |
103 |
| - "?:\\Windows\\System32\\svchost.exe", |
104 |
| - "?:\\Windows\\System32\\Netplwiz.exe", |
105 |
| - "?:\\Windows\\System32\\msiexec.exe", |
106 |
| - "?:\\Windows\\System32\\CloudExperienceHostBroker.exe", |
107 |
| - "?:\\Windows\\System32\\wbem\\WmiPrvSE.exe", |
108 |
| - "?:\\Windows\\System32\\SrTasks.exe", |
109 |
| - "?:\\Windows\\System32\\lsass.exe", |
110 |
| - "?:\\Windows\\System32\\diskshadow.exe", |
111 |
| - "?:\\Windows\\System32\\dfsrs.exe", |
112 |
| - "?:\\Program Files\\*.exe", |
113 |
| - "?:\\Program Files (x86)\\*.exe") and |
| 96 | + /* noisy and usual legit processes excluded */ |
| 97 | + not winlog.event_data.CallerProcessName: |
| 98 | + ("?:\\Windows\\System32\\VSSVC.exe", |
| 99 | + "?:\\Windows\\System32\\SearchIndexer.exe", |
| 100 | + "?:\\Windows\\System32\\CompatTelRunner.exe", |
| 101 | + "?:\\Windows\\System32\\oobe\\msoobe.exe", |
| 102 | + "?:\\Windows\\System32\\net1.exe", |
| 103 | + "?:\\Windows\\System32\\svchost.exe", |
| 104 | + "?:\\Windows\\System32\\Netplwiz.exe", |
| 105 | + "?:\\Windows\\System32\\msiexec.exe", |
| 106 | + "?:\\Windows\\System32\\CloudExperienceHostBroker.exe", |
| 107 | + "?:\\Windows\\System32\\wbem\\WmiPrvSE.exe", |
| 108 | + "?:\\Windows\\System32\\SrTasks.exe", |
| 109 | + "?:\\Windows\\System32\\lsass.exe", |
| 110 | + "?:\\Windows\\System32\\diskshadow.exe", |
| 111 | + "?:\\Windows\\System32\\dfsrs.exe", |
| 112 | + "?:\\Program Files\\*.exe", |
| 113 | + "?:\\Program Files (x86)\\*.exe", |
| 114 | + "?:\\WindowsAzure\\*\\WaAppAgent.exe") and |
| 115 | +
|
114 | 116 | /* privileged local groups */
|
115 |
| - (group.name:("admin*","RemoteDesktopUsers") or |
116 |
| - winlog.event_data.TargetSid:("S-1-5-32-544","S-1-5-32-555")) |
| 117 | + (group.name:("admin*","RemoteDesktopUsers") or |
| 118 | + winlog.event_data.TargetSid:("S-1-5-32-544","S-1-5-32-555")) |
117 | 119 | '''
|
118 | 120 |
|
119 | 121 |
|
|
0 commit comments