| 1 | import type { AlertsSummary } from "@/types/alerts.d" |
| 2 | import { |
| 3 | AlertSourceDataGroup, |
| 4 | AlertSourceDataKind, |
| 5 | AlertSourceDataLevelEnum, |
| 6 | AlertSourceDataLogsourceCategory, |
| 7 | AlertSourceDataLogsourceProduct, |
| 8 | AlertSourceDataStatus, |
| 9 | AlertSourceDataWinEventdataIntegrityLevel, |
| 10 | AlertSourceDataWinSystemSeverityValue, |
| 11 | AlertSourceDecoderName, |
| 12 | AlertSourceSyslogLevel, |
| 13 | AlertSourceSyslogType |
| 14 | } from "@/types/alerts.d" |
| 15 | |
| 16 | export const alerts_summary: AlertsSummary[] = [ |
| 17 | { |
| 18 | index_name: "wazuh-wso4vxhq_7", |
| 19 | total_alerts: 5, |
| 20 | alerts: [ |
| 21 | { |
| 22 | _index: "wazuh-wso4vxhq_7", |
| 23 | _id: "54842c0a-7bd6-11ee-93bc-86000046278a", |
| 24 | _score: null, |
| 25 | _source: { |
| 26 | rule_level: 12, |
| 27 | rule_description: |
| 28 | "Possible code injection on explorer.exe by C:\\\\Program Files\\\\VMware\\\\VMware Tools\\\\vmtoolsd.exe", |
| 29 | rule_groups: "sysmon, sysmon_eid8_detections, windows", |
| 30 | rule_firedtimes: 1, |
| 31 | rule_id: "92400", |
| 32 | rule_mail: true, |
| 33 | |
| 34 | syslog_type: AlertSourceSyslogType.Wazuh, |
| 35 | syslog_level: AlertSourceSyslogLevel.Alert, |
| 36 | |
| 37 | agent_id: "070", |
| 38 | agent_ip: "202.43.110.138", |
| 39 | agent_name: "web1", |
| 40 | agent_labels_customer: "wso4vxhq", |
| 41 | |
| 42 | alert_url: |
| 43 | "https://ashirs01.socfortress.local/alerts?cid=1&page=1&per_page=10&sort=desc&alert_ids=2751", |
| 44 | |
| 45 | source: "10.255.255.13", |
| 46 | streams: ["650d3da25e9a2d550c6d6491"], |
| 47 | decoder_name: AlertSourceDecoderName.WindowsEventchannel, |
| 48 | manager_name: "ASHWZHMA", |
| 49 | location: "EventChannel", |
| 50 | |
| 51 | data_win_eventdata_newThreadId: "16400", |
| 52 | source_reserved_ip: true, |
| 53 | data_win_system_eventRecordID: "4879057", |
| 54 | gl2_remote_ip: "10.255.255.13", |
| 55 | data_win_system_eventID: "8", |
| 56 | gl2_remote_port: 50576, |
| 57 | agent_ip_city_name: "N/A", |
| 58 | data_win_eventdata_targetImage: "C:\\\\Windows\\\\explorer.exe", |
| 59 | gl2_source_input: "6459151dea00fd5d3da2df91", |
| 60 | data_win_eventdata_sourceUser: "NT AUTHORITY\\\\SYSTEM", |
| 61 | data_win_system_task: "8", |
| 62 | timestamp_utc: "2023-11-05T12:24:50.567Z", |
| 63 | data_win_system_threadID: "5576", |
| 64 | gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38", |
| 65 | id: "1699187091.698192264", |
| 66 | data_win_eventdata_sourceImage: "C:\\\\Program Files\\\\VMware\\\\VMware Tools\\\\vmtoolsd.exe", |
| 67 | rule_mitre_tactic: "Defense Evasion, Privilege Escalation", |
| 68 | data_win_eventdata_targetProcessGuid: "{d9ab9ebb-62bb-6547-601c-020000003000}", |
| 69 | gl2_accounted_message_size: 5134, |
| 70 | data_win_eventdata_utcTime: "2023-11-05 12:24:50.567", |
| 71 | rule_mitre_id: "T1055", |
| 72 | gl2_message_id: "01HEFQ2Z1GF61945NDN156XZRD", |
| 73 | data_win_system_computer: "web1", |
| 74 | data_win_eventdata_ruleName: "technique_id=T1055,technique_name=Process Injection", |
| 75 | data_win_eventdata_startAddress: "0x00007FFDE5CCE720", |
| 76 | true: 1699187091.846419, |
| 77 | data_win_system_keywords: "0x8000000000000000", |
| 78 | data_win_system_level: "4", |
| 79 | data_win_system_severityValue: AlertSourceDataWinSystemSeverityValue.Information, |
| 80 | data_win_eventdata_targetUser: "WEB1\\\\Administrator", |
| 81 | agent_ip_geolocation: "16.1667,107.8333", |
| 82 | rule_mitre_technique: "Process Injection", |
| 83 | data_win_system_systemTime: "2023-11-05T12:24:50.567370300Z", |
| 84 | agent_ip_country_code: "VN", |
| 85 | data_win_system_processID: "3468", |
| 86 | data_win_system_channel: "Microsoft-Windows-Sysmon/Operational", |
| 87 | data_win_system_providerName: "Microsoft-Windows-Sysmon", |
| 88 | data_win_system_version: "2", |
| 89 | data_win_system_providerGuid: "{5770385f-c22a-43e0-bf4c-06f5698ffbd9}", |
| 90 | timestamp: "2023-11-05 12:24:56.624", |
| 91 | data_win_system_opcode: "0", |
| 92 | gl2_processing_error: |
| 93 | 'Replaced invalid timestamp value in message <54842c0a-7bd6-11ee-93bc-86000046278a> with current time - Value <2023-11-05T12:24:51.691+0000> caused exception: Invalid format: "2023-11-05T12:24:51.691+0000" is malformed at "T12:24:51.691+0000".', |
| 94 | data_win_eventdata_sourceProcessId: "3368", |
| 95 | data_win_eventdata_startModule: "C:\\\\Windows\\\\System32\\\\KERNEL32.DLL", |
| 96 | message: |
| 97 | '{"true":1699187091.846419,"timestamp":"2023-11-05T12:24:51.691+0000","rule":{"level":12,"description":"Possible code injection on explorer.exe by C:\\\\\\\\Program Files\\\\\\\\VMware\\\\\\\\VMware Tools\\\\\\\\vmtoolsd.exe","id":"92400","mitre":{"id":["T1055"],"tactic":["Defense Evasion","Privilege Escalation"],"technique":["Process Injection"]},"firedtimes":1,"mail":true,"groups":["sysmon","sysmon_eid8_detections","windows"]},"agent":{"id":"070","name":"web1","ip":"202.43.110.138","labels":{"customer":"wso4vxhq"}},"manager":{"name":"ASHWZHMA"},"id":"1699187091.698192264","decoder":{"name":"windows_eventchannel"},"data":{"win":{"system":{"providerName":"Microsoft-Windows-Sysmon","providerGuid":"{5770385f-c22a-43e0-bf4c-06f5698ffbd9}","eventID":"8","version":"2","level":"4","task":"8","opcode":"0","keywords":"0x8000000000000000","systemTime":"2023-11-05T12:24:50.567370300Z","eventRecordID":"4879057","processID":"3468","threadID":"5576","channel":"Microsoft-Windows-Sysmon/Operational","computer":"web1","severityValue":"INFORMATION","message":"\\"CreateRemoteThread detected:\\r\\nRuleName: technique_id=T1055,technique_name=Process Injection\\r\\nUtcTime: 2023-11-05 12:24:50.567\\r\\nSourceProcessGuid: {d9ab9ebb-48da-652f-4900-000000003000}\\r\\nSourceProcessId: 3368\\r\\nSourceImage: C:\\\\Program Files\\\\VMware\\\\VMware Tools\\\\vmtoolsd.exe\\r\\nTargetProcessGuid: {d9ab9ebb-62bb-6547-601c-020000003000}\\r\\nTargetProcessId: 4384\\r\\nTargetImage: C:\\\\Windows\\\\explorer.exe\\r\\nNewThreadId: 16400\\r\\nStartAddress: 0x00007FFDE5CCE720\\r\\nStartModule: C:\\\\Windows\\\\System32\\\\KERNEL32.DLL\\r\\nStartFunction: GetCommandLineW\\r\\nSourceUser: NT AUTHORITY\\\\SYSTEM\\r\\nTargetUser: WEB1\\\\Administrator\\""},"eventdata":{"ruleName":"technique_id=T1055,technique_name=Process Injection","utcTime":"2023-11-05 12:24:50.567","sourceProcessGuid":"{d9ab9ebb-48da-652f-4900-000000003000}","sourceProcessId":"3368","sourceImage":"C:\\\\\\\\Program Files\\\\\\\\VMware\\\\\\\\VMware Tools\\\\\\\\vmtoolsd.exe","targetProcessGuid":"{d9ab9ebb-62bb-6547-601c-020000003000}","targetProcessId":"4384","targetImage":"C:\\\\\\\\Windows\\\\\\\\explorer.exe","newThreadId":"16400","startAddress":"0x00007FFDE5CCE720","startModule":"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\KERNEL32.DLL","startFunction":"GetCommandLineW","sourceUser":"NT AUTHORITY\\\\\\\\SYSTEM","targetUser":"WEB1\\\\\\\\Administrator"}}},"location":"EventChannel"}', |
| 98 | data_win_eventdata_sourceProcessGuid: "{d9ab9ebb-48da-652f-4900-000000003000}", |
| 99 | data_win_eventdata_targetProcessId: "4384", |
| 100 | data_win_eventdata_startFunction: "GetCommandLineW", |
| 101 | rule_group3: AlertSourceDataLogsourceProduct.Windows, |
| 102 | data_win_system_message: |
| 103 | '"CreateRemoteThread detected:\r\nRuleName: technique_id=T1055,technique_name=Process Injection\r\nUtcTime: 2023-11-05 12:24:50.567\r\nSourceProcessGuid: {d9ab9ebb-48da-652f-4900-000000003000}\r\nSourceProcessId: 3368\r\nSourceImage: C:\\Program Files\\VMware\\VMware Tools\\vmtoolsd.exe\r\nTargetProcessGuid: {d9ab9ebb-62bb-6547-601c-020000003000}\r\nTargetProcessId: 4384\r\nTargetImage: C:\\Windows\\explorer.exe\r\nNewThreadId: 16400\r\nStartAddress: 0x00007FFDE5CCE720\r\nStartModule: C:\\Windows\\System32\\KERNEL32.DLL\r\nStartFunction: GetCommandLineW\r\nSourceUser: NT AUTHORITY\\SYSTEM\r\nTargetUser: WEB1\\Administrator"', |
| 104 | msg_timestamp: "2023-11-05T12:24:51.691Z", |
| 105 | rule_group2: "sysmon_eid8_detections", |
| 106 | rule_group1: "sysmon" |
| 107 | }, |
| 108 | sort: [1699187090567] |
| 109 | }, |
| 110 | { |
| 111 | _index: "wazuh-wso4vxhq_7", |
| 112 | _id: "48a2f142-7bd6-11ee-93bc-86000046278a", |
| 113 | _score: null, |
| 114 | _source: { |
| 115 | data_win_eventdata_newThreadId: "17292", |
| 116 | source_reserved_ip: true, |
| 117 | data_win_system_eventRecordID: "4878905", |
| 118 | agent_id: "070", |
| 119 | agent_name: "web1", |
| 120 | gl2_remote_ip: "10.255.255.13", |
| 121 | data_win_system_eventID: "8", |
| 122 | gl2_remote_port: 57222, |
| 123 | agent_labels_customer: "wso4vxhq", |
| 124 | agent_ip_city_name: "N/A", |
| 125 | source: "10.255.255.13", |
| 126 | data_win_eventdata_targetImage: "C:\\\\Windows\\\\System32\\\\lsass.exe", |
| 127 | gl2_source_input: "6459151dea00fd5d3da2df91", |
| 128 | rule_level: 12, |
| 129 | data_win_eventdata_sourceUser: "NT AUTHORITY\\\\SYSTEM", |
| 130 | data_win_system_task: "8", |
| 131 | timestamp_utc: "2023-11-05T12:24:32.015Z", |
| 132 | syslog_type: AlertSourceSyslogType.Wazuh, |
| 133 | data_win_system_threadID: "5576", |
| 134 | rule_description: |
| 135 | "Local Security Authority Subsystem Service (LSASS) process was accessed by C:\\\\Program Files\\\\VMware\\\\VMware Tools\\\\vmtoolsd.exe, possible code injection for credential dumping", |
| 136 | gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38", |
| 137 | id: "1699187072.697473214", |
| 138 | data_win_eventdata_sourceImage: "C:\\\\Program Files\\\\VMware\\\\VMware Tools\\\\vmtoolsd.exe", |
| 139 | rule_mitre_tactic: "Defense Evasion, Privilege Escalation", |
| 140 | data_win_eventdata_targetProcessGuid: "{d9ab9ebb-48d7-652f-0c00-000000003000}", |
| 141 | gl2_accounted_message_size: 5323, |
| 142 | data_win_eventdata_utcTime: "2023-11-05 12:24:32.013", |
| 143 | streams: ["650d3da25e9a2d550c6d6491"], |
| 144 | rule_mitre_id: "T1055", |
| 145 | gl2_message_id: "01HEFQ2BJMQ6D8ZQD9SW96GKRJ", |
| 146 | data_win_system_computer: "web1", |
| 147 | data_win_eventdata_ruleName: "technique_id=T1055,technique_name=Process Injection", |
| 148 | agent_ip: "202.43.110.138", |
| 149 | data_win_eventdata_startAddress: "0x00007FFDE5CCE720", |
| 150 | true: 1699187072.493505, |
| 151 | rule_groups: "sysmon, sysmon_eid8_detections, windows", |
| 152 | data_win_system_keywords: "0x8000000000000000", |
| 153 | data_win_system_level: "4", |
| 154 | data_win_system_severityValue: AlertSourceDataWinSystemSeverityValue.Information, |
| 155 | data_win_eventdata_targetUser: "NT AUTHORITY\\\\SYSTEM", |
| 156 | agent_ip_geolocation: "16.1667,107.8333", |
| 157 | rule_mitre_technique: "Process Injection", |
| 158 | rule_firedtimes: 1, |
| 159 | data_win_system_systemTime: "2023-11-05T12:24:32.015055900Z", |
| 160 | rule_mail: true, |
| 161 | decoder_name: AlertSourceDecoderName.WindowsEventchannel, |
| 162 | agent_ip_country_code: "VN", |
| 163 | data_win_system_processID: "3468", |
| 164 | data_win_system_channel: "Microsoft-Windows-Sysmon/Operational", |
| 165 | syslog_level: AlertSourceSyslogLevel.Alert, |
| 166 | data_win_system_providerName: "Microsoft-Windows-Sysmon", |
| 167 | data_win_system_version: "2", |
| 168 | data_win_system_providerGuid: "{5770385f-c22a-43e0-bf4c-06f5698ffbd9}", |
| 169 | timestamp: "2023-11-05 12:24:36.692", |
| 170 | data_win_system_opcode: "0", |
| 171 | gl2_processing_error: |
| 172 | 'Replaced invalid timestamp value in message <48a2f142-7bd6-11ee-93bc-86000046278a> with current time - Value <2023-11-05T12:24:32.489+0000> caused exception: Invalid format: "2023-11-05T12:24:32.489+0000" is malformed at "T12:24:32.489+0000".', |
| 173 | data_win_eventdata_sourceProcessId: "3368", |
| 174 | data_win_eventdata_startModule: "C:\\\\Windows\\\\System32\\\\KERNEL32.DLL", |
| 175 | message: |
| 176 | '{"true":1699187072.493505,"timestamp":"2023-11-05T12:24:32.489+0000","rule":{"level":12,"description":"Local Security Authority Subsystem Service (LSASS) process was accessed by C:\\\\\\\\Program Files\\\\\\\\VMware\\\\\\\\VMware Tools\\\\\\\\vmtoolsd.exe, possible code injection for credential dumping","id":"92403","mitre":{"id":["T1055"],"tactic":["Defense Evasion","Privilege Escalation"],"technique":["Process Injection"]},"firedtimes":1,"mail":true,"groups":["sysmon","sysmon_eid8_detections","windows"]},"agent":{"id":"070","name":"web1","ip":"202.43.110.138","labels":{"customer":"wso4vxhq"}},"manager":{"name":"ASHWZHMA"},"id":"1699187072.697473214","decoder":{"name":"windows_eventchannel"},"data":{"win":{"system":{"providerName":"Microsoft-Windows-Sysmon","providerGuid":"{5770385f-c22a-43e0-bf4c-06f5698ffbd9}","eventID":"8","version":"2","level":"4","task":"8","opcode":"0","keywords":"0x8000000000000000","systemTime":"2023-11-05T12:24:32.015055900Z","eventRecordID":"4878905","processID":"3468","threadID":"5576","channel":"Microsoft-Windows-Sysmon/Operational","computer":"web1","severityValue":"INFORMATION","message":"\\"CreateRemoteThread detected:\\r\\nRuleName: technique_id=T1055,technique_name=Process Injection\\r\\nUtcTime: 2023-11-05 12:24:32.013\\r\\nSourceProcessGuid: {d9ab9ebb-48da-652f-4900-000000003000}\\r\\nSourceProcessId: 3368\\r\\nSourceImage: C:\\\\Program Files\\\\VMware\\\\VMware Tools\\\\vmtoolsd.exe\\r\\nTargetProcessGuid: {d9ab9ebb-48d7-652f-0c00-000000003000}\\r\\nTargetProcessId: 740\\r\\nTargetImage: C:\\\\Windows\\\\System32\\\\lsass.exe\\r\\nNewThreadId: 17292\\r\\nStartAddress: 0x00007FFDE5CCE720\\r\\nStartModule: C:\\\\Windows\\\\System32\\\\KERNEL32.DLL\\r\\nStartFunction: GetCommandLineW\\r\\nSourceUser: NT AUTHORITY\\\\SYSTEM\\r\\nTargetUser: NT AUTHORITY\\\\SYSTEM\\""},"eventdata":{"ruleName":"technique_id=T1055,technique_name=Process Injection","utcTime":"2023-11-05 12:24:32.013","sourceProcessGuid":"{d9ab9ebb-48da-652f-4900-000000003000}","sourceProcessId":"3368","sourceImage":"C:\\\\\\\\Program Files\\\\\\\\VMware\\\\\\\\VMware Tools\\\\\\\\vmtoolsd.exe","targetProcessGuid":"{d9ab9ebb-48d7-652f-0c00-000000003000}","targetProcessId":"740","targetImage":"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\lsass.exe","newThreadId":"17292","startAddress":"0x00007FFDE5CCE720","startModule":"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\KERNEL32.DLL","startFunction":"GetCommandLineW","sourceUser":"NT AUTHORITY\\\\\\\\SYSTEM","targetUser":"NT AUTHORITY\\\\\\\\SYSTEM"}}},"location":"EventChannel"}', |
| 177 | rule_id: "92403", |
| 178 | manager_name: "ASHWZHMA", |
| 179 | data_win_eventdata_sourceProcessGuid: "{d9ab9ebb-48da-652f-4900-000000003000}", |
| 180 | location: "EventChannel", |
| 181 | data_win_eventdata_targetProcessId: "740", |
| 182 | data_win_eventdata_startFunction: "GetCommandLineW", |
| 183 | rule_group3: AlertSourceDataLogsourceProduct.Windows, |
| 184 | data_win_system_message: |
| 185 | '"CreateRemoteThread detected:\r\nRuleName: technique_id=T1055,technique_name=Process Injection\r\nUtcTime: 2023-11-05 12:24:32.013\r\nSourceProcessGuid: {d9ab9ebb-48da-652f-4900-000000003000}\r\nSourceProcessId: 3368\r\nSourceImage: C:\\Program Files\\VMware\\VMware Tools\\vmtoolsd.exe\r\nTargetProcessGuid: {d9ab9ebb-48d7-652f-0c00-000000003000}\r\nTargetProcessId: 740\r\nTargetImage: C:\\Windows\\System32\\lsass.exe\r\nNewThreadId: 17292\r\nStartAddress: 0x00007FFDE5CCE720\r\nStartModule: C:\\Windows\\System32\\KERNEL32.DLL\r\nStartFunction: GetCommandLineW\r\nSourceUser: NT AUTHORITY\\SYSTEM\r\nTargetUser: NT AUTHORITY\\SYSTEM"', |
| 186 | msg_timestamp: "2023-11-05T12:24:32.489Z", |
| 187 | rule_group2: "sysmon_eid8_detections", |
| 188 | rule_group1: "sysmon" |
| 189 | }, |
| 190 | sort: [1699187072015] |
| 191 | }, |
| 192 | { |
| 193 | _index: "wazuh-wso4vxhq_7", |
| 194 | _id: "18e9b012-7bd6-11ee-93bc-86000046278a", |
| 195 | _score: null, |
| 196 | _source: { |
| 197 | source_reserved_ip: true, |
| 198 | data_win_system_eventRecordID: "4878784", |
| 199 | agent_id: "070", |
| 200 | agent_name: "web1", |
| 201 | data_win_eventdata_sourceProcessGUID: "{d9ab9ebb-7e1a-6544-44e0-010000003000}", |
| 202 | gl2_remote_ip: "10.255.255.13", |
| 203 | data_win_system_eventID: "10", |
| 204 | gl2_remote_port: 60342, |
| 205 | agent_labels_customer: "wso4vxhq", |
| 206 | agent_ip_city_name: "N/A", |
| 207 | source: "10.255.255.13", |
| 208 | data_win_eventdata_targetImage: "C:\\\\Windows\\\\explorer.exe", |
| 209 | gl2_source_input: "6459151dea00fd5d3da2df91", |
| 210 | rule_level: 12, |
| 211 | data_win_eventdata_sourceUser: "WEB1\\\\Administrator", |
| 212 | data_win_system_task: "10", |
| 213 | timestamp_utc: "2023-11-05T12:23:11.139Z", |
| 214 | syslog_type: AlertSourceSyslogType.Wazuh, |
| 215 | data_win_system_threadID: "5576", |
| 216 | rule_description: |
| 217 | "Explorer process was accessed by C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe, possible process injection", |
| 218 | gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38", |
| 219 | id: "1699186992.695685886", |
| 220 | data_win_eventdata_grantedAccess: "0x40", |
| 221 | data_win_eventdata_sourceImage: |
| 222 | "C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe", |
| 223 | rule_mitre_tactic: "Defense Evasion, Privilege Escalation", |
| 224 | gl2_accounted_message_size: 11630, |
| 225 | data_win_eventdata_utcTime: "2023-11-05 12:23:11.138", |
| 226 | streams: ["650d3da25e9a2d550c6d6491"], |
| 227 | rule_mitre_id: "T1055", |
| 228 | gl2_message_id: "01HEFPZXCJZA24HYV8G8E45ND1", |
| 229 | data_win_system_computer: "web1", |
| 230 | data_win_eventdata_ruleName: "technique_id=T1036,technique_name=Masquerading", |
| 231 | agent_ip: "202.43.110.138", |
| 232 | true: 1699186992.569563, |
| 233 | rule_groups: "sysmon, sysmon_eid10_detections, windows", |
| 234 | data_win_system_keywords: "0x8000000000000000", |
| 235 | data_win_system_level: "4", |
| 236 | data_win_eventdata_targetProcessGUID: "{d9ab9ebb-62bb-6547-601c-020000003000}", |
| 237 | data_win_system_severityValue: AlertSourceDataWinSystemSeverityValue.Information, |
| 238 | data_win_eventdata_targetUser: "WEB1\\\\Administrator", |
| 239 | agent_ip_geolocation: "16.1667,107.8333", |
| 240 | rule_mitre_technique: "Process Injection", |
| 241 | rule_firedtimes: 33, |
| 242 | data_win_system_systemTime: "2023-11-05T12:23:11.139487000Z", |
| 243 | rule_mail: true, |
| 244 | decoder_name: AlertSourceDecoderName.WindowsEventchannel, |
| 245 | agent_ip_country_code: "VN", |
| 246 | data_win_system_processID: "3468", |
| 247 | data_win_system_channel: "Microsoft-Windows-Sysmon/Operational", |
| 248 | syslog_level: AlertSourceSyslogLevel.Alert, |
| 249 | data_win_system_providerName: "Microsoft-Windows-Sysmon", |
| 250 | data_win_system_version: "3", |
| 251 | data_win_system_providerGuid: "{5770385f-c22a-43e0-bf4c-06f5698ffbd9}", |
| 252 | timestamp: "2023-11-05 12:23:16.626", |
| 253 | data_win_eventdata_callTrace: |
| 254 | "C:\\\\Windows\\\\SYSTEM32\\\\ntdll.dll+9ff24|C:\\\\Windows\\\\System32\\\\KERNELBASE.dll+1668e|C:\\\\Windows\\\\System32\\\\shcore.dll+cca8|C:\\\\Windows\\\\System32\\\\shcore.dll+ba77|C:\\\\Windows\\\\System32\\\\shcore.dll+b967|C:\\\\Windows\\\\System32\\\\shcore.dll+b8f1|C:\\\\Windows\\\\System32\\\\shcore.dll+b61a|C:\\\\Windows\\\\system32\\\\explorerframe.dll+12b9d0|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+157bd8c|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+18051ce|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2e1a17|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2dfdfe|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+130216a|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a566ec|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a5695f|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3e93b|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c40433|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb8e|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3d62541|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb68|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c942dd|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3db94|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a52491|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a3e4a9", |
| 255 | data_win_system_opcode: "0", |
| 256 | gl2_processing_error: |
| 257 | 'Replaced invalid timestamp value in message <18e9b012-7bd6-11ee-93bc-86000046278a> with current time - Value <2023-11-05T12:23:12.276+0000> caused exception: Invalid format: "2023-11-05T12:23:12.276+0000" is malformed at "T12:23:12.276+0000".', |
| 258 | data_win_eventdata_sourceProcessId: "1652", |
| 259 | message: |
| 260 | '{"true":1699186992.569563,"timestamp":"2023-11-05T12:23:12.276+0000","rule":{"level":12,"description":"Explorer process was accessed by C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe, possible process injection","id":"92910","mitre":{"id":["T1055"],"tactic":["Defense Evasion","Privilege Escalation"],"technique":["Process Injection"]},"firedtimes":33,"mail":true,"groups":["sysmon","sysmon_eid10_detections","windows"]},"agent":{"id":"070","name":"web1","ip":"202.43.110.138","labels":{"customer":"wso4vxhq"}},"manager":{"name":"ASHWZHMA"},"id":"1699186992.695685886","decoder":{"name":"windows_eventchannel"},"data":{"win":{"system":{"providerName":"Microsoft-Windows-Sysmon","providerGuid":"{5770385f-c22a-43e0-bf4c-06f5698ffbd9}","eventID":"10","version":"3","level":"4","task":"10","opcode":"0","keywords":"0x8000000000000000","systemTime":"2023-11-05T12:23:11.139487000Z","eventRecordID":"4878784","processID":"3468","threadID":"5576","channel":"Microsoft-Windows-Sysmon/Operational","computer":"web1","severityValue":"INFORMATION","message":"\\"Process accessed:\\r\\nRuleName: technique_id=T1036,technique_name=Masquerading\\r\\nUtcTime: 2023-11-05 12:23:11.138\\r\\nSourceProcessGUID: {d9ab9ebb-7e1a-6544-44e0-010000003000}\\r\\nSourceProcessId: 1652\\r\\nSourceThreadId: 1284\\r\\nSourceImage: C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe\\r\\nTargetProcessGUID: {d9ab9ebb-62bb-6547-601c-020000003000}\\r\\nTargetProcessId: 4384\\r\\nTargetImage: C:\\\\Windows\\\\explorer.exe\\r\\nGrantedAccess: 0x40\\r\\nCallTrace: C:\\\\Windows\\\\SYSTEM32\\\\ntdll.dll+9ff24|C:\\\\Windows\\\\System32\\\\KERNELBASE.dll+1668e|C:\\\\Windows\\\\System32\\\\shcore.dll+cca8|C:\\\\Windows\\\\System32\\\\shcore.dll+ba77|C:\\\\Windows\\\\System32\\\\shcore.dll+b967|C:\\\\Windows\\\\System32\\\\shcore.dll+b8f1|C:\\\\Windows\\\\System32\\\\shcore.dll+b61a|C:\\\\Windows\\\\system32\\\\explorerframe.dll+12b9d0|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+157bd8c|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+18051ce|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2e1a17|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2dfdfe|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+130216a|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a566ec|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a5695f|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3e93b|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c40433|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb8e|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3d62541|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb68|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c942dd|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3db94|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a52491|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a3e4a9\\r\\nSourceUser: WEB1\\\\Administrator\\r\\nTargetUser: WEB1\\\\Administrator\\""},"eventdata":{"ruleName":"technique_id=T1036,technique_name=Masquerading","utcTime":"2023-11-05 12:23:11.138","sourceProcessGUID":"{d9ab9ebb-7e1a-6544-44e0-010000003000}","sourceProcessId":"1652","sourceThreadId":"1284","sourceImage":"C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe","targetProcessGUID":"{d9ab9ebb-62bb-6547-601c-020000003000}","targetProcessId":"4384","targetImage":"C:\\\\\\\\Windows\\\\\\\\explorer.exe","grantedAccess":"0x40","callTrace":"C:\\\\\\\\Windows\\\\\\\\SYSTEM32\\\\\\\\ntdll.dll+9ff24|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\KERNELBASE.dll+1668e|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+cca8|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+ba77|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+b967|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+b8f1|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+b61a|C:\\\\\\\\Windows\\\\\\\\system32\\\\\\\\explorerframe.dll+12b9d0|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+157bd8c|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+18051ce|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+2e1a17|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+2dfdfe|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+130216a|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+a566ec|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+a5695f|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c3e93b|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c40433|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3fbdb8e|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3d62541|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3fbdb68|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c942dd|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c3db94|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+a52491|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+a3e4a9","sourceUser":"WEB1\\\\\\\\Administrator","targetUser":"WEB1\\\\\\\\Administrator"}}},"location":"EventChannel"}', |
| 261 | rule_id: "92910", |
| 262 | manager_name: "ASHWZHMA", |
| 263 | location: "EventChannel", |
| 264 | data_win_eventdata_targetProcessId: "4384", |
| 265 | rule_group3: AlertSourceDataLogsourceProduct.Windows, |
| 266 | data_win_system_message: |
| 267 | '"Process accessed:\r\nRuleName: technique_id=T1036,technique_name=Masquerading\r\nUtcTime: 2023-11-05 12:23:11.138\r\nSourceProcessGUID: {d9ab9ebb-7e1a-6544-44e0-010000003000}\r\nSourceProcessId: 1652\r\nSourceThreadId: 1284\r\nSourceImage: C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe\r\nTargetProcessGUID: {d9ab9ebb-62bb-6547-601c-020000003000}\r\nTargetProcessId: 4384\r\nTargetImage: C:\\Windows\\explorer.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+9ff24|C:\\Windows\\System32\\KERNELBASE.dll+1668e|C:\\Windows\\System32\\shcore.dll+cca8|C:\\Windows\\System32\\shcore.dll+ba77|C:\\Windows\\System32\\shcore.dll+b967|C:\\Windows\\System32\\shcore.dll+b8f1|C:\\Windows\\System32\\shcore.dll+b61a|C:\\Windows\\system32\\explorerframe.dll+12b9d0|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+157bd8c|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+18051ce|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+2e1a17|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+2dfdfe|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+130216a|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+a566ec|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+a5695f|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c3e93b|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c40433|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3fbdb8e|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3d62541|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3fbdb68|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c942dd|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c3db94|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+a52491|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+a3e4a9\r\nSourceUser: WEB1\\Administrator\r\nTargetUser: WEB1\\Administrator"', |
| 268 | data_win_eventdata_sourceThreadId: "1284", |
| 269 | msg_timestamp: "2023-11-05T12:23:12.276Z", |
| 270 | rule_group2: "sysmon_eid10_detections", |
| 271 | rule_group1: "sysmon" |
| 272 | }, |
| 273 | sort: [1699186991139] |
| 274 | }, |
| 275 | { |
| 276 | _index: "wazuh-wso4vxhq_7", |
| 277 | _id: "18e9b010-7bd6-11ee-93bc-86000046278a", |
| 278 | _score: null, |
| 279 | _source: { |
| 280 | source_reserved_ip: true, |
| 281 | data_win_system_eventRecordID: "4878783", |
| 282 | agent_id: "070", |
| 283 | agent_name: "web1", |
| 284 | data_win_eventdata_sourceProcessGUID: "{d9ab9ebb-7e1a-6544-44e0-010000003000}", |
| 285 | gl2_remote_ip: "10.255.255.13", |
| 286 | data_win_system_eventID: "10", |
| 287 | gl2_remote_port: 60342, |
| 288 | agent_labels_customer: "wso4vxhq", |
| 289 | agent_ip_city_name: "N/A", |
| 290 | source: "10.255.255.13", |
| 291 | data_win_eventdata_targetImage: "C:\\\\Windows\\\\explorer.exe", |
| 292 | gl2_source_input: "6459151dea00fd5d3da2df91", |
| 293 | rule_level: 12, |
| 294 | data_win_eventdata_sourceUser: "WEB1\\\\Administrator", |
| 295 | data_win_system_task: "10", |
| 296 | timestamp_utc: "2023-11-05T12:23:11.139Z", |
| 297 | syslog_type: AlertSourceSyslogType.Wazuh, |
| 298 | data_win_system_threadID: "5576", |
| 299 | rule_description: |
| 300 | "Explorer process was accessed by C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe, possible process injection", |
| 301 | gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38", |
| 302 | id: "1699186992.695678238", |
| 303 | data_win_eventdata_grantedAccess: "0x40", |
| 304 | data_win_eventdata_sourceImage: |
| 305 | "C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe", |
| 306 | rule_mitre_tactic: "Defense Evasion, Privilege Escalation", |
| 307 | gl2_accounted_message_size: 11455, |
| 308 | data_win_eventdata_utcTime: "2023-11-05 12:23:11.137", |
| 309 | streams: ["650d3da25e9a2d550c6d6491"], |
| 310 | rule_mitre_id: "T1055", |
| 311 | gl2_message_id: "01HEFPZXCJWE7EJ5BK46QKR67G", |
| 312 | data_win_system_computer: "web1", |
| 313 | data_win_eventdata_ruleName: "technique_id=T1036,technique_name=Masquerading", |
| 314 | agent_ip: "202.43.110.138", |
| 315 | true: 1699186992.277071, |
| 316 | rule_groups: "sysmon, sysmon_eid10_detections, windows", |
| 317 | data_win_system_keywords: "0x8000000000000000", |
| 318 | data_win_system_level: "4", |
| 319 | data_win_eventdata_targetProcessGUID: "{d9ab9ebb-62bb-6547-601c-020000003000}", |
| 320 | data_win_system_severityValue: AlertSourceDataWinSystemSeverityValue.Information, |
| 321 | data_win_eventdata_targetUser: "WEB1\\\\Administrator", |
| 322 | agent_ip_geolocation: "16.1667,107.8333", |
| 323 | rule_mitre_technique: "Process Injection", |
| 324 | rule_firedtimes: 32, |
| 325 | data_win_system_systemTime: "2023-11-05T12:23:11.139039000Z", |
| 326 | rule_mail: true, |
| 327 | decoder_name: AlertSourceDecoderName.WindowsEventchannel, |
| 328 | agent_ip_country_code: "VN", |
| 329 | data_win_system_processID: "3468", |
| 330 | data_win_system_channel: "Microsoft-Windows-Sysmon/Operational", |
| 331 | syslog_level: AlertSourceSyslogLevel.Alert, |
| 332 | data_win_system_providerName: "Microsoft-Windows-Sysmon", |
| 333 | data_win_system_version: "3", |
| 334 | data_win_system_providerGuid: "{5770385f-c22a-43e0-bf4c-06f5698ffbd9}", |
| 335 | timestamp: "2023-11-05 12:23:16.626", |
| 336 | data_win_eventdata_callTrace: |
| 337 | "C:\\\\Windows\\\\SYSTEM32\\\\ntdll.dll+9ff24|C:\\\\Windows\\\\System32\\\\KERNELBASE.dll+1668e|C:\\\\Windows\\\\System32\\\\shcore.dll+cca8|C:\\\\Windows\\\\System32\\\\shcore.dll+ba62|C:\\\\Windows\\\\System32\\\\shcore.dll+b585|C:\\\\Windows\\\\System32\\\\shcore.dll+b275|C:\\\\Windows\\\\System32\\\\shcore.dll+b209|C:\\\\Windows\\\\System32\\\\shcore.dll+b104|C:\\\\Windows\\\\system32\\\\explorerframe.dll+12b986|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+157bd8c|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+18051ce|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2e1a17|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2dfdfe|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+130216a|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a566ec|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a5695f|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3e93b|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c40433|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb8e|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3d62541|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb68|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c942dd|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3db94|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a52491", |
| 338 | data_win_system_opcode: "0", |
| 339 | gl2_processing_error: |
| 340 | 'Replaced invalid timestamp value in message <18e9b010-7bd6-11ee-93bc-86000046278a> with current time - Value <2023-11-05T12:23:12.272+0000> caused exception: Invalid format: "2023-11-05T12:23:12.272+0000" is malformed at "T12:23:12.272+0000".', |
| 341 | data_win_eventdata_sourceProcessId: "1652", |
| 342 | message: |
| 343 | '{"true":1699186992.277071,"timestamp":"2023-11-05T12:23:12.272+0000","rule":{"level":12,"description":"Explorer process was accessed by C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe, possible process injection","id":"92910","mitre":{"id":["T1055"],"tactic":["Defense Evasion","Privilege Escalation"],"technique":["Process Injection"]},"firedtimes":32,"mail":true,"groups":["sysmon","sysmon_eid10_detections","windows"]},"agent":{"id":"070","name":"web1","ip":"202.43.110.138","labels":{"customer":"wso4vxhq"}},"manager":{"name":"ASHWZHMA"},"id":"1699186992.695678238","decoder":{"name":"windows_eventchannel"},"data":{"win":{"system":{"providerName":"Microsoft-Windows-Sysmon","providerGuid":"{5770385f-c22a-43e0-bf4c-06f5698ffbd9}","eventID":"10","version":"3","level":"4","task":"10","opcode":"0","keywords":"0x8000000000000000","systemTime":"2023-11-05T12:23:11.139039000Z","eventRecordID":"4878783","processID":"3468","threadID":"5576","channel":"Microsoft-Windows-Sysmon/Operational","computer":"web1","severityValue":"INFORMATION","message":"\\"Process accessed:\\r\\nRuleName: technique_id=T1036,technique_name=Masquerading\\r\\nUtcTime: 2023-11-05 12:23:11.137\\r\\nSourceProcessGUID: {d9ab9ebb-7e1a-6544-44e0-010000003000}\\r\\nSourceProcessId: 1652\\r\\nSourceThreadId: 1284\\r\\nSourceImage: C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe\\r\\nTargetProcessGUID: {d9ab9ebb-62bb-6547-601c-020000003000}\\r\\nTargetProcessId: 4384\\r\\nTargetImage: C:\\\\Windows\\\\explorer.exe\\r\\nGrantedAccess: 0x40\\r\\nCallTrace: C:\\\\Windows\\\\SYSTEM32\\\\ntdll.dll+9ff24|C:\\\\Windows\\\\System32\\\\KERNELBASE.dll+1668e|C:\\\\Windows\\\\System32\\\\shcore.dll+cca8|C:\\\\Windows\\\\System32\\\\shcore.dll+ba62|C:\\\\Windows\\\\System32\\\\shcore.dll+b585|C:\\\\Windows\\\\System32\\\\shcore.dll+b275|C:\\\\Windows\\\\System32\\\\shcore.dll+b209|C:\\\\Windows\\\\System32\\\\shcore.dll+b104|C:\\\\Windows\\\\system32\\\\explorerframe.dll+12b986|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+157bd8c|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+18051ce|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2e1a17|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2dfdfe|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+130216a|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a566ec|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a5695f|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3e93b|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c40433|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb8e|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3d62541|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb68|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c942dd|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3db94|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a52491\\r\\nSourceUser: WEB1\\\\Administrator\\r\\nTargetUser: WEB1\\\\Administrator\\""},"eventdata":{"ruleName":"technique_id=T1036,technique_name=Masquerading","utcTime":"2023-11-05 12:23:11.137","sourceProcessGUID":"{d9ab9ebb-7e1a-6544-44e0-010000003000}","sourceProcessId":"1652","sourceThreadId":"1284","sourceImage":"C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe","targetProcessGUID":"{d9ab9ebb-62bb-6547-601c-020000003000}","targetProcessId":"4384","targetImage":"C:\\\\\\\\Windows\\\\\\\\explorer.exe","grantedAccess":"0x40","callTrace":"C:\\\\\\\\Windows\\\\\\\\SYSTEM32\\\\\\\\ntdll.dll+9ff24|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\KERNELBASE.dll+1668e|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+cca8|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+ba62|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+b585|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+b275|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+b209|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+b104|C:\\\\\\\\Windows\\\\\\\\system32\\\\\\\\explorerframe.dll+12b986|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+157bd8c|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+18051ce|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+2e1a17|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+2dfdfe|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+130216a|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+a566ec|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+a5695f|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c3e93b|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c40433|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3fbdb8e|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3d62541|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3fbdb68|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c942dd|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c3db94|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+a52491","sourceUser":"WEB1\\\\\\\\Administrator","targetUser":"WEB1\\\\\\\\Administrator"}}},"location":"EventChannel"}', |
| 344 | rule_id: "92910", |
| 345 | manager_name: "ASHWZHMA", |
| 346 | location: "EventChannel", |
| 347 | data_win_eventdata_targetProcessId: "4384", |
| 348 | rule_group3: AlertSourceDataLogsourceProduct.Windows, |
| 349 | data_win_system_message: |
| 350 | '"Process accessed:\r\nRuleName: technique_id=T1036,technique_name=Masquerading\r\nUtcTime: 2023-11-05 12:23:11.137\r\nSourceProcessGUID: {d9ab9ebb-7e1a-6544-44e0-010000003000}\r\nSourceProcessId: 1652\r\nSourceThreadId: 1284\r\nSourceImage: C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe\r\nTargetProcessGUID: {d9ab9ebb-62bb-6547-601c-020000003000}\r\nTargetProcessId: 4384\r\nTargetImage: C:\\Windows\\explorer.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+9ff24|C:\\Windows\\System32\\KERNELBASE.dll+1668e|C:\\Windows\\System32\\shcore.dll+cca8|C:\\Windows\\System32\\shcore.dll+ba62|C:\\Windows\\System32\\shcore.dll+b585|C:\\Windows\\System32\\shcore.dll+b275|C:\\Windows\\System32\\shcore.dll+b209|C:\\Windows\\System32\\shcore.dll+b104|C:\\Windows\\system32\\explorerframe.dll+12b986|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+157bd8c|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+18051ce|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+2e1a17|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+2dfdfe|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+130216a|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+a566ec|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+a5695f|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c3e93b|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c40433|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3fbdb8e|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3d62541|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3fbdb68|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c942dd|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c3db94|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+a52491\r\nSourceUser: WEB1\\Administrator\r\nTargetUser: WEB1\\Administrator"', |
| 351 | data_win_eventdata_sourceThreadId: "1284", |
| 352 | msg_timestamp: "2023-11-05T12:23:12.272Z", |
| 353 | rule_group2: "sysmon_eid10_detections", |
| 354 | rule_group1: "sysmon" |
| 355 | }, |
| 356 | sort: [1699186991139] |
| 357 | }, |
| 358 | { |
| 359 | _index: "wazuh-wso4vxhq_7", |
| 360 | _id: "18e98900-7bd6-11ee-93bc-86000046278a", |
| 361 | _score: null, |
| 362 | _source: { |
| 363 | source_reserved_ip: true, |
| 364 | data_win_system_eventRecordID: "4878782", |
| 365 | agent_id: "070", |
| 366 | agent_name: "web1", |
| 367 | data_win_eventdata_sourceProcessGUID: "{d9ab9ebb-7e1a-6544-44e0-010000003000}", |
| 368 | gl2_remote_ip: "10.255.255.13", |
| 369 | data_win_system_eventID: "10", |
| 370 | gl2_remote_port: 60342, |
| 371 | agent_labels_customer: "wso4vxhq", |
| 372 | agent_ip_city_name: "N/A", |
| 373 | source: "10.255.255.13", |
| 374 | data_win_eventdata_targetImage: "C:\\\\Windows\\\\explorer.exe", |
| 375 | gl2_source_input: "6459151dea00fd5d3da2df91", |
| 376 | rule_level: 12, |
| 377 | data_win_eventdata_sourceUser: "WEB1\\\\Administrator", |
| 378 | data_win_system_task: "10", |
| 379 | timestamp_utc: "2023-11-05T12:23:11.138Z", |
| 380 | syslog_type: AlertSourceSyslogType.Wazuh, |
| 381 | data_win_system_threadID: "5576", |
| 382 | rule_description: |
| 383 | "Explorer process was accessed by C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe, possible process injection", |
| 384 | gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38", |
| 385 | id: "1699186992.695672487", |
| 386 | data_win_eventdata_grantedAccess: "0x40", |
| 387 | data_win_eventdata_sourceImage: |
| 388 | "C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe", |
| 389 | rule_mitre_tactic: "Defense Evasion, Privilege Escalation", |
| 390 | gl2_accounted_message_size: 11630, |
| 391 | data_win_eventdata_utcTime: "2023-11-05 12:23:11.137", |
| 392 | streams: ["650d3da25e9a2d550c6d6491"], |
| 393 | rule_mitre_id: "T1055", |
| 394 | gl2_message_id: "01HEFPZXCH0JEEF6TT8BQK4XJR", |
| 395 | data_win_system_computer: "web1", |
| 396 | data_win_eventdata_ruleName: "technique_id=T1036,technique_name=Masquerading", |
| 397 | agent_ip: "202.43.110.138", |
| 398 | true: 1699186992.273304, |
| 399 | rule_groups: "sysmon, sysmon_eid10_detections, windows", |
| 400 | data_win_system_keywords: "0x8000000000000000", |
| 401 | data_win_system_level: "4", |
| 402 | data_win_eventdata_targetProcessGUID: "{d9ab9ebb-62bb-6547-601c-020000003000}", |
| 403 | data_win_system_severityValue: AlertSourceDataWinSystemSeverityValue.Information, |
| 404 | data_win_eventdata_targetUser: "WEB1\\\\Administrator", |
| 405 | agent_ip_geolocation: "16.1667,107.8333", |
| 406 | rule_mitre_technique: "Process Injection", |
| 407 | rule_firedtimes: 31, |
| 408 | data_win_system_systemTime: "2023-11-05T12:23:11.138753100Z", |
| 409 | rule_mail: true, |
| 410 | decoder_name: AlertSourceDecoderName.WindowsEventchannel, |
| 411 | agent_ip_country_code: "VN", |
| 412 | data_win_system_processID: "3468", |
| 413 | data_win_system_channel: "Microsoft-Windows-Sysmon/Operational", |
| 414 | syslog_level: AlertSourceSyslogLevel.Alert, |
| 415 | data_win_system_providerName: "Microsoft-Windows-Sysmon", |
| 416 | data_win_system_version: "3", |
| 417 | data_win_system_providerGuid: "{5770385f-c22a-43e0-bf4c-06f5698ffbd9}", |
| 418 | timestamp: "2023-11-05 12:23:16.625", |
| 419 | data_win_eventdata_callTrace: |
| 420 | "C:\\\\Windows\\\\SYSTEM32\\\\ntdll.dll+9ff24|C:\\\\Windows\\\\System32\\\\KERNELBASE.dll+1668e|C:\\\\Windows\\\\System32\\\\shcore.dll+cca8|C:\\\\Windows\\\\System32\\\\shcore.dll+b55c|C:\\\\Windows\\\\System32\\\\shcore.dll+b275|C:\\\\Windows\\\\System32\\\\shcore.dll+b209|C:\\\\Windows\\\\System32\\\\shcore.dll+b104|C:\\\\Windows\\\\system32\\\\explorerframe.dll+12b986|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+157bd8c|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+18051ce|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2e1a17|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2dfdfe|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+130216a|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a566ec|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a5695f|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3e93b|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c40433|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb8e|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3d62541|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb68|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c942dd|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3db94|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a52491|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a3e4a9", |
| 421 | data_win_system_opcode: "0", |
| 422 | gl2_processing_error: |
| 423 | 'Replaced invalid timestamp value in message <18e98900-7bd6-11ee-93bc-86000046278a> with current time - Value <2023-11-05T12:23:12.272+0000> caused exception: Invalid format: "2023-11-05T12:23:12.272+0000" is malformed at "T12:23:12.272+0000".', |
| 424 | data_win_eventdata_sourceProcessId: "1652", |
| 425 | message: |
| 426 | '{"true":1699186992.273304,"timestamp":"2023-11-05T12:23:12.272+0000","rule":{"level":12,"description":"Explorer process was accessed by C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe, possible process injection","id":"92910","mitre":{"id":["T1055"],"tactic":["Defense Evasion","Privilege Escalation"],"technique":["Process Injection"]},"firedtimes":31,"mail":true,"groups":["sysmon","sysmon_eid10_detections","windows"]},"agent":{"id":"070","name":"web1","ip":"202.43.110.138","labels":{"customer":"wso4vxhq"}},"manager":{"name":"ASHWZHMA"},"id":"1699186992.695672487","decoder":{"name":"windows_eventchannel"},"data":{"win":{"system":{"providerName":"Microsoft-Windows-Sysmon","providerGuid":"{5770385f-c22a-43e0-bf4c-06f5698ffbd9}","eventID":"10","version":"3","level":"4","task":"10","opcode":"0","keywords":"0x8000000000000000","systemTime":"2023-11-05T12:23:11.138753100Z","eventRecordID":"4878782","processID":"3468","threadID":"5576","channel":"Microsoft-Windows-Sysmon/Operational","computer":"web1","severityValue":"INFORMATION","message":"\\"Process accessed:\\r\\nRuleName: technique_id=T1036,technique_name=Masquerading\\r\\nUtcTime: 2023-11-05 12:23:11.137\\r\\nSourceProcessGUID: {d9ab9ebb-7e1a-6544-44e0-010000003000}\\r\\nSourceProcessId: 1652\\r\\nSourceThreadId: 1284\\r\\nSourceImage: C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe\\r\\nTargetProcessGUID: {d9ab9ebb-62bb-6547-601c-020000003000}\\r\\nTargetProcessId: 4384\\r\\nTargetImage: C:\\\\Windows\\\\explorer.exe\\r\\nGrantedAccess: 0x40\\r\\nCallTrace: C:\\\\Windows\\\\SYSTEM32\\\\ntdll.dll+9ff24|C:\\\\Windows\\\\System32\\\\KERNELBASE.dll+1668e|C:\\\\Windows\\\\System32\\\\shcore.dll+cca8|C:\\\\Windows\\\\System32\\\\shcore.dll+b55c|C:\\\\Windows\\\\System32\\\\shcore.dll+b275|C:\\\\Windows\\\\System32\\\\shcore.dll+b209|C:\\\\Windows\\\\System32\\\\shcore.dll+b104|C:\\\\Windows\\\\system32\\\\explorerframe.dll+12b986|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+157bd8c|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+18051ce|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2e1a17|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2dfdfe|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+130216a|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a566ec|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a5695f|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3e93b|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c40433|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb8e|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3d62541|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb68|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c942dd|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3db94|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a52491|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a3e4a9\\r\\nSourceUser: WEB1\\\\Administrator\\r\\nTargetUser: WEB1\\\\Administrator\\""},"eventdata":{"ruleName":"technique_id=T1036,technique_name=Masquerading","utcTime":"2023-11-05 12:23:11.137","sourceProcessGUID":"{d9ab9ebb-7e1a-6544-44e0-010000003000}","sourceProcessId":"1652","sourceThreadId":"1284","sourceImage":"C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe","targetProcessGUID":"{d9ab9ebb-62bb-6547-601c-020000003000}","targetProcessId":"4384","targetImage":"C:\\\\\\\\Windows\\\\\\\\explorer.exe","grantedAccess":"0x40","callTrace":"C:\\\\\\\\Windows\\\\\\\\SYSTEM32\\\\\\\\ntdll.dll+9ff24|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\KERNELBASE.dll+1668e|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+cca8|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+b55c|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+b275|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+b209|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+b104|C:\\\\\\\\Windows\\\\\\\\system32\\\\\\\\explorerframe.dll+12b986|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+157bd8c|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+18051ce|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+2e1a17|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+2dfdfe|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+130216a|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+a566ec|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+a5695f|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c3e93b|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c40433|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3fbdb8e|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3d62541|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3fbdb68|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c942dd|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c3db94|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+a52491|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+a3e4a9","sourceUser":"WEB1\\\\\\\\Administrator","targetUser":"WEB1\\\\\\\\Administrator"}}},"location":"EventChannel"}', |
| 427 | rule_id: "92910", |
| 428 | manager_name: "ASHWZHMA", |
| 429 | location: "EventChannel", |
| 430 | data_win_eventdata_targetProcessId: "4384", |
| 431 | rule_group3: AlertSourceDataLogsourceProduct.Windows, |
| 432 | data_win_system_message: |
| 433 | '"Process accessed:\r\nRuleName: technique_id=T1036,technique_name=Masquerading\r\nUtcTime: 2023-11-05 12:23:11.137\r\nSourceProcessGUID: {d9ab9ebb-7e1a-6544-44e0-010000003000}\r\nSourceProcessId: 1652\r\nSourceThreadId: 1284\r\nSourceImage: C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe\r\nTargetProcessGUID: {d9ab9ebb-62bb-6547-601c-020000003000}\r\nTargetProcessId: 4384\r\nTargetImage: C:\\Windows\\explorer.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+9ff24|C:\\Windows\\System32\\KERNELBASE.dll+1668e|C:\\Windows\\System32\\shcore.dll+cca8|C:\\Windows\\System32\\shcore.dll+b55c|C:\\Windows\\System32\\shcore.dll+b275|C:\\Windows\\System32\\shcore.dll+b209|C:\\Windows\\System32\\shcore.dll+b104|C:\\Windows\\system32\\explorerframe.dll+12b986|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+157bd8c|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+18051ce|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+2e1a17|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+2dfdfe|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+130216a|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+a566ec|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+a5695f|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c3e93b|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c40433|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3fbdb8e|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3d62541|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3fbdb68|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c942dd|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c3db94|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+a52491|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+a3e4a9\r\nSourceUser: WEB1\\Administrator\r\nTargetUser: WEB1\\Administrator"', |
| 434 | data_win_eventdata_sourceThreadId: "1284", |
| 435 | msg_timestamp: "2023-11-05T12:23:12.272Z", |
| 436 | rule_group2: "sysmon_eid10_detections", |
| 437 | rule_group1: "sysmon" |
| 438 | }, |
| 439 | sort: [1699186991138] |
| 440 | } |
| 441 | ] |
| 442 | }, |
| 443 | { |
| 444 | index_name: "wazuh-zaff3p5c_0", |
| 445 | total_alerts: 1, |
| 446 | alerts: [ |
| 447 | { |
| 448 | _index: "wazuh-zaff3p5c_0", |
| 449 | _id: "4978eea4-7bc5-11ee-93bc-86000046278a", |
| 450 | _score: null, |
| 451 | _source: { |
| 452 | parent_process_id: "3565733", |
| 453 | source_reserved_ip: true, |
| 454 | agent_id: "072", |
| 455 | agent_name: "ip-178-216-201-141", |
| 456 | gl2_remote_ip: "10.255.255.13", |
| 457 | gl2_remote_port: 46242, |
| 458 | agent_labels_customer: "zaff3p5c", |
| 459 | agent_ip_city_name: "N/A", |
| 460 | source: "10.255.255.13", |
| 461 | gl2_source_input: "6459151dea00fd5d3da2df91", |
| 462 | rule_level: 12, |
| 463 | data_calendarTime: "Sun Nov 5 10:22:52 2023 UTC", |
| 464 | data_counter: "8287", |
| 465 | data_columns_duration: "132210", |
| 466 | timestamp_utc: "2023-11-05T10:22:52.000Z", |
| 467 | syslog_type: AlertSourceSyslogType.Wazuh, |
| 468 | process_name: "/usr/bin/chmod", |
| 469 | process_cmd_line: "chmod +r /var/lib/update-notifier/updates-available", |
| 470 | data_hostIdentifier: "ip-178-216-201-141", |
| 471 | data_columns_probe_error: "0", |
| 472 | rule_description: "Detects file and folder permission changes.", |
| 473 | gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38", |
| 474 | id: "1699179774.599228705", |
| 475 | rule_mitre_tactic: "Defense Evasion", |
| 476 | process_image: "/usr/bin/chmod", |
| 477 | gl2_accounted_message_size: 2584, |
| 478 | data_columns_uid: "0", |
| 479 | streams: ["651176ee5e9a2d550c79fa32"], |
| 480 | rule_mitre_id: "T1222", |
| 481 | gl2_message_id: "01HEFG3JMB8FK2YN4EYWBQ5FSS", |
| 482 | agent_ip: "178.216.201.141", |
| 483 | data_columns_gid: "0", |
| 484 | data_columns_syscall: "exec", |
| 485 | true: 1699179774.197991, |
| 486 | data_columns_cid: "30181", |
| 487 | rule_groups: "osquery, bpf_process_events", |
| 488 | data_columns_exit_code: "0", |
| 489 | process_id: "3565780", |
| 490 | agent_ip_geolocation: "52.2394,21.0362", |
| 491 | rule_mitre_technique: "File and Directory Permissions Modification", |
| 492 | rule_firedtimes: 1, |
| 493 | rule_mail: true, |
| 494 | data_name: "bpf_process_events", |
| 495 | decoder_name: AlertSourceDecoderName.JSON, |
| 496 | agent_ip_country_code: "PL", |
| 497 | data_columns_ntime: "3515969404589692", |
| 498 | syslog_level: AlertSourceSyslogLevel.Alert, |
| 499 | timestamp: "2023-11-05 10:22:56.651", |
| 500 | data_columns_cmdline: "chmod +r /var/lib/update-notifier/updates-available", |
| 501 | data_columns_tid: "3565780", |
| 502 | gl2_processing_error: |
| 503 | 'Replaced invalid timestamp value in message <4978eea4-7bc5-11ee-93bc-86000046278a> with current time - Value <2023-11-05T10:22:54.197+0000> caused exception: Invalid format: "2023-11-05T10:22:54.197+0000" is malformed at "T10:22:54.197+0000".', |
| 504 | data_columns_pid: "3565780", |
| 505 | message: |
| 506 | '{"true":1699179774.197991,"timestamp":"2023-11-05T10:22:54.197+0000","rule":{"level":12,"description":"Detects file and folder permission changes.","id":"200259","mitre":{"id":["T1222"],"tactic":["Defense Evasion"],"technique":["File and Directory Permissions Modification"]},"firedtimes":1,"mail":true,"groups":["osquery","bpf_process_events"]},"agent":{"id":"072","name":"ip-178-216-201-141","ip":"178.216.201.141","labels":{"customer":"zaff3p5c"}},"manager":{"name":"ASHWZHMA"},"id":"1699179774.599228705","decoder":{"name":"json"},"data":{"action":"added","name":"bpf_process_events","hostIdentifier":"ip-178-216-201-141","calendarTime":"Sun Nov 5 10:22:52 2023 UTC","unixTime":"1699179772","epoch":"0","counter":"8287","numerics":"false","columns":{"cid":"30181","cmdline":"chmod +r /var/lib/update-notifier/updates-available","duration":"132210","exit_code":"0","gid":"0","ntime":"3515969404589692","parent":"3565733","path":"/usr/bin/chmod","pid":"3565780","probe_error":"0","syscall":"exec","tid":"3565780","uid":"0"}},"location":"/var/log/osquery/osqueryd.results.log"}', |
| 507 | data_numerics: "false", |
| 508 | rule_id: "200259", |
| 509 | manager_name: "ASHWZHMA", |
| 510 | data_columns_path: "/usr/bin/chmod", |
| 511 | data_unixTime: "1699179772", |
| 512 | data_action: "added", |
| 513 | data_epoch: "0", |
| 514 | location: "/var/log/osquery/osqueryd.results.log", |
| 515 | data_columns_parent: "3565733", |
| 516 | msg_timestamp: "2023-11-05T10:22:54.197Z", |
| 517 | rule_group2: "bpf_process_events", |
| 518 | rule_group1: "osquery" |
| 519 | }, |
| 520 | sort: [1699179772000] |
| 521 | } |
| 522 | ] |
| 523 | }, |
| 524 | { |
| 525 | index_name: "wazuh_00002_201", |
| 526 | total_alerts: 5, |
| 527 | alerts: [ |
| 528 | { |
| 529 | _index: "wazuh_00002_201", |
| 530 | _id: "366ba9a0-7bd5-11ee-93bc-86000046278a", |
| 531 | _score: null, |
| 532 | _source: { |
| 533 | data_system_Task: "11", |
| 534 | source_reserved_ip: true, |
| 535 | agent_id: "097", |
| 536 | agent_name: "ANSYDWDC01", |
| 537 | data_system_Correlation: "null", |
| 538 | gl2_remote_ip: "10.255.255.13", |
| 539 | gl2_remote_port: 50678, |
| 540 | agent_labels_customer: "00002", |
| 541 | data_system_Version: "2", |
| 542 | agent_ip_city_name: "Singapore", |
| 543 | source: "10.255.255.13", |
| 544 | gl2_source_input: "6459151dea00fd5d3da2df91", |
| 545 | rule_level: 12, |
| 546 | data_level: AlertSourceDataLevelEnum.High, |
| 547 | timestamp_utc: "2023-11-05T12:16:02.043Z", |
| 548 | data_event_ProcessId: "4684", |
| 549 | syslog_type: AlertSourceSyslogType.Wazuh, |
| 550 | data_system_Opcode: "0", |
| 551 | rule_description: "Process Explorer Driver Creation By Non-Sysinternals Binary", |
| 552 | gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38", |
| 553 | id: "1699186616.690805701", |
| 554 | data_status: AlertSourceDataStatus.Experimental, |
| 555 | data_system_Computer: "ANSYDWDC01.ANMS.LOCAL", |
| 556 | gl2_accounted_message_size: 10712, |
| 557 | data_document: |
| 558 | '{"kind":"evtx","path":"C:\\\\Windows\\\\System32\\\\winevt\\\\Logs\\\\Microsoft-Windows-Sysmon%4Operational.evtx","data":{"Event":{"EventData":{"CreationUtcTime":"2023-11-01 06:52:11.733","Image":"C:\\\\Program Files\\\\socfortress\\\\sysinternals\\\\logonsessions64.exe","ProcessGuid":"6D0AAEFA-8781-6547-C4BB-000000004200","ProcessId":4684,"RuleName":"-","TargetFilename":"C:\\\\Windows\\\\System32\\\\drivers\\\\PROCEXP152.SYS","User":"NT AUTHORITY\\\\SYSTEM","UtcTime":"2023-11-05 12:16:02.043"},"System":{"Channel":"Microsoft-Windows-Sysmon/Operational","Computer":"ANSYDWDC01.ANMS.LOCAL","Correlation":null,"EventID":11,"EventRecordID":18141034,"Execution_attributes":{"ProcessID":2564,"ThreadID":3804},"Keywords":"0x8000000000000000","Level":4,"Opcode":0,"Provider_attributes":{"Guid":"5770385F-C22A-43E0-BF4C-06F5698FFBD9","Name":"Microsoft-Windows-Sysmon"},"Security_attributes":{"UserID":"S-1-5-18"},"Task":11,"TimeCreated_attributes":{"SystemTime":"2023-11-05T12:16:02.045670Z"},"Version":2}},"Event_attributes":{"xmlns":"http://schemas.microsoft.com/win/2004/08/events/event"}}}', |
| 559 | data_event_UtcTime: "2023-11-05 12:16:02.043", |
| 560 | streams: ["645a3a6123e5cc30bbc0e5dc"], |
| 561 | gl2_message_id: "01HEFPMAE4N8YW57K4Q6P44CKB", |
| 562 | data_source: AlertSourceDataLogsourceProduct.Sigma, |
| 563 | agent_ip: "139.180.134.102", |
| 564 | data_system_Security_attributes_UserID: "S-1-5-18", |
| 565 | true: 1699186616.142398, |
| 566 | data_timestamp: "2023-11-05T12:16:02.045670+00:00", |
| 567 | data_system_Level: "4", |
| 568 | data_event_CreationUtcTime: "2023-11-01 06:52:11.733", |
| 569 | data_system_Execution_attributes_ProcessID: "2564", |
| 570 | rule_groups: "windows, chainsaw, sigma", |
| 571 | data_system_EventRecordID: "18141034", |
| 572 | process_id: "4684", |
| 573 | data_system_TimeCreated_attributes_SystemTime: "2023-11-05T12:16:02.045670Z", |
| 574 | data_event_RuleName: "-", |
| 575 | data_logsource_category: AlertSourceDataLogsourceCategory.FileEvent, |
| 576 | data_system_Keywords: "0x8000000000000000", |
| 577 | sigma_name_encoded: "Process%20Explorer%20Driver%20Creation%20By%20Non-Sysinternals%20Binary", |
| 578 | agent_ip_geolocation: "1.3078,103.6818", |
| 579 | data_group: AlertSourceDataGroup.Sigma, |
| 580 | rule_firedtimes: 1, |
| 581 | data_event_User: "NT AUTHORITY\\SYSTEM", |
| 582 | data_path: "C:\\Windows\\System32\\winevt\\Logs\\Microsoft-Windows-Sysmon%4Operational.evtx", |
| 583 | rule_mail: true, |
| 584 | data_system_Provider_attributes_Name: "Microsoft-Windows-Sysmon", |
| 585 | data_name: "Process Explorer Driver Creation By Non-Sysinternals Binary", |
| 586 | decoder_name: AlertSourceDecoderName.JSON, |
| 587 | data_id: "de46c52b-0bf8-4936-a327-aace94f94ac6", |
| 588 | agent_ip_country_code: "SG", |
| 589 | syslog_level: AlertSourceSyslogLevel.Alert, |
| 590 | data_tags: "attack.persistence, attack.privilege_escalation, attack.t1068", |
| 591 | data_kind: AlertSourceDataKind.Individual, |
| 592 | data_logsource_product: AlertSourceDataLogsourceProduct.Windows, |
| 593 | timestamp: "2023-11-05 12:16:56.772", |
| 594 | ask_socfortress_message: |
| 595 | "The SIGMA alert \"Process Explorer Driver Creation By Non-Sysinternals Binary\" suggests that a non-Sysinternals binary has attempted to create a Process Explorer driver on a Windows endpoint. Process Explorer is a widely used system monitoring tool developed by Sysinternals (now part of Microsoft). The creation of a Process Explorer driver by a non-Sysinternals binary could indicate suspicious or potentially malicious activity.\n\nTo investigate this alert and determine an appropriate response, you should focus on the following key aspects:\n\n1. Validate the Alert: Verify the accuracy of the alert by checking if it was triggered by legitimate activity or if it is a false positive. Ensure that your detection system is properly configured and up to date.\n\n2. Identify the Binary: Determine which specific binary attempted to create the Process Explorer driver. Look for any unusual or suspicious characteristics such as unfamiliar names, file paths, digital signatures, or hash values.\n\n3. Analyze Process Execution Context: Investigate the context in which the binary executed and attempted to create the driver. Review process execution details, such as parent processes, command-line arguments, process creation time, and associated network connections.\n\n4. Assess System Impact: Evaluate whether any abnormal behavior occurred on the endpoint after this event took place. Look for signs of system instability, crashes, performance degradation, or other anomalous activities that may indicate malicious intent.\n\n5. Conduct File Analysis: Perform an in-depth analysis of the binary itself using appropriate tools like antivirus scanners and sandboxing environments to identify any malware indicators such as malicious code patterns or known signatures associated with malware families.\n\n6. Check Reputation: Research information about the binary's reputation online using threat intelligence platforms, virus total scanners, or security forums to determine if it has been previously identified as malicious.\n\n7. Perform Behavioral Analysis: If feasible, conduct dynamic analysis by executing the binary in an isolated environment while monitoring its behavior for any suspicious activities like network communication, file system changes, or attempts to escalate privileges.\n\n8. Review System Logs: Examine relevant logs such as event logs, process creation logs, driver loading logs, and network logs to identify any additional indicators of compromise or related activities.\n\nWhen assessing this alert, you should also ask yourself the following additional questions:\n\n1. Is the binary a legitimate tool that is commonly used in your organization? If not, why would it be present on the endpoint?\n\n2. Is there a business justification for creating a Process Explorer driver with this specific binary? Are there any documented cases or known legitimate reasons for doing so?\n\n3. Are there any other security events or alerts related to this binary or associated processes that can provide further context?\n\n4. Has the binary been whitelisted or approved by your organization's security policies? If not, why was it allowed to execute on the endpoint?\n\n5. Do you have sufficient visibility into other endpoints within your environment? Have similar events been observed elsewhere? This could indicate a larger-scale attack.\n\nRemember that each investigation may vary based on your organization's specific context and requirements.", |
| 596 | data_system_Channel: "Microsoft-Windows-Sysmon/Operational", |
| 597 | data_references: |
| 598 | "https://learn.microsoft.com/en-us/sysinternals/downloads/process-explorer, https://github.com/Yaxser/Backstab, https://www.elastic.co/security-labs/stopping-vulnerable-driver-attacks, https://news.sophos.com/en-us/2023/04/19/aukill-edr-killer-malware-abuses-process-explorer-driver/", |
| 599 | data_event_ProcessGuid: "6D0AAEFA-8781-6547-C4BB-000000004200", |
| 600 | gl2_processing_error: |
| 601 | 'Replaced invalid timestamp value in message <366ba9a0-7bd5-11ee-93bc-86000046278a> with current time - Value <2023-11-05T12:16:56.030+0000> caused exception: Invalid format: "2023-11-05T12:16:56.030+0000" is malformed at "T12:16:56.030+0000".', |
| 602 | data_falsepositives: |
| 603 | "Some false positives may occur with legitimate renamed process explorer binaries", |
| 604 | data_event_Image: "C:\\Program Files\\socfortress\\sysinternals\\logonsessions64.exe", |
| 605 | data_system_Execution_attributes_ThreadID: "3804", |
| 606 | message: |
| 607 | '{"true":1699186616.142398,"timestamp":"2023-11-05T12:16:56.030+0000","rule":{"level":12,"description":"Process Explorer Driver Creation By Non-Sysinternals Binary","id":"200051","firedtimes":1,"mail":true,"groups":["windows","chainsaw","sigma"]},"agent":{"id":"097","name":"ANSYDWDC01","ip":"139.180.134.102","labels":{"customer":"00002"}},"manager":{"name":"ASHWZHMA"},"id":"1699186616.690805701","decoder":{"name":"json"},"data":{"id":"de46c52b-0bf8-4936-a327-aace94f94ac6","status":"experimental","group":"Sigma","kind":"individual","document":"{\\"kind\\":\\"evtx\\",\\"path\\":\\"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\winevt\\\\\\\\Logs\\\\\\\\Microsoft-Windows-Sysmon%4Operational.evtx\\",\\"data\\":{\\"Event\\":{\\"EventData\\":{\\"CreationUtcTime\\":\\"2023-11-01 06:52:11.733\\",\\"Image\\":\\"C:\\\\\\\\Program Files\\\\\\\\socfortress\\\\\\\\sysinternals\\\\\\\\logonsessions64.exe\\",\\"ProcessGuid\\":\\"6D0AAEFA-8781-6547-C4BB-000000004200\\",\\"ProcessId\\":4684,\\"RuleName\\":\\"-\\",\\"TargetFilename\\":\\"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\drivers\\\\\\\\PROCEXP152.SYS\\",\\"User\\":\\"NT AUTHORITY\\\\\\\\SYSTEM\\",\\"UtcTime\\":\\"2023-11-05 12:16:02.043\\"},\\"System\\":{\\"Channel\\":\\"Microsoft-Windows-Sysmon/Operational\\",\\"Computer\\":\\"ANSYDWDC01.ANMS.LOCAL\\",\\"Correlation\\":null,\\"EventID\\":11,\\"EventRecordID\\":18141034,\\"Execution_attributes\\":{\\"ProcessID\\":2564,\\"ThreadID\\":3804},\\"Keywords\\":\\"0x8000000000000000\\",\\"Level\\":4,\\"Opcode\\":0,\\"Provider_attributes\\":{\\"Guid\\":\\"5770385F-C22A-43E0-BF4C-06F5698FFBD9\\",\\"Name\\":\\"Microsoft-Windows-Sysmon\\"},\\"Security_attributes\\":{\\"UserID\\":\\"S-1-5-18\\"},\\"Task\\":11,\\"TimeCreated_attributes\\":{\\"SystemTime\\":\\"2023-11-05T12:16:02.045670Z\\"},\\"Version\\":2}},\\"Event_attributes\\":{\\"xmlns\\":\\"http://schemas.microsoft.com/win/2004/08/events/event\\"}}}","event":{"CreationUtcTime":"2023-11-01 06:52:11.733","Image":"C:\\\\Program Files\\\\socfortress\\\\sysinternals\\\\logonsessions64.exe","ProcessGuid":"6D0AAEFA-8781-6547-C4BB-000000004200","ProcessId":"4684","RuleName":"-","TargetFilename":"C:\\\\Windows\\\\System32\\\\drivers\\\\PROCEXP152.SYS","User":"NT AUTHORITY\\\\SYSTEM","UtcTime":"2023-11-05 12:16:02.043"},"path":"C:\\\\Windows\\\\System32\\\\winevt\\\\Logs\\\\Microsoft-Windows-Sysmon%4Operational.evtx","system":{"Channel":"Microsoft-Windows-Sysmon/Operational","Computer":"ANSYDWDC01.ANMS.LOCAL","Correlation":"null","EventID":"11","EventRecordID":"18141034","Execution_attributes":{"ProcessID":"2564","ThreadID":"3804"},"Keywords":"0x8000000000000000","Level":"4","Opcode":"0","Provider_attributes":{"Guid":"5770385F-C22A-43E0-BF4C-06F5698FFBD9","Name":"Microsoft-Windows-Sysmon"},"Security_attributes":{"UserID":"S-1-5-18"},"Task":"11","TimeCreated_attributes":{"SystemTime":"2023-11-05T12:16:02.045670Z"},"Version":"2"},"name":"Process Explorer Driver Creation By Non-Sysinternals Binary","timestamp":"2023-11-05T12:16:02.045670+00:00","authors":["Florian Roth (Nextron Systems)"],"level":"high","source":"sigma","falsepositives":["Some false positives may occur with legitimate renamed process explorer binaries"],"logsource":{"category":"file_event","product":"windows"},"references":["https://learn.microsoft.com/en-us/sysinternals/downloads/process-explorer","https://github.com/Yaxser/Backstab","https://www.elastic.co/security-labs/stopping-vulnerable-driver-attacks","https://news.sophos.com/en-us/2023/04/19/aukill-edr-killer-malware-abuses-process-explorer-driver/"],"tags":["attack.persistence","attack.privilege_escalation","attack.t1068"]},"location":"active-response\\\\active-responses.log"}', |
| 608 | data_system_EventID: "11", |
| 609 | data_system_Provider_attributes_Guid: "5770385F-C22A-43E0-BF4C-06F5698FFBD9", |
| 610 | rule_id: "200051", |
| 611 | manager_name: "ASHWZHMA", |
| 612 | data_event_TargetFilename: "C:\\Windows\\System32\\drivers\\PROCEXP152.SYS", |
| 613 | location: "active-response\\active-responses.log", |
| 614 | data_authors: "Florian Roth (Nextron Systems)", |
| 615 | rule_group3: AlertSourceDataLogsourceProduct.Sigma, |
| 616 | msg_timestamp: "2023-11-05T12:16:56.030Z", |
| 617 | rule_group2: "chainsaw", |
| 618 | rule_group1: "windows" |
| 619 | }, |
| 620 | sort: [1699186562043] |
| 621 | }, |
| 622 | { |
| 623 | _index: "wazuh_00002_201", |
| 624 | _id: "2e1383c2-7bd7-11ee-93bc-86000046278a", |
| 625 | _score: null, |
| 626 | _source: { |
| 627 | data_system_Task: "11", |
| 628 | source_reserved_ip: true, |
| 629 | agent_id: "097", |
| 630 | agent_name: "ANSYDWDC01", |
| 631 | data_system_Correlation: "null", |
| 632 | gl2_remote_ip: "10.255.255.13", |
| 633 | gl2_remote_port: 35304, |
| 634 | agent_labels_customer: "00002", |
| 635 | data_system_Version: "2", |
| 636 | agent_ip_city_name: "Singapore", |
| 637 | source: "10.255.255.13", |
| 638 | gl2_source_input: "6459151dea00fd5d3da2df91", |
| 639 | rule_level: 12, |
| 640 | data_level: AlertSourceDataLevelEnum.High, |
| 641 | timestamp_utc: "2023-11-05T12:16:02.043Z", |
| 642 | data_event_ProcessId: "4684", |
| 643 | syslog_type: AlertSourceSyslogType.Wazuh, |
| 644 | data_system_Opcode: "0", |
| 645 | rule_description: "Process Explorer Driver Creation By Non-Sysinternals Binary", |
| 646 | gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38", |
| 647 | id: "1699187457.705230523", |
| 648 | data_status: AlertSourceDataStatus.Experimental, |
| 649 | data_system_Computer: "ANSYDWDC01.ANMS.LOCAL", |
| 650 | gl2_accounted_message_size: 10712, |
| 651 | data_document: |
| 652 | '{"kind":"evtx","path":"C:\\\\Windows\\\\System32\\\\winevt\\\\Logs\\\\Microsoft-Windows-Sysmon%4Operational.evtx","data":{"Event":{"EventData":{"CreationUtcTime":"2023-11-01 06:52:11.733","Image":"C:\\\\Program Files\\\\socfortress\\\\sysinternals\\\\logonsessions64.exe","ProcessGuid":"6D0AAEFA-8781-6547-C4BB-000000004200","ProcessId":4684,"RuleName":"-","TargetFilename":"C:\\\\Windows\\\\System32\\\\drivers\\\\PROCEXP152.SYS","User":"NT AUTHORITY\\\\SYSTEM","UtcTime":"2023-11-05 12:16:02.043"},"System":{"Channel":"Microsoft-Windows-Sysmon/Operational","Computer":"ANSYDWDC01.ANMS.LOCAL","Correlation":null,"EventID":11,"EventRecordID":18141034,"Execution_attributes":{"ProcessID":2564,"ThreadID":3804},"Keywords":"0x8000000000000000","Level":4,"Opcode":0,"Provider_attributes":{"Guid":"5770385F-C22A-43E0-BF4C-06F5698FFBD9","Name":"Microsoft-Windows-Sysmon"},"Security_attributes":{"UserID":"S-1-5-18"},"Task":11,"TimeCreated_attributes":{"SystemTime":"2023-11-05T12:16:02.045670Z"},"Version":2}},"Event_attributes":{"xmlns":"http://schemas.microsoft.com/win/2004/08/events/event"}}}', |
| 653 | data_event_UtcTime: "2023-11-05 12:16:02.043", |
| 654 | streams: ["645a3a6123e5cc30bbc0e5dc"], |
| 655 | gl2_message_id: "01HEFQE3FX6ARYDEQYMHJPGTE9", |
| 656 | data_source: AlertSourceDataLogsourceProduct.Sigma, |
| 657 | agent_ip: "139.180.134.102", |
| 658 | data_system_Security_attributes_UserID: "S-1-5-18", |
| 659 | true: 1699187457.773739, |
| 660 | data_timestamp: "2023-11-05T12:16:02.045670+00:00", |
| 661 | data_system_Level: "4", |
| 662 | data_event_CreationUtcTime: "2023-11-01 06:52:11.733", |
| 663 | data_system_Execution_attributes_ProcessID: "2564", |
| 664 | rule_groups: "windows, chainsaw, sigma", |
| 665 | data_system_EventRecordID: "18141034", |
| 666 | process_id: "4684", |
| 667 | data_system_TimeCreated_attributes_SystemTime: "2023-11-05T12:16:02.045670Z", |
| 668 | data_event_RuleName: "-", |
| 669 | data_logsource_category: AlertSourceDataLogsourceCategory.FileEvent, |
| 670 | data_system_Keywords: "0x8000000000000000", |
| 671 | sigma_name_encoded: "Process%20Explorer%20Driver%20Creation%20By%20Non-Sysinternals%20Binary", |
| 672 | agent_ip_geolocation: "1.3078,103.6818", |
| 673 | data_group: AlertSourceDataGroup.Sigma, |
| 674 | rule_firedtimes: 2, |
| 675 | data_event_User: "NT AUTHORITY\\SYSTEM", |
| 676 | data_path: "C:\\Windows\\System32\\winevt\\Logs\\Microsoft-Windows-Sysmon%4Operational.evtx", |
| 677 | rule_mail: true, |
| 678 | data_system_Provider_attributes_Name: "Microsoft-Windows-Sysmon", |
| 679 | data_name: "Process Explorer Driver Creation By Non-Sysinternals Binary", |
| 680 | decoder_name: AlertSourceDecoderName.JSON, |
| 681 | data_id: "de46c52b-0bf8-4936-a327-aace94f94ac6", |
| 682 | agent_ip_country_code: "SG", |
| 683 | syslog_level: AlertSourceSyslogLevel.Alert, |
| 684 | data_tags: "attack.persistence, attack.privilege_escalation, attack.t1068", |
| 685 | data_kind: AlertSourceDataKind.Individual, |
| 686 | data_logsource_product: AlertSourceDataLogsourceProduct.Windows, |
| 687 | timestamp: "2023-11-05 12:31:01.629", |
| 688 | ask_socfortress_message: |
| 689 | "The SIGMA alert \"Process Explorer Driver Creation By Non-Sysinternals Binary\" suggests that a non-Sysinternals binary has attempted to create a Process Explorer driver on a Windows endpoint. Process Explorer is a widely used system monitoring tool developed by Sysinternals (now part of Microsoft). The creation of a Process Explorer driver by a non-Sysinternals binary could indicate suspicious or potentially malicious activity.\n\nTo investigate this alert and determine an appropriate response, you should focus on the following key aspects:\n\n1. Validate the Alert: Verify the accuracy of the alert by checking if it was triggered by legitimate activity or if it is a false positive. Ensure that your detection system is properly configured and up to date.\n\n2. Identify the Binary: Determine which specific binary attempted to create the Process Explorer driver. Look for any unusual or suspicious characteristics such as unfamiliar names, file paths, digital signatures, or hash values.\n\n3. Analyze Process Execution Context: Investigate the context in which the binary executed and attempted to create the driver. Review process execution details, such as parent processes, command-line arguments, process creation time, and associated network connections.\n\n4. Assess System Impact: Evaluate whether any abnormal behavior occurred on the endpoint after this event took place. Look for signs of system instability, crashes, performance degradation, or other anomalous activities that may indicate malicious intent.\n\n5. Conduct File Analysis: Perform an in-depth analysis of the binary itself using appropriate tools like antivirus scanners and sandboxing environments to identify any malware indicators such as malicious code patterns or known signatures associated with malware families.\n\n6. Check Reputation: Research information about the binary's reputation online using threat intelligence platforms, virus total scanners, or security forums to determine if it has been previously identified as malicious.\n\n7. Perform Behavioral Analysis: If feasible, conduct dynamic analysis by executing the binary in an isolated environment while monitoring its behavior for any suspicious activities like network communication, file system changes, or attempts to escalate privileges.\n\n8. Review System Logs: Examine relevant logs such as event logs, process creation logs, driver loading logs, and network logs to identify any additional indicators of compromise or related activities.\n\nWhen assessing this alert, you should also ask yourself the following additional questions:\n\n1. Is the binary a legitimate tool that is commonly used in your organization? If not, why would it be present on the endpoint?\n\n2. Is there a business justification for creating a Process Explorer driver with this specific binary? Are there any documented cases or known legitimate reasons for doing so?\n\n3. Are there any other security events or alerts related to this binary or associated processes that can provide further context?\n\n4. Has the binary been whitelisted or approved by your organization's security policies? If not, why was it allowed to execute on the endpoint?\n\n5. Do you have sufficient visibility into other endpoints within your environment? Have similar events been observed elsewhere? This could indicate a larger-scale attack.\n\nRemember that each investigation may vary based on your organization's specific context and requirements.", |
| 690 | data_system_Channel: "Microsoft-Windows-Sysmon/Operational", |
| 691 | data_references: |
| 692 | "https://learn.microsoft.com/en-us/sysinternals/downloads/process-explorer, https://github.com/Yaxser/Backstab, https://www.elastic.co/security-labs/stopping-vulnerable-driver-attacks, https://news.sophos.com/en-us/2023/04/19/aukill-edr-killer-malware-abuses-process-explorer-driver/", |
| 693 | data_event_ProcessGuid: "6D0AAEFA-8781-6547-C4BB-000000004200", |
| 694 | gl2_processing_error: |
| 695 | 'Replaced invalid timestamp value in message <2e1383c2-7bd7-11ee-93bc-86000046278a> with current time - Value <2023-11-05T12:30:57.704+0000> caused exception: Invalid format: "2023-11-05T12:30:57.704+0000" is malformed at "T12:30:57.704+0000".', |
| 696 | data_falsepositives: |
| 697 | "Some false positives may occur with legitimate renamed process explorer binaries", |
| 698 | data_event_Image: "C:\\Program Files\\socfortress\\sysinternals\\logonsessions64.exe", |
| 699 | data_system_Execution_attributes_ThreadID: "3804", |
| 700 | message: |
| 701 | '{"true":1699187457.773739,"timestamp":"2023-11-05T12:30:57.704+0000","rule":{"level":12,"description":"Process Explorer Driver Creation By Non-Sysinternals Binary","id":"200051","firedtimes":2,"mail":true,"groups":["windows","chainsaw","sigma"]},"agent":{"id":"097","name":"ANSYDWDC01","ip":"139.180.134.102","labels":{"customer":"00002"}},"manager":{"name":"ASHWZHMA"},"id":"1699187457.705230523","decoder":{"name":"json"},"data":{"id":"de46c52b-0bf8-4936-a327-aace94f94ac6","status":"experimental","group":"Sigma","kind":"individual","document":"{\\"kind\\":\\"evtx\\",\\"path\\":\\"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\winevt\\\\\\\\Logs\\\\\\\\Microsoft-Windows-Sysmon%4Operational.evtx\\",\\"data\\":{\\"Event\\":{\\"EventData\\":{\\"CreationUtcTime\\":\\"2023-11-01 06:52:11.733\\",\\"Image\\":\\"C:\\\\\\\\Program Files\\\\\\\\socfortress\\\\\\\\sysinternals\\\\\\\\logonsessions64.exe\\",\\"ProcessGuid\\":\\"6D0AAEFA-8781-6547-C4BB-000000004200\\",\\"ProcessId\\":4684,\\"RuleName\\":\\"-\\",\\"TargetFilename\\":\\"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\drivers\\\\\\\\PROCEXP152.SYS\\",\\"User\\":\\"NT AUTHORITY\\\\\\\\SYSTEM\\",\\"UtcTime\\":\\"2023-11-05 12:16:02.043\\"},\\"System\\":{\\"Channel\\":\\"Microsoft-Windows-Sysmon/Operational\\",\\"Computer\\":\\"ANSYDWDC01.ANMS.LOCAL\\",\\"Correlation\\":null,\\"EventID\\":11,\\"EventRecordID\\":18141034,\\"Execution_attributes\\":{\\"ProcessID\\":2564,\\"ThreadID\\":3804},\\"Keywords\\":\\"0x8000000000000000\\",\\"Level\\":4,\\"Opcode\\":0,\\"Provider_attributes\\":{\\"Guid\\":\\"5770385F-C22A-43E0-BF4C-06F5698FFBD9\\",\\"Name\\":\\"Microsoft-Windows-Sysmon\\"},\\"Security_attributes\\":{\\"UserID\\":\\"S-1-5-18\\"},\\"Task\\":11,\\"TimeCreated_attributes\\":{\\"SystemTime\\":\\"2023-11-05T12:16:02.045670Z\\"},\\"Version\\":2}},\\"Event_attributes\\":{\\"xmlns\\":\\"http://schemas.microsoft.com/win/2004/08/events/event\\"}}}","event":{"CreationUtcTime":"2023-11-01 06:52:11.733","Image":"C:\\\\Program Files\\\\socfortress\\\\sysinternals\\\\logonsessions64.exe","ProcessGuid":"6D0AAEFA-8781-6547-C4BB-000000004200","ProcessId":"4684","RuleName":"-","TargetFilename":"C:\\\\Windows\\\\System32\\\\drivers\\\\PROCEXP152.SYS","User":"NT AUTHORITY\\\\SYSTEM","UtcTime":"2023-11-05 12:16:02.043"},"path":"C:\\\\Windows\\\\System32\\\\winevt\\\\Logs\\\\Microsoft-Windows-Sysmon%4Operational.evtx","system":{"Channel":"Microsoft-Windows-Sysmon/Operational","Computer":"ANSYDWDC01.ANMS.LOCAL","Correlation":"null","EventID":"11","EventRecordID":"18141034","Execution_attributes":{"ProcessID":"2564","ThreadID":"3804"},"Keywords":"0x8000000000000000","Level":"4","Opcode":"0","Provider_attributes":{"Guid":"5770385F-C22A-43E0-BF4C-06F5698FFBD9","Name":"Microsoft-Windows-Sysmon"},"Security_attributes":{"UserID":"S-1-5-18"},"Task":"11","TimeCreated_attributes":{"SystemTime":"2023-11-05T12:16:02.045670Z"},"Version":"2"},"name":"Process Explorer Driver Creation By Non-Sysinternals Binary","timestamp":"2023-11-05T12:16:02.045670+00:00","authors":["Florian Roth (Nextron Systems)"],"level":"high","source":"sigma","falsepositives":["Some false positives may occur with legitimate renamed process explorer binaries"],"logsource":{"category":"file_event","product":"windows"},"references":["https://learn.microsoft.com/en-us/sysinternals/downloads/process-explorer","https://github.com/Yaxser/Backstab","https://www.elastic.co/security-labs/stopping-vulnerable-driver-attacks","https://news.sophos.com/en-us/2023/04/19/aukill-edr-killer-malware-abuses-process-explorer-driver/"],"tags":["attack.persistence","attack.privilege_escalation","attack.t1068"]},"location":"active-response\\\\active-responses.log"}', |
| 702 | data_system_EventID: "11", |
| 703 | data_system_Provider_attributes_Guid: "5770385F-C22A-43E0-BF4C-06F5698FFBD9", |
| 704 | rule_id: "200051", |
| 705 | manager_name: "ASHWZHMA", |
| 706 | data_event_TargetFilename: "C:\\Windows\\System32\\drivers\\PROCEXP152.SYS", |
| 707 | location: "active-response\\active-responses.log", |
| 708 | data_authors: "Florian Roth (Nextron Systems)", |
| 709 | rule_group3: AlertSourceDataLogsourceProduct.Sigma, |
| 710 | msg_timestamp: "2023-11-05T12:30:57.704Z", |
| 711 | rule_group2: "chainsaw", |
| 712 | rule_group1: "windows" |
| 713 | }, |
| 714 | sort: [1699186562043] |
| 715 | }, |
| 716 | { |
| 717 | _index: "wazuh_00002_201", |
| 718 | _id: "d4a60924-7bcc-11ee-93bc-86000046278a", |
| 719 | _score: null, |
| 720 | _source: { |
| 721 | data_system_Task: "11", |
| 722 | source_reserved_ip: true, |
| 723 | agent_id: "097", |
| 724 | agent_name: "ANSYDWDC01", |
| 725 | data_system_Correlation: "null", |
| 726 | gl2_remote_ip: "10.255.255.13", |
| 727 | gl2_remote_port: 38584, |
| 728 | agent_labels_customer: "00002", |
| 729 | data_system_Version: "2", |
| 730 | agent_ip_city_name: "Singapore", |
| 731 | source: "10.255.255.13", |
| 732 | gl2_source_input: "6459151dea00fd5d3da2df91", |
| 733 | rule_level: 12, |
| 734 | data_level: AlertSourceDataLevelEnum.High, |
| 735 | timestamp_utc: "2023-11-05T11:16:02.307Z", |
| 736 | data_event_ProcessId: "6712", |
| 737 | syslog_type: AlertSourceSyslogType.Wazuh, |
| 738 | data_system_Opcode: "0", |
| 739 | rule_description: "Process Explorer Driver Creation By Non-Sysinternals Binary", |
| 740 | gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38", |
| 741 | id: "1699183014.641989382", |
| 742 | data_status: AlertSourceDataStatus.Experimental, |
| 743 | data_system_Computer: "ANSYDWDC01.ANMS.LOCAL", |
| 744 | gl2_accounted_message_size: 10712, |
| 745 | data_document: |
| 746 | '{"kind":"evtx","path":"C:\\\\Windows\\\\System32\\\\winevt\\\\Logs\\\\Microsoft-Windows-Sysmon%4Operational.evtx","data":{"Event":{"EventData":{"CreationUtcTime":"2023-11-01 06:52:11.733","Image":"C:\\\\Program Files\\\\socfortress\\\\sysinternals\\\\logonsessions64.exe","ProcessGuid":"6D0AAEFA-7972-6547-E6B9-000000004200","ProcessId":6712,"RuleName":"-","TargetFilename":"C:\\\\Windows\\\\System32\\\\drivers\\\\PROCEXP152.SYS","User":"NT AUTHORITY\\\\SYSTEM","UtcTime":"2023-11-05 11:16:02.307"},"System":{"Channel":"Microsoft-Windows-Sysmon/Operational","Computer":"ANSYDWDC01.ANMS.LOCAL","Correlation":null,"EventID":11,"EventRecordID":18140573,"Execution_attributes":{"ProcessID":2564,"ThreadID":3804},"Keywords":"0x8000000000000000","Level":4,"Opcode":0,"Provider_attributes":{"Guid":"5770385F-C22A-43E0-BF4C-06F5698FFBD9","Name":"Microsoft-Windows-Sysmon"},"Security_attributes":{"UserID":"S-1-5-18"},"Task":11,"TimeCreated_attributes":{"SystemTime":"2023-11-05T11:16:02.321071Z"},"Version":2}},"Event_attributes":{"xmlns":"http://schemas.microsoft.com/win/2004/08/events/event"}}}', |
| 747 | data_event_UtcTime: "2023-11-05 11:16:02.307", |
| 748 | streams: ["645a3a6123e5cc30bbc0e5dc"], |
| 749 | gl2_message_id: "01HEFK6ESE3ZHZY3GH5THZQ7VS", |
| 750 | data_source: AlertSourceDataLogsourceProduct.Sigma, |
| 751 | agent_ip: "139.180.134.102", |
| 752 | data_system_Security_attributes_UserID: "S-1-5-18", |
| 753 | true: 1699183014.546914, |
| 754 | data_timestamp: "2023-11-05T11:16:02.321071+00:00", |
| 755 | data_system_Level: "4", |
| 756 | data_event_CreationUtcTime: "2023-11-01 06:52:11.733", |
| 757 | data_system_Execution_attributes_ProcessID: "2564", |
| 758 | rule_groups: "windows, chainsaw, sigma", |
| 759 | data_system_EventRecordID: "18140573", |
| 760 | process_id: "6712", |
| 761 | data_system_TimeCreated_attributes_SystemTime: "2023-11-05T11:16:02.321071Z", |
| 762 | data_event_RuleName: "-", |
| 763 | data_logsource_category: AlertSourceDataLogsourceCategory.FileEvent, |
| 764 | data_system_Keywords: "0x8000000000000000", |
| 765 | sigma_name_encoded: "Process%20Explorer%20Driver%20Creation%20By%20Non-Sysinternals%20Binary", |
| 766 | agent_ip_geolocation: "1.3078,103.6818", |
| 767 | data_group: AlertSourceDataGroup.Sigma, |
| 768 | rule_firedtimes: 1, |
| 769 | data_event_User: "NT AUTHORITY\\SYSTEM", |
| 770 | data_path: "C:\\Windows\\System32\\winevt\\Logs\\Microsoft-Windows-Sysmon%4Operational.evtx", |
| 771 | rule_mail: true, |
| 772 | data_system_Provider_attributes_Name: "Microsoft-Windows-Sysmon", |
| 773 | data_name: "Process Explorer Driver Creation By Non-Sysinternals Binary", |
| 774 | decoder_name: AlertSourceDecoderName.JSON, |
| 775 | data_id: "de46c52b-0bf8-4936-a327-aace94f94ac6", |
| 776 | agent_ip_country_code: "SG", |
| 777 | syslog_level: AlertSourceSyslogLevel.Alert, |
| 778 | data_tags: "attack.persistence, attack.privilege_escalation, attack.t1068", |
| 779 | data_kind: AlertSourceDataKind.Individual, |
| 780 | data_logsource_product: AlertSourceDataLogsourceProduct.Windows, |
| 781 | timestamp: "2023-11-05 11:16:56.750", |
| 782 | ask_socfortress_message: |
| 783 | "The SIGMA alert \"Process Explorer Driver Creation By Non-Sysinternals Binary\" suggests that a non-Sysinternals binary has attempted to create a Process Explorer driver on a Windows endpoint. Process Explorer is a widely used system monitoring tool developed by Sysinternals (now part of Microsoft). The creation of a Process Explorer driver by a non-Sysinternals binary could indicate suspicious or potentially malicious activity.\n\nTo investigate this alert and determine an appropriate response, you should focus on the following key aspects:\n\n1. Validate the Alert: Verify the accuracy of the alert by checking if it was triggered by legitimate activity or if it is a false positive. Ensure that your detection system is properly configured and up to date.\n\n2. Identify the Binary: Determine which specific binary attempted to create the Process Explorer driver. Look for any unusual or suspicious characteristics such as unfamiliar names, file paths, digital signatures, or hash values.\n\n3. Analyze Process Execution Context: Investigate the context in which the binary executed and attempted to create the driver. Review process execution details, such as parent processes, command-line arguments, process creation time, and associated network connections.\n\n4. Assess System Impact: Evaluate whether any abnormal behavior occurred on the endpoint after this event took place. Look for signs of system instability, crashes, performance degradation, or other anomalous activities that may indicate malicious intent.\n\n5. Conduct File Analysis: Perform an in-depth analysis of the binary itself using appropriate tools like antivirus scanners and sandboxing environments to identify any malware indicators such as malicious code patterns or known signatures associated with malware families.\n\n6. Check Reputation: Research information about the binary's reputation online using threat intelligence platforms, virus total scanners, or security forums to determine if it has been previously identified as malicious.\n\n7. Perform Behavioral Analysis: If feasible, conduct dynamic analysis by executing the binary in an isolated environment while monitoring its behavior for any suspicious activities like network communication, file system changes, or attempts to escalate privileges.\n\n8. Review System Logs: Examine relevant logs such as event logs, process creation logs, driver loading logs, and network logs to identify any additional indicators of compromise or related activities.\n\nWhen assessing this alert, you should also ask yourself the following additional questions:\n\n1. Is the binary a legitimate tool that is commonly used in your organization? If not, why would it be present on the endpoint?\n\n2. Is there a business justification for creating a Process Explorer driver with this specific binary? Are there any documented cases or known legitimate reasons for doing so?\n\n3. Are there any other security events or alerts related to this binary or associated processes that can provide further context?\n\n4. Has the binary been whitelisted or approved by your organization's security policies? If not, why was it allowed to execute on the endpoint?\n\n5. Do you have sufficient visibility into other endpoints within your environment? Have similar events been observed elsewhere? This could indicate a larger-scale attack.\n\nRemember that each investigation may vary based on your organization's specific context and requirements.", |
| 784 | data_system_Channel: "Microsoft-Windows-Sysmon/Operational", |
| 785 | data_references: |
| 786 | "https://learn.microsoft.com/en-us/sysinternals/downloads/process-explorer, https://github.com/Yaxser/Backstab, https://www.elastic.co/security-labs/stopping-vulnerable-driver-attacks, https://news.sophos.com/en-us/2023/04/19/aukill-edr-killer-malware-abuses-process-explorer-driver/", |
| 787 | data_event_ProcessGuid: "6D0AAEFA-7972-6547-E6B9-000000004200", |
| 788 | gl2_processing_error: |
| 789 | 'Replaced invalid timestamp value in message <d4a60924-7bcc-11ee-93bc-86000046278a> with current time - Value <2023-11-05T11:16:54.542+0000> caused exception: Invalid format: "2023-11-05T11:16:54.542+0000" is malformed at "T11:16:54.542+0000".', |
| 790 | data_falsepositives: |
| 791 | "Some false positives may occur with legitimate renamed process explorer binaries", |
| 792 | data_event_Image: "C:\\Program Files\\socfortress\\sysinternals\\logonsessions64.exe", |
| 793 | data_system_Execution_attributes_ThreadID: "3804", |
| 794 | message: |
| 795 | '{"true":1699183014.546914,"timestamp":"2023-11-05T11:16:54.542+0000","rule":{"level":12,"description":"Process Explorer Driver Creation By Non-Sysinternals Binary","id":"200051","firedtimes":1,"mail":true,"groups":["windows","chainsaw","sigma"]},"agent":{"id":"097","name":"ANSYDWDC01","ip":"139.180.134.102","labels":{"customer":"00002"}},"manager":{"name":"ASHWZHMA"},"id":"1699183014.641989382","decoder":{"name":"json"},"data":{"id":"de46c52b-0bf8-4936-a327-aace94f94ac6","status":"experimental","group":"Sigma","kind":"individual","document":"{\\"kind\\":\\"evtx\\",\\"path\\":\\"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\winevt\\\\\\\\Logs\\\\\\\\Microsoft-Windows-Sysmon%4Operational.evtx\\",\\"data\\":{\\"Event\\":{\\"EventData\\":{\\"CreationUtcTime\\":\\"2023-11-01 06:52:11.733\\",\\"Image\\":\\"C:\\\\\\\\Program Files\\\\\\\\socfortress\\\\\\\\sysinternals\\\\\\\\logonsessions64.exe\\",\\"ProcessGuid\\":\\"6D0AAEFA-7972-6547-E6B9-000000004200\\",\\"ProcessId\\":6712,\\"RuleName\\":\\"-\\",\\"TargetFilename\\":\\"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\drivers\\\\\\\\PROCEXP152.SYS\\",\\"User\\":\\"NT AUTHORITY\\\\\\\\SYSTEM\\",\\"UtcTime\\":\\"2023-11-05 11:16:02.307\\"},\\"System\\":{\\"Channel\\":\\"Microsoft-Windows-Sysmon/Operational\\",\\"Computer\\":\\"ANSYDWDC01.ANMS.LOCAL\\",\\"Correlation\\":null,\\"EventID\\":11,\\"EventRecordID\\":18140573,\\"Execution_attributes\\":{\\"ProcessID\\":2564,\\"ThreadID\\":3804},\\"Keywords\\":\\"0x8000000000000000\\",\\"Level\\":4,\\"Opcode\\":0,\\"Provider_attributes\\":{\\"Guid\\":\\"5770385F-C22A-43E0-BF4C-06F5698FFBD9\\",\\"Name\\":\\"Microsoft-Windows-Sysmon\\"},\\"Security_attributes\\":{\\"UserID\\":\\"S-1-5-18\\"},\\"Task\\":11,\\"TimeCreated_attributes\\":{\\"SystemTime\\":\\"2023-11-05T11:16:02.321071Z\\"},\\"Version\\":2}},\\"Event_attributes\\":{\\"xmlns\\":\\"http://schemas.microsoft.com/win/2004/08/events/event\\"}}}","event":{"CreationUtcTime":"2023-11-01 06:52:11.733","Image":"C:\\\\Program Files\\\\socfortress\\\\sysinternals\\\\logonsessions64.exe","ProcessGuid":"6D0AAEFA-7972-6547-E6B9-000000004200","ProcessId":"6712","RuleName":"-","TargetFilename":"C:\\\\Windows\\\\System32\\\\drivers\\\\PROCEXP152.SYS","User":"NT AUTHORITY\\\\SYSTEM","UtcTime":"2023-11-05 11:16:02.307"},"path":"C:\\\\Windows\\\\System32\\\\winevt\\\\Logs\\\\Microsoft-Windows-Sysmon%4Operational.evtx","system":{"Channel":"Microsoft-Windows-Sysmon/Operational","Computer":"ANSYDWDC01.ANMS.LOCAL","Correlation":"null","EventID":"11","EventRecordID":"18140573","Execution_attributes":{"ProcessID":"2564","ThreadID":"3804"},"Keywords":"0x8000000000000000","Level":"4","Opcode":"0","Provider_attributes":{"Guid":"5770385F-C22A-43E0-BF4C-06F5698FFBD9","Name":"Microsoft-Windows-Sysmon"},"Security_attributes":{"UserID":"S-1-5-18"},"Task":"11","TimeCreated_attributes":{"SystemTime":"2023-11-05T11:16:02.321071Z"},"Version":"2"},"name":"Process Explorer Driver Creation By Non-Sysinternals Binary","timestamp":"2023-11-05T11:16:02.321071+00:00","authors":["Florian Roth (Nextron Systems)"],"level":"high","source":"sigma","falsepositives":["Some false positives may occur with legitimate renamed process explorer binaries"],"logsource":{"category":"file_event","product":"windows"},"references":["https://learn.microsoft.com/en-us/sysinternals/downloads/process-explorer","https://github.com/Yaxser/Backstab","https://www.elastic.co/security-labs/stopping-vulnerable-driver-attacks","https://news.sophos.com/en-us/2023/04/19/aukill-edr-killer-malware-abuses-process-explorer-driver/"],"tags":["attack.persistence","attack.privilege_escalation","attack.t1068"]},"location":"active-response\\\\active-responses.log"}', |
| 796 | data_system_EventID: "11", |
| 797 | data_system_Provider_attributes_Guid: "5770385F-C22A-43E0-BF4C-06F5698FFBD9", |
| 798 | rule_id: "200051", |
| 799 | manager_name: "ASHWZHMA", |
| 800 | data_event_TargetFilename: "C:\\Windows\\System32\\drivers\\PROCEXP152.SYS", |
| 801 | location: "active-response\\active-responses.log", |
| 802 | data_authors: "Florian Roth (Nextron Systems)", |
| 803 | rule_group3: AlertSourceDataLogsourceProduct.Sigma, |
| 804 | msg_timestamp: "2023-11-05T11:16:54.542Z", |
| 805 | rule_group2: "chainsaw", |
| 806 | rule_group1: "windows" |
| 807 | }, |
| 808 | sort: [1699182962307] |
| 809 | }, |
| 810 | { |
| 811 | _index: "wazuh_00002_201", |
| 812 | _id: "cf49be20-7bce-11ee-93bc-86000046278a", |
| 813 | _score: null, |
| 814 | _source: { |
| 815 | data_system_Task: "11", |
| 816 | source_reserved_ip: true, |
| 817 | agent_id: "097", |
| 818 | agent_name: "ANSYDWDC01", |
| 819 | data_system_Correlation: "null", |
| 820 | gl2_remote_ip: "10.255.255.13", |
| 821 | gl2_remote_port: 49198, |
| 822 | agent_labels_customer: "00002", |
| 823 | data_system_Version: "2", |
| 824 | agent_ip_city_name: "Singapore", |
| 825 | source: "10.255.255.13", |
| 826 | gl2_source_input: "6459151dea00fd5d3da2df91", |
| 827 | rule_level: 12, |
| 828 | data_level: AlertSourceDataLevelEnum.High, |
| 829 | timestamp_utc: "2023-11-05T11:16:02.307Z", |
| 830 | data_event_ProcessId: "6712", |
| 831 | syslog_type: AlertSourceSyslogType.Wazuh, |
| 832 | data_system_Opcode: "0", |
| 833 | rule_description: "Process Explorer Driver Creation By Non-Sysinternals Binary", |
| 834 | gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38", |
| 835 | id: "1699183862.653635812", |
| 836 | data_status: AlertSourceDataStatus.Experimental, |
| 837 | data_system_Computer: "ANSYDWDC01.ANMS.LOCAL", |
| 838 | gl2_accounted_message_size: 10712, |
| 839 | data_document: |
| 840 | '{"kind":"evtx","path":"C:\\\\Windows\\\\System32\\\\winevt\\\\Logs\\\\Microsoft-Windows-Sysmon%4Operational.evtx","data":{"Event":{"EventData":{"CreationUtcTime":"2023-11-01 06:52:11.733","Image":"C:\\\\Program Files\\\\socfortress\\\\sysinternals\\\\logonsessions64.exe","ProcessGuid":"6D0AAEFA-7972-6547-E6B9-000000004200","ProcessId":6712,"RuleName":"-","TargetFilename":"C:\\\\Windows\\\\System32\\\\drivers\\\\PROCEXP152.SYS","User":"NT AUTHORITY\\\\SYSTEM","UtcTime":"2023-11-05 11:16:02.307"},"System":{"Channel":"Microsoft-Windows-Sysmon/Operational","Computer":"ANSYDWDC01.ANMS.LOCAL","Correlation":null,"EventID":11,"EventRecordID":18140573,"Execution_attributes":{"ProcessID":2564,"ThreadID":3804},"Keywords":"0x8000000000000000","Level":4,"Opcode":0,"Provider_attributes":{"Guid":"5770385F-C22A-43E0-BF4C-06F5698FFBD9","Name":"Microsoft-Windows-Sysmon"},"Security_attributes":{"UserID":"S-1-5-18"},"Task":11,"TimeCreated_attributes":{"SystemTime":"2023-11-05T11:16:02.321071Z"},"Version":2}},"Event_attributes":{"xmlns":"http://schemas.microsoft.com/win/2004/08/events/event"}}}', |
| 841 | data_event_UtcTime: "2023-11-05 11:16:02.307", |
| 842 | streams: ["645a3a6123e5cc30bbc0e5dc"], |
| 843 | gl2_message_id: "01HEFM0CR3M66JCE9GK8X0BSHV", |
| 844 | data_source: AlertSourceDataLogsourceProduct.Sigma, |
| 845 | agent_ip: "139.180.134.102", |
| 846 | data_system_Security_attributes_UserID: "S-1-5-18", |
| 847 | true: 1699183863.254522, |
| 848 | data_timestamp: "2023-11-05T11:16:02.321071+00:00", |
| 849 | data_system_Level: "4", |
| 850 | data_event_CreationUtcTime: "2023-11-01 06:52:11.733", |
| 851 | data_system_Execution_attributes_ProcessID: "2564", |
| 852 | rule_groups: "windows, chainsaw, sigma", |
| 853 | data_system_EventRecordID: "18140573", |
| 854 | process_id: "6712", |
| 855 | data_system_TimeCreated_attributes_SystemTime: "2023-11-05T11:16:02.321071Z", |
| 856 | data_event_RuleName: "-", |
| 857 | data_logsource_category: AlertSourceDataLogsourceCategory.FileEvent, |
| 858 | data_system_Keywords: "0x8000000000000000", |
| 859 | sigma_name_encoded: "Process%20Explorer%20Driver%20Creation%20By%20Non-Sysinternals%20Binary", |
| 860 | agent_ip_geolocation: "1.3078,103.6818", |
| 861 | data_group: AlertSourceDataGroup.Sigma, |
| 862 | rule_firedtimes: 2, |
| 863 | data_event_User: "NT AUTHORITY\\SYSTEM", |
| 864 | data_path: "C:\\Windows\\System32\\winevt\\Logs\\Microsoft-Windows-Sysmon%4Operational.evtx", |
| 865 | rule_mail: true, |
| 866 | data_system_Provider_attributes_Name: "Microsoft-Windows-Sysmon", |
| 867 | data_name: "Process Explorer Driver Creation By Non-Sysinternals Binary", |
| 868 | decoder_name: AlertSourceDecoderName.JSON, |
| 869 | data_id: "de46c52b-0bf8-4936-a327-aace94f94ac6", |
| 870 | agent_ip_country_code: "SG", |
| 871 | syslog_level: AlertSourceSyslogLevel.Alert, |
| 872 | data_tags: "attack.persistence, attack.privilege_escalation, attack.t1068", |
| 873 | data_kind: AlertSourceDataKind.Individual, |
| 874 | data_logsource_product: AlertSourceDataLogsourceProduct.Windows, |
| 875 | timestamp: "2023-11-05 11:31:06.627", |
| 876 | ask_socfortress_message: |
| 877 | "The SIGMA alert \"Process Explorer Driver Creation By Non-Sysinternals Binary\" suggests that a non-Sysinternals binary has attempted to create a Process Explorer driver on a Windows endpoint. Process Explorer is a widely used system monitoring tool developed by Sysinternals (now part of Microsoft). The creation of a Process Explorer driver by a non-Sysinternals binary could indicate suspicious or potentially malicious activity.\n\nTo investigate this alert and determine an appropriate response, you should focus on the following key aspects:\n\n1. Validate the Alert: Verify the accuracy of the alert by checking if it was triggered by legitimate activity or if it is a false positive. Ensure that your detection system is properly configured and up to date.\n\n2. Identify the Binary: Determine which specific binary attempted to create the Process Explorer driver. Look for any unusual or suspicious characteristics such as unfamiliar names, file paths, digital signatures, or hash values.\n\n3. Analyze Process Execution Context: Investigate the context in which the binary executed and attempted to create the driver. Review process execution details, such as parent processes, command-line arguments, process creation time, and associated network connections.\n\n4. Assess System Impact: Evaluate whether any abnormal behavior occurred on the endpoint after this event took place. Look for signs of system instability, crashes, performance degradation, or other anomalous activities that may indicate malicious intent.\n\n5. Conduct File Analysis: Perform an in-depth analysis of the binary itself using appropriate tools like antivirus scanners and sandboxing environments to identify any malware indicators such as malicious code patterns or known signatures associated with malware families.\n\n6. Check Reputation: Research information about the binary's reputation online using threat intelligence platforms, virus total scanners, or security forums to determine if it has been previously identified as malicious.\n\n7. Perform Behavioral Analysis: If feasible, conduct dynamic analysis by executing the binary in an isolated environment while monitoring its behavior for any suspicious activities like network communication, file system changes, or attempts to escalate privileges.\n\n8. Review System Logs: Examine relevant logs such as event logs, process creation logs, driver loading logs, and network logs to identify any additional indicators of compromise or related activities.\n\nWhen assessing this alert, you should also ask yourself the following additional questions:\n\n1. Is the binary a legitimate tool that is commonly used in your organization? If not, why would it be present on the endpoint?\n\n2. Is there a business justification for creating a Process Explorer driver with this specific binary? Are there any documented cases or known legitimate reasons for doing so?\n\n3. Are there any other security events or alerts related to this binary or associated processes that can provide further context?\n\n4. Has the binary been whitelisted or approved by your organization's security policies? If not, why was it allowed to execute on the endpoint?\n\n5. Do you have sufficient visibility into other endpoints within your environment? Have similar events been observed elsewhere? This could indicate a larger-scale attack.\n\nRemember that each investigation may vary based on your organization's specific context and requirements.", |
| 878 | data_system_Channel: "Microsoft-Windows-Sysmon/Operational", |
| 879 | data_references: |
| 880 | "https://learn.microsoft.com/en-us/sysinternals/downloads/process-explorer, https://github.com/Yaxser/Backstab, https://www.elastic.co/security-labs/stopping-vulnerable-driver-attacks, https://news.sophos.com/en-us/2023/04/19/aukill-edr-killer-malware-abuses-process-explorer-driver/", |
| 881 | data_event_ProcessGuid: "6D0AAEFA-7972-6547-E6B9-000000004200", |
| 882 | gl2_processing_error: |
| 883 | 'Replaced invalid timestamp value in message <cf49be20-7bce-11ee-93bc-86000046278a> with current time - Value <2023-11-05T11:31:02.897+0000> caused exception: Invalid format: "2023-11-05T11:31:02.897+0000" is malformed at "T11:31:02.897+0000".', |
| 884 | data_falsepositives: |
| 885 | "Some false positives may occur with legitimate renamed process explorer binaries", |
| 886 | data_event_Image: "C:\\Program Files\\socfortress\\sysinternals\\logonsessions64.exe", |
| 887 | data_system_Execution_attributes_ThreadID: "3804", |
| 888 | message: |
| 889 | '{"true":1699183863.254522,"timestamp":"2023-11-05T11:31:02.897+0000","rule":{"level":12,"description":"Process Explorer Driver Creation By Non-Sysinternals Binary","id":"200051","firedtimes":2,"mail":true,"groups":["windows","chainsaw","sigma"]},"agent":{"id":"097","name":"ANSYDWDC01","ip":"139.180.134.102","labels":{"customer":"00002"}},"manager":{"name":"ASHWZHMA"},"id":"1699183862.653635812","decoder":{"name":"json"},"data":{"id":"de46c52b-0bf8-4936-a327-aace94f94ac6","status":"experimental","group":"Sigma","kind":"individual","document":"{\\"kind\\":\\"evtx\\",\\"path\\":\\"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\winevt\\\\\\\\Logs\\\\\\\\Microsoft-Windows-Sysmon%4Operational.evtx\\",\\"data\\":{\\"Event\\":{\\"EventData\\":{\\"CreationUtcTime\\":\\"2023-11-01 06:52:11.733\\",\\"Image\\":\\"C:\\\\\\\\Program Files\\\\\\\\socfortress\\\\\\\\sysinternals\\\\\\\\logonsessions64.exe\\",\\"ProcessGuid\\":\\"6D0AAEFA-7972-6547-E6B9-000000004200\\",\\"ProcessId\\":6712,\\"RuleName\\":\\"-\\",\\"TargetFilename\\":\\"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\drivers\\\\\\\\PROCEXP152.SYS\\",\\"User\\":\\"NT AUTHORITY\\\\\\\\SYSTEM\\",\\"UtcTime\\":\\"2023-11-05 11:16:02.307\\"},\\"System\\":{\\"Channel\\":\\"Microsoft-Windows-Sysmon/Operational\\",\\"Computer\\":\\"ANSYDWDC01.ANMS.LOCAL\\",\\"Correlation\\":null,\\"EventID\\":11,\\"EventRecordID\\":18140573,\\"Execution_attributes\\":{\\"ProcessID\\":2564,\\"ThreadID\\":3804},\\"Keywords\\":\\"0x8000000000000000\\",\\"Level\\":4,\\"Opcode\\":0,\\"Provider_attributes\\":{\\"Guid\\":\\"5770385F-C22A-43E0-BF4C-06F5698FFBD9\\",\\"Name\\":\\"Microsoft-Windows-Sysmon\\"},\\"Security_attributes\\":{\\"UserID\\":\\"S-1-5-18\\"},\\"Task\\":11,\\"TimeCreated_attributes\\":{\\"SystemTime\\":\\"2023-11-05T11:16:02.321071Z\\"},\\"Version\\":2}},\\"Event_attributes\\":{\\"xmlns\\":\\"http://schemas.microsoft.com/win/2004/08/events/event\\"}}}","event":{"CreationUtcTime":"2023-11-01 06:52:11.733","Image":"C:\\\\Program Files\\\\socfortress\\\\sysinternals\\\\logonsessions64.exe","ProcessGuid":"6D0AAEFA-7972-6547-E6B9-000000004200","ProcessId":"6712","RuleName":"-","TargetFilename":"C:\\\\Windows\\\\System32\\\\drivers\\\\PROCEXP152.SYS","User":"NT AUTHORITY\\\\SYSTEM","UtcTime":"2023-11-05 11:16:02.307"},"path":"C:\\\\Windows\\\\System32\\\\winevt\\\\Logs\\\\Microsoft-Windows-Sysmon%4Operational.evtx","system":{"Channel":"Microsoft-Windows-Sysmon/Operational","Computer":"ANSYDWDC01.ANMS.LOCAL","Correlation":"null","EventID":"11","EventRecordID":"18140573","Execution_attributes":{"ProcessID":"2564","ThreadID":"3804"},"Keywords":"0x8000000000000000","Level":"4","Opcode":"0","Provider_attributes":{"Guid":"5770385F-C22A-43E0-BF4C-06F5698FFBD9","Name":"Microsoft-Windows-Sysmon"},"Security_attributes":{"UserID":"S-1-5-18"},"Task":"11","TimeCreated_attributes":{"SystemTime":"2023-11-05T11:16:02.321071Z"},"Version":"2"},"name":"Process Explorer Driver Creation By Non-Sysinternals Binary","timestamp":"2023-11-05T11:16:02.321071+00:00","authors":["Florian Roth (Nextron Systems)"],"level":"high","source":"sigma","falsepositives":["Some false positives may occur with legitimate renamed process explorer binaries"],"logsource":{"category":"file_event","product":"windows"},"references":["https://learn.microsoft.com/en-us/sysinternals/downloads/process-explorer","https://github.com/Yaxser/Backstab","https://www.elastic.co/security-labs/stopping-vulnerable-driver-attacks","https://news.sophos.com/en-us/2023/04/19/aukill-edr-killer-malware-abuses-process-explorer-driver/"],"tags":["attack.persistence","attack.privilege_escalation","attack.t1068"]},"location":"active-response\\\\active-responses.log"}', |
| 890 | data_system_EventID: "11", |
| 891 | data_system_Provider_attributes_Guid: "5770385F-C22A-43E0-BF4C-06F5698FFBD9", |
| 892 | rule_id: "200051", |
| 893 | manager_name: "ASHWZHMA", |
| 894 | data_event_TargetFilename: "C:\\Windows\\System32\\drivers\\PROCEXP152.SYS", |
| 895 | location: "active-response\\active-responses.log", |
| 896 | data_authors: "Florian Roth (Nextron Systems)", |
| 897 | rule_group3: AlertSourceDataLogsourceProduct.Sigma, |
| 898 | msg_timestamp: "2023-11-05T11:31:02.897Z", |
| 899 | rule_group2: "chainsaw", |
| 900 | rule_group1: "windows" |
| 901 | }, |
| 902 | sort: [1699182962307] |
| 903 | }, |
| 904 | { |
| 905 | _index: "wazuh_00002_201", |
| 906 | _id: "75dcb8b2-7bc4-11ee-93bc-86000046278a", |
| 907 | _score: null, |
| 908 | _source: { |
| 909 | data_system_Task: "11", |
| 910 | source_reserved_ip: true, |
| 911 | agent_id: "097", |
| 912 | agent_name: "ANSYDWDC01", |
| 913 | data_system_Correlation: "null", |
| 914 | gl2_remote_ip: "10.255.255.13", |
| 915 | gl2_remote_port: 59674, |
| 916 | agent_labels_customer: "00002", |
| 917 | data_system_Version: "2", |
| 918 | agent_ip_city_name: "Singapore", |
| 919 | source: "10.255.255.13", |
| 920 | gl2_source_input: "6459151dea00fd5d3da2df91", |
| 921 | rule_level: 12, |
| 922 | data_level: AlertSourceDataLevelEnum.High, |
| 923 | timestamp_utc: "2023-11-05T10:16:05.625Z", |
| 924 | data_event_ProcessId: "5020", |
| 925 | syslog_type: AlertSourceSyslogType.Wazuh, |
| 926 | data_system_Opcode: "0", |
| 927 | rule_description: "Process Explorer Driver Creation By Non-Sysinternals Binary", |
| 928 | gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38", |
| 929 | id: "1699179418.594692359", |
| 930 | data_status: AlertSourceDataStatus.Experimental, |
| 931 | data_system_Computer: "ANSYDWDC01.ANMS.LOCAL", |
| 932 | gl2_accounted_message_size: 11648, |
| 933 | data_document: |
| 934 | '{"kind":"evtx","path":"C:\\\\Windows\\\\System32\\\\winevt\\\\Logs\\\\Microsoft-Windows-Sysmon%4Operational.evtx","data":{"Event":{"EventData":{"CreationUtcTime":"2023-11-01 06:52:11.733","Image":"C:\\\\Program Files\\\\socfortress\\\\sysinternals\\\\logonsessions64.exe","ProcessGuid":"6D0AAEFA-6B64-6547-61B8-000000004200","ProcessId":5020,"RuleName":"-","TargetFilename":"C:\\\\Windows\\\\System32\\\\drivers\\\\PROCEXP152.SYS","User":"NT AUTHORITY\\\\SYSTEM","UtcTime":"2023-11-05 10:16:05.625"},"System":{"Channel":"Microsoft-Windows-Sysmon/Operational","Computer":"ANSYDWDC01.ANMS.LOCAL","Correlation":null,"EventID":11,"EventRecordID":18140150,"Execution_attributes":{"ProcessID":2564,"ThreadID":3804},"Keywords":"0x8000000000000000","Level":4,"Opcode":0,"Provider_attributes":{"Guid":"5770385F-C22A-43E0-BF4C-06F5698FFBD9","Name":"Microsoft-Windows-Sysmon"},"Security_attributes":{"UserID":"S-1-5-18"},"Task":11,"TimeCreated_attributes":{"SystemTime":"2023-11-05T10:16:05.635338Z"},"Version":2}},"Event_attributes":{"xmlns":"http://schemas.microsoft.com/win/2004/08/events/event"}}}', |
| 935 | data_event_UtcTime: "2023-11-05 10:16:05.625", |
| 936 | streams: ["645a3a6123e5cc30bbc0e5dc"], |
| 937 | gl2_message_id: "01HEFFRR246C2SFHZZNDKNXRYP", |
| 938 | data_source: AlertSourceDataLogsourceProduct.Sigma, |
| 939 | agent_ip: "139.180.134.102", |
| 940 | data_system_Security_attributes_UserID: "S-1-5-18", |
| 941 | true: 1699179418.395436, |
| 942 | data_timestamp: "2023-11-05T10:16:05.635338+00:00", |
| 943 | data_system_Level: "4", |
| 944 | data_event_CreationUtcTime: "2023-11-01 06:52:11.733", |
| 945 | data_system_Execution_attributes_ProcessID: "2564", |
| 946 | rule_groups: "windows, chainsaw, sigma", |
| 947 | data_system_EventRecordID: "18140150", |
| 948 | process_id: "5020", |
| 949 | data_system_TimeCreated_attributes_SystemTime: "2023-11-05T10:16:05.635338Z", |
| 950 | data_event_RuleName: "-", |
| 951 | data_logsource_category: AlertSourceDataLogsourceCategory.FileEvent, |
| 952 | data_system_Keywords: "0x8000000000000000", |
| 953 | sigma_name_encoded: "Process%20Explorer%20Driver%20Creation%20By%20Non-Sysinternals%20Binary", |
| 954 | agent_ip_geolocation: "1.3078,103.6818", |
| 955 | data_group: AlertSourceDataGroup.Sigma, |
| 956 | rule_firedtimes: 1, |
| 957 | data_event_User: "NT AUTHORITY\\SYSTEM", |
| 958 | data_path: "C:\\Windows\\System32\\winevt\\Logs\\Microsoft-Windows-Sysmon%4Operational.evtx", |
| 959 | rule_mail: true, |
| 960 | data_system_Provider_attributes_Name: "Microsoft-Windows-Sysmon", |
| 961 | data_name: "Process Explorer Driver Creation By Non-Sysinternals Binary", |
| 962 | decoder_name: AlertSourceDecoderName.JSON, |
| 963 | data_id: "de46c52b-0bf8-4936-a327-aace94f94ac6", |
| 964 | agent_ip_country_code: "SG", |
| 965 | syslog_level: AlertSourceSyslogLevel.Alert, |
| 966 | data_tags: "attack.persistence, attack.privilege_escalation, attack.t1068", |
| 967 | data_kind: AlertSourceDataKind.Individual, |
| 968 | data_logsource_product: AlertSourceDataLogsourceProduct.Windows, |
| 969 | timestamp: "2023-11-05 10:17:01.764", |
| 970 | ask_socfortress_message: |
| 971 | "The SIGMA alert \"Process Explorer Driver Creation By Non-Sysinternals Binary\" indicates that a Windows endpoint has detected an instance where a process explorer driver was created by a binary that is not associated with Microsoft Sysinternals, a legitimate software tool widely used for system monitoring and troubleshooting.\n\nThis alert suggests the possibility of malicious activity on the endpoint. Attackers often leverage process explorer drivers or similar techniques to gain unauthorized access, elevate privileges, or hide their presence on a system. As such, it is important to thoroughly investigate this alert to determine the appropriate response.\n\nHere are key aspects you should investigate when responding to this alert:\n\n1. Endpoint Details: Gather information about the affected endpoint such as its hostname, IP address, operating system version, and any other relevant details. This information will help in understanding the context and potential impact of the alert.\n\n2. Timestamp and Correlation: Identify when the event occurred and check for any correlation with other security events or alerts on the same endpoint or across your environment. This can help determine if it's an isolated incident or part of a broader attack pattern.\n\n3. Process Explorer Driver: Determine which specific driver was created and by which binary it was created. Identify its location on disk and inspect its file properties (e.g., name, size, creation date). Compare these details against known legitimate drivers associated with Microsoft Sysinternals tools.\n\n4. Binary Analysis: Conduct further analysis of the non-Sysinternals binary responsible for creating the process explorer driver. Scan it using antivirus/anti-malware tools to identify any potential malicious behavior or indicators of compromise (IOCs). Consider submitting samples to threat intelligence platforms for additional analysis.\n\n5. Process Information: Examine details about the process associated with creating this driver (e.g., process ID (PID), parent PID) to understand how it was initiated and by what means.\n\n6. System Logs: Review relevant logs such as event logs, system logs, and security logs to identify any suspicious activities or additional indicators of compromise. Look for any abnormal system behavior or unauthorized modifications.\n\n7. User Context: Determine the user account associated with the process that initiated the driver creation. Check if it is a privileged account or a standard user account. If it is a privileged account, investigate whether this activity was expected and authorized.\n\n8. Network Activity: Analyze network traffic logs to identify any communication originating from the affected endpoint during or after the event. Look for connections to suspicious IP addresses, domains, or known command-and-control servers.\n\n9. Endpoint Security Posture: Evaluate the security controls deployed on the affected endpoint, such as antivirus/anti-malware software, intrusion prevention systems (IPS), host-based firewalls, and endpoint detection and response (EDR) solutions. Determine if these controls detected or blocked any malicious activity related to this alert.\n\n10. Incident Response Plan: Assess your organization's incident response plan and determine if there are predefined steps for responding to similar alerts like this one. Follow established procedures to contain the incident, mitigate risks, remediate affected systems, and prevent future occurrences.\n\nAdditional questions you should ask yourself when assessing this alert:\n\n1. Is there any legitimate reason for a non-Sysinternals binary to create a process explorer driver on this endpoint?\n2. Have there been any recent changes in software deployment or system configuration that could explain this alert?\n3. Are there other endpoints in your environment running similar binaries that could trigger similar alerts?\n4. Are there any recent reports of malware campaigns targeting process explorer drivers or abusing legitimate tools like Sysinternals?\n5. Are there any indicators suggesting compromise on this endpoint beyond just the creation of the driver?\n\nBy thoroughly investigating these aspects and considering additional relevant questions specific to your environment, you can make an informed decision about how best to respond to this SIGMA alert and mitigate potential risks.", |
| 972 | data_system_Channel: "Microsoft-Windows-Sysmon/Operational", |
| 973 | data_references: |
| 974 | "https://learn.microsoft.com/en-us/sysinternals/downloads/process-explorer, https://github.com/Yaxser/Backstab, https://www.elastic.co/security-labs/stopping-vulnerable-driver-attacks, https://news.sophos.com/en-us/2023/04/19/aukill-edr-killer-malware-abuses-process-explorer-driver/", |
| 975 | data_event_ProcessGuid: "6D0AAEFA-6B64-6547-61B8-000000004200", |
| 976 | gl2_processing_error: |
| 977 | 'Replaced invalid timestamp value in message <75dcb8b2-7bc4-11ee-93bc-86000046278a> with current time - Value <2023-11-05T10:16:58.328+0000> caused exception: Invalid format: "2023-11-05T10:16:58.328+0000" is malformed at "T10:16:58.328+0000".', |
| 978 | data_falsepositives: |
| 979 | "Some false positives may occur with legitimate renamed process explorer binaries", |
| 980 | data_event_Image: "C:\\Program Files\\socfortress\\sysinternals\\logonsessions64.exe", |
| 981 | data_system_Execution_attributes_ThreadID: "3804", |
| 982 | message: |
| 983 | '{"true":1699179418.395436,"timestamp":"2023-11-05T10:16:58.328+0000","rule":{"level":12,"description":"Process Explorer Driver Creation By Non-Sysinternals Binary","id":"200051","firedtimes":1,"mail":true,"groups":["windows","chainsaw","sigma"]},"agent":{"id":"097","name":"ANSYDWDC01","ip":"139.180.134.102","labels":{"customer":"00002"}},"manager":{"name":"ASHWZHMA"},"id":"1699179418.594692359","decoder":{"name":"json"},"data":{"id":"de46c52b-0bf8-4936-a327-aace94f94ac6","status":"experimental","group":"Sigma","kind":"individual","document":"{\\"kind\\":\\"evtx\\",\\"path\\":\\"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\winevt\\\\\\\\Logs\\\\\\\\Microsoft-Windows-Sysmon%4Operational.evtx\\",\\"data\\":{\\"Event\\":{\\"EventData\\":{\\"CreationUtcTime\\":\\"2023-11-01 06:52:11.733\\",\\"Image\\":\\"C:\\\\\\\\Program Files\\\\\\\\socfortress\\\\\\\\sysinternals\\\\\\\\logonsessions64.exe\\",\\"ProcessGuid\\":\\"6D0AAEFA-6B64-6547-61B8-000000004200\\",\\"ProcessId\\":5020,\\"RuleName\\":\\"-\\",\\"TargetFilename\\":\\"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\drivers\\\\\\\\PROCEXP152.SYS\\",\\"User\\":\\"NT AUTHORITY\\\\\\\\SYSTEM\\",\\"UtcTime\\":\\"2023-11-05 10:16:05.625\\"},\\"System\\":{\\"Channel\\":\\"Microsoft-Windows-Sysmon/Operational\\",\\"Computer\\":\\"ANSYDWDC01.ANMS.LOCAL\\",\\"Correlation\\":null,\\"EventID\\":11,\\"EventRecordID\\":18140150,\\"Execution_attributes\\":{\\"ProcessID\\":2564,\\"ThreadID\\":3804},\\"Keywords\\":\\"0x8000000000000000\\",\\"Level\\":4,\\"Opcode\\":0,\\"Provider_attributes\\":{\\"Guid\\":\\"5770385F-C22A-43E0-BF4C-06F5698FFBD9\\",\\"Name\\":\\"Microsoft-Windows-Sysmon\\"},\\"Security_attributes\\":{\\"UserID\\":\\"S-1-5-18\\"},\\"Task\\":11,\\"TimeCreated_attributes\\":{\\"SystemTime\\":\\"2023-11-05T10:16:05.635338Z\\"},\\"Version\\":2}},\\"Event_attributes\\":{\\"xmlns\\":\\"http://schemas.microsoft.com/win/2004/08/events/event\\"}}}","event":{"CreationUtcTime":"2023-11-01 06:52:11.733","Image":"C:\\\\Program Files\\\\socfortress\\\\sysinternals\\\\logonsessions64.exe","ProcessGuid":"6D0AAEFA-6B64-6547-61B8-000000004200","ProcessId":"5020","RuleName":"-","TargetFilename":"C:\\\\Windows\\\\System32\\\\drivers\\\\PROCEXP152.SYS","User":"NT AUTHORITY\\\\SYSTEM","UtcTime":"2023-11-05 10:16:05.625"},"path":"C:\\\\Windows\\\\System32\\\\winevt\\\\Logs\\\\Microsoft-Windows-Sysmon%4Operational.evtx","system":{"Channel":"Microsoft-Windows-Sysmon/Operational","Computer":"ANSYDWDC01.ANMS.LOCAL","Correlation":"null","EventID":"11","EventRecordID":"18140150","Execution_attributes":{"ProcessID":"2564","ThreadID":"3804"},"Keywords":"0x8000000000000000","Level":"4","Opcode":"0","Provider_attributes":{"Guid":"5770385F-C22A-43E0-BF4C-06F5698FFBD9","Name":"Microsoft-Windows-Sysmon"},"Security_attributes":{"UserID":"S-1-5-18"},"Task":"11","TimeCreated_attributes":{"SystemTime":"2023-11-05T10:16:05.635338Z"},"Version":"2"},"name":"Process Explorer Driver Creation By Non-Sysinternals Binary","timestamp":"2023-11-05T10:16:05.635338+00:00","authors":["Florian Roth (Nextron Systems)"],"level":"high","source":"sigma","falsepositives":["Some false positives may occur with legitimate renamed process explorer binaries"],"logsource":{"category":"file_event","product":"windows"},"references":["https://learn.microsoft.com/en-us/sysinternals/downloads/process-explorer","https://github.com/Yaxser/Backstab","https://www.elastic.co/security-labs/stopping-vulnerable-driver-attacks","https://news.sophos.com/en-us/2023/04/19/aukill-edr-killer-malware-abuses-process-explorer-driver/"],"tags":["attack.persistence","attack.privilege_escalation","attack.t1068"]},"location":"active-response\\\\active-responses.log"}', |
| 984 | data_system_EventID: "11", |
| 985 | data_system_Provider_attributes_Guid: "5770385F-C22A-43E0-BF4C-06F5698FFBD9", |
| 986 | rule_id: "200051", |
| 987 | manager_name: "ASHWZHMA", |
| 988 | data_event_TargetFilename: "C:\\Windows\\System32\\drivers\\PROCEXP152.SYS", |
| 989 | location: "active-response\\active-responses.log", |
| 990 | data_authors: "Florian Roth (Nextron Systems)", |
| 991 | rule_group3: AlertSourceDataLogsourceProduct.Sigma, |
| 992 | msg_timestamp: "2023-11-05T10:16:58.328Z", |
| 993 | rule_group2: "chainsaw", |
| 994 | rule_group1: "windows" |
| 995 | }, |
| 996 | sort: [1699179365625] |
| 997 | } |
| 998 | ] |
| 999 | }, |
| 1000 | { |
| 1001 | index_name: "wazuh-bkomanh1_1", |
| 1002 | total_alerts: 5, |
| 1003 | alerts: [ |
| 1004 | { |
| 1005 | _index: "wazuh-bkomanh1_1", |
| 1006 | _id: "ae3aac92-7bd7-11ee-93bc-86000046278a", |
| 1007 | _score: null, |
| 1008 | _source: { |
| 1009 | data_win_eventdata_description: "Application Compatibility Database Installer", |
| 1010 | source_reserved_ip: true, |
| 1011 | data_win_system_eventRecordID: "834890", |
| 1012 | data_win_eventdata_user: "NT AUTHORITY\\\\SYSTEM", |
| 1013 | agent_id: "068", |
| 1014 | agent_name: "WinDev2308Eval", |
| 1015 | sha256: "5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77", |
| 1016 | gl2_remote_ip: "10.255.255.13", |
| 1017 | data_win_system_eventID: "1", |
| 1018 | gl2_remote_port: 36714, |
| 1019 | agent_labels_customer: "bkomanh1", |
| 1020 | source: "10.255.255.13", |
| 1021 | gl2_source_input: "6459151dea00fd5d3da2df91", |
| 1022 | rule_level: 12, |
| 1023 | data_win_eventdata_originalFileName: "sdbinst.exe", |
| 1024 | data_win_eventdata_company: "Microsoft Corporation", |
| 1025 | data_win_system_task: "1", |
| 1026 | timestamp_utc: "2023-11-05T12:34:39.363Z", |
| 1027 | syslog_type: AlertSourceSyslogType.Wazuh, |
| 1028 | data_win_system_threadID: "4928", |
| 1029 | rule_description: "Application Compatibility Database launched", |
| 1030 | data_win_eventdata_parentUser: "NT AUTHORITY\\\\SYSTEM", |
| 1031 | gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38", |
| 1032 | id: "1699187674.709551442", |
| 1033 | rule_mitre_tactic: "Privilege Escalation, Persistence", |
| 1034 | gl2_accounted_message_size: 7629, |
| 1035 | data_win_eventdata_integrityLevel: AlertSourceDataWinEventdataIntegrityLevel.System, |
| 1036 | data_win_eventdata_utcTime: "2023-11-05 12:34:39.359", |
| 1037 | streams: ["650b315d5e9a2d550c6687ae"], |
| 1038 | rule_mitre_id: "T1546.011", |
| 1039 | gl2_message_id: "01HEFQMNETVW5WV1DMEJR3V2FD", |
| 1040 | data_win_system_computer: "WinDev2308Eval", |
| 1041 | data_win_eventdata_currentDirectory: "C:\\\\Windows\\\\system32\\\\", |
| 1042 | agent_ip_reserved_ip: true, |
| 1043 | data_win_eventdata_ruleName: "technique_id=T1546.011,technique_name=Application Shimming", |
| 1044 | data_win_eventdata_hashes: |
| 1045 | "SHA1=C0C9554DCEBF89ABC7DA5332037BC2C88A3B0F1E,MD5=72A442005F409F233C223E60A7A0D868,SHA256=5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77,IMPHASH=999B9DCD61DAB941B1E8D50FE6EF72CD", |
| 1046 | agent_ip: "172.26.161.217", |
| 1047 | data_win_eventdata_image: "C:\\\\Windows\\\\System32\\\\sdbinst.exe", |
| 1048 | data_win_eventdata_parentProcessGuid: "{10906cbf-9e07-6528-8600-000000000e00}", |
| 1049 | true: 1699187674.749328, |
| 1050 | data_win_eventdata_parentProcessId: "5952", |
| 1051 | rule_groups: "sysmon, sysmon_eid1_detections, windows", |
| 1052 | data_win_system_keywords: "0x8000000000000000", |
| 1053 | data_win_system_level: "4", |
| 1054 | data_win_eventdata_fileVersion: "10.0.22621.2361 (WinBuild.160101.0800)", |
| 1055 | data_win_eventdata_parentImage: "C:\\\\Windows\\\\System32\\\\svchost.exe", |
| 1056 | process_id: "7076", |
| 1057 | data_win_system_severityValue: AlertSourceDataWinSystemSeverityValue.Information, |
| 1058 | data_win_eventdata_processGuid: "{10906cbf-8bdf-6547-fe84-010000000e00}", |
| 1059 | rule_mitre_technique: "Application Shimming", |
| 1060 | rule_firedtimes: 1, |
| 1061 | data_win_system_systemTime: "2023-11-05T12:34:39.3631014Z", |
| 1062 | rule_mail: true, |
| 1063 | decoder_name: AlertSourceDecoderName.WindowsEventchannel, |
| 1064 | data_win_eventdata_commandLine: "C:\\\\Windows\\\\System32\\\\sdbinst.exe -m -bg", |
| 1065 | data_win_system_processID: "3808", |
| 1066 | data_win_system_channel: "Microsoft-Windows-Sysmon/Operational", |
| 1067 | syslog_level: AlertSourceSyslogLevel.Alert, |
| 1068 | data_win_system_providerName: "Microsoft-Windows-Sysmon", |
| 1069 | data_win_eventdata_processId: "7076", |
| 1070 | data_win_system_version: "5", |
| 1071 | data_win_system_providerGuid: "{5770385f-c22a-43e0-bf4c-06f5698ffbd9}", |
| 1072 | timestamp: "2023-11-05 12:34:36.634", |
| 1073 | data_win_eventdata_parentCommandLine: |
| 1074 | "C:\\\\Windows\\\\system32\\\\svchost.exe -k LocalSystemNetworkRestricted -p -s PcaSvc", |
| 1075 | data_win_system_opcode: "0", |
| 1076 | gl2_processing_error: |
| 1077 | 'Replaced invalid timestamp value in message <ae3aac92-7bd7-11ee-93bc-86000046278a> with current time - Value <2023-11-05T12:34:34.734+0000> caused exception: Invalid format: "2023-11-05T12:34:34.734+0000" is malformed at "T12:34:34.734+0000".', |
| 1078 | data_win_eventdata_terminalSessionId: "0", |
| 1079 | message: |
| 1080 | '{"true":1699187674.749328,"timestamp":"2023-11-05T12:34:34.734+0000","rule":{"level":12,"description":"Application Compatibility Database launched","id":"92058","mitre":{"id":["T1546.011"],"tactic":["Privilege Escalation","Persistence"],"technique":["Application Shimming"]},"firedtimes":1,"mail":true,"groups":["sysmon","sysmon_eid1_detections","windows"]},"agent":{"id":"068","name":"WinDev2308Eval","ip":"172.26.161.217","labels":{"customer":"bkomanh1"}},"manager":{"name":"ASHWZHMA"},"id":"1699187674.709551442","decoder":{"name":"windows_eventchannel"},"data":{"win":{"system":{"providerName":"Microsoft-Windows-Sysmon","providerGuid":"{5770385f-c22a-43e0-bf4c-06f5698ffbd9}","eventID":"1","version":"5","level":"4","task":"1","opcode":"0","keywords":"0x8000000000000000","systemTime":"2023-11-05T12:34:39.3631014Z","eventRecordID":"834890","processID":"3808","threadID":"4928","channel":"Microsoft-Windows-Sysmon/Operational","computer":"WinDev2308Eval","severityValue":"INFORMATION","message":"\\"Process Create:\\r\\nRuleName: technique_id=T1546.011,technique_name=Application Shimming\\r\\nUtcTime: 2023-11-05 12:34:39.359\\r\\nProcessGuid: {10906cbf-8bdf-6547-fe84-010000000e00}\\r\\nProcessId: 7076\\r\\nImage: C:\\\\Windows\\\\System32\\\\sdbinst.exe\\r\\nFileVersion: 10.0.22621.2361 (WinBuild.160101.0800)\\r\\nDescription: Application Compatibility Database Installer\\r\\nProduct: Microsoft® Windows® Operating System\\r\\nCompany: Microsoft Corporation\\r\\nOriginalFileName: sdbinst.exe\\r\\nCommandLine: C:\\\\Windows\\\\System32\\\\sdbinst.exe -m -bg\\r\\nCurrentDirectory: C:\\\\Windows\\\\system32\\\\\\r\\nUser: NT AUTHORITY\\\\SYSTEM\\r\\nLogonGuid: {10906cbf-9df1-6528-e703-000000000000}\\r\\nLogonId: 0x3E7\\r\\nTerminalSessionId: 0\\r\\nIntegrityLevel: System\\r\\nHashes: SHA1=C0C9554DCEBF89ABC7DA5332037BC2C88A3B0F1E,MD5=72A442005F409F233C223E60A7A0D868,SHA256=5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77,IMPHASH=999B9DCD61DAB941B1E8D50FE6EF72CD\\r\\nParentProcessGuid: {10906cbf-9e07-6528-8600-000000000e00}\\r\\nParentProcessId: 5952\\r\\nParentImage: C:\\\\Windows\\\\System32\\\\svchost.exe\\r\\nParentCommandLine: C:\\\\Windows\\\\system32\\\\svchost.exe -k LocalSystemNetworkRestricted -p -s PcaSvc\\r\\nParentUser: NT AUTHORITY\\\\SYSTEM\\""},"eventdata":{"ruleName":"technique_id=T1546.011,technique_name=Application Shimming","utcTime":"2023-11-05 12:34:39.359","processGuid":"{10906cbf-8bdf-6547-fe84-010000000e00}","processId":"7076","image":"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\sdbinst.exe","fileVersion":"10.0.22621.2361 (WinBuild.160101.0800)","description":"Application Compatibility Database Installer","product":"Microsoft® Windows® Operating System","company":"Microsoft Corporation","originalFileName":"sdbinst.exe","commandLine":"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\sdbinst.exe -m -bg","currentDirectory":"C:\\\\\\\\Windows\\\\\\\\system32\\\\\\\\","user":"NT AUTHORITY\\\\\\\\SYSTEM","logonGuid":"{10906cbf-9df1-6528-e703-000000000000}","logonId":"0x3e7","terminalSessionId":"0","integrityLevel":"System","hashes":"SHA1=C0C9554DCEBF89ABC7DA5332037BC2C88A3B0F1E,MD5=72A442005F409F233C223E60A7A0D868,SHA256=5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77,IMPHASH=999B9DCD61DAB941B1E8D50FE6EF72CD","parentProcessGuid":"{10906cbf-9e07-6528-8600-000000000e00}","parentProcessId":"5952","parentImage":"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\svchost.exe","parentCommandLine":"C:\\\\\\\\Windows\\\\\\\\system32\\\\\\\\svchost.exe -k LocalSystemNetworkRestricted -p -s PcaSvc","parentUser":"NT AUTHORITY\\\\\\\\SYSTEM"}}},"location":"EventChannel"}', |
| 1081 | rule_id: "92058", |
| 1082 | hash_sha256: "SHA256=5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77", |
| 1083 | manager_name: "ASHWZHMA", |
| 1084 | data_win_eventdata_logonGuid: "{10906cbf-9df1-6528-e703-000000000000}", |
| 1085 | data_win_eventdata_logonId: "0x3e7", |
| 1086 | location: "EventChannel", |
| 1087 | rule_group3: AlertSourceDataLogsourceProduct.Windows, |
| 1088 | data_win_system_message: |
| 1089 | '"Process Create:\r\nRuleName: technique_id=T1546.011,technique_name=Application Shimming\r\nUtcTime: 2023-11-05 12:34:39.359\r\nProcessGuid: {10906cbf-8bdf-6547-fe84-010000000e00}\r\nProcessId: 7076\r\nImage: C:\\Windows\\System32\\sdbinst.exe\r\nFileVersion: 10.0.22621.2361 (WinBuild.160101.0800)\r\nDescription: Application Compatibility Database Installer\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: sdbinst.exe\r\nCommandLine: C:\\Windows\\System32\\sdbinst.exe -m -bg\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {10906cbf-9df1-6528-e703-000000000000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: SHA1=C0C9554DCEBF89ABC7DA5332037BC2C88A3B0F1E,MD5=72A442005F409F233C223E60A7A0D868,SHA256=5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77,IMPHASH=999B9DCD61DAB941B1E8D50FE6EF72CD\r\nParentProcessGuid: {10906cbf-9e07-6528-8600-000000000e00}\r\nParentProcessId: 5952\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k LocalSystemNetworkRestricted -p -s PcaSvc\r\nParentUser: NT AUTHORITY\\SYSTEM"', |
| 1090 | msg_timestamp: "2023-11-05T12:34:34.734Z", |
| 1091 | rule_group2: "sysmon_eid1_detections", |
| 1092 | data_win_eventdata_product: "Microsoft® Windows® Operating System", |
| 1093 | rule_group1: "sysmon" |
| 1094 | }, |
| 1095 | sort: [1699187679363] |
| 1096 | }, |
| 1097 | { |
| 1098 | _index: "wazuh-bkomanh1_1", |
| 1099 | _id: "6d89de79-7bd0-11ee-93bc-86000046278a", |
| 1100 | _score: null, |
| 1101 | _source: { |
| 1102 | source_reserved_ip: true, |
| 1103 | data_win_system_eventRecordID: "10017", |
| 1104 | agent_id: "068", |
| 1105 | agent_name: "WinDev2308Eval", |
| 1106 | gl2_remote_ip: "10.255.255.13", |
| 1107 | data_win_system_eventID: "1116", |
| 1108 | data_win_eventdata_fWLink: |
| 1109 | "https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Wacatac.H!ml&threatid=2147814523&enterprise=0", |
| 1110 | gl2_remote_port: 37408, |
| 1111 | rule_tsc: "A1.2, CC7.2, CC7.3, CC6.1, CC6.8", |
| 1112 | agent_labels_customer: "bkomanh1", |
| 1113 | source: "10.255.255.13", |
| 1114 | gl2_source_input: "6459151dea00fd5d3da2df91", |
| 1115 | rule_level: 12, |
| 1116 | data_win_system_task: "0", |
| 1117 | timestamp_utc: "2023-11-05T11:42:41.269Z", |
| 1118 | syslog_type: AlertSourceSyslogType.Wazuh, |
| 1119 | data_win_system_threadID: "1424", |
| 1120 | rule_description: |
| 1121 | "Windows Defender: Antimalware platform detected potentially unwanted software ()", |
| 1122 | gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38", |
| 1123 | id: "1699184556.662819009", |
| 1124 | gl2_accounted_message_size: 6560, |
| 1125 | streams: ["650b315d5e9a2d550c6687ae"], |
| 1126 | gl2_message_id: "01HEFMNKESZFXFE4JGPJ43SFF6", |
| 1127 | data_win_system_computer: "WinDev2308Eval", |
| 1128 | agent_ip_reserved_ip: true, |
| 1129 | agent_ip: "172.26.161.217", |
| 1130 | true: 1699184556.769473, |
| 1131 | rule_hipaa: "164.312.b", |
| 1132 | rule_groups: "windows, windows_defender", |
| 1133 | data_win_system_keywords: "0x8000000000000000", |
| 1134 | data_win_system_level: "3", |
| 1135 | process_id: "3772", |
| 1136 | data_win_system_severityValue: AlertSourceDataWinSystemSeverityValue.Warning, |
| 1137 | rule_gdpr: "IV_35.7.d", |
| 1138 | rule_firedtimes: 1, |
| 1139 | data_win_system_systemTime: "2023-11-05T11:42:41.2693093Z", |
| 1140 | rule_mail: true, |
| 1141 | rule_pci_dss: "5.1, 5.2, 10.6.1, 11.4", |
| 1142 | rule_nist_800_53: "SI.3, AU.6, SI.4", |
| 1143 | decoder_name: AlertSourceDecoderName.WindowsEventchannel, |
| 1144 | data_win_system_processID: "3772", |
| 1145 | data_win_system_channel: "Microsoft-Windows-Windows Defender/Operational", |
| 1146 | syslog_level: AlertSourceSyslogLevel.Alert, |
| 1147 | data_win_system_providerName: "Microsoft-Windows-Windows Defender", |
| 1148 | data_win_system_version: "0", |
| 1149 | data_win_system_providerGuid: "{11cd958a-c507-4ef3-b3f2-5fd9dfbd2c78}", |
| 1150 | timestamp: "2023-11-05 11:42:41.625", |
| 1151 | data_win_eventdata_path: |
| 1152 | "containerfile:_C:\\\\Users\\\\User\\\\Desktop\\\\Email Extractor Professional Edition v7.3.3.6 Full Activated - WwW.Dr-FarFar.CoM.zip; file:_C:\\\\Users\\\\User\\\\Desktop\\\\Email Extractor Professional Edition v7.3.3.6 Full Activated - WwW.Dr-FarFar.CoM.zip->Setup/Email Extractor Professional Edition Full Activated.exe->(inno#000059)", |
| 1153 | data_win_system_opcode: "0", |
| 1154 | gl2_processing_error: |
| 1155 | 'Replaced invalid timestamp value in message <6d89de79-7bd0-11ee-93bc-86000046278a> with current time - Value <2023-11-05T11:42:36.668+0000> caused exception: Invalid format: "2023-11-05T11:42:36.668+0000" is malformed at "T11:42:36.668+0000".', |
| 1156 | message: |
| 1157 | '{"true":1699184556.769473,"timestamp":"2023-11-05T11:42:36.668+0000","rule":{"level":12,"description":"Windows Defender: Antimalware platform detected potentially unwanted software ()","id":"62123","firedtimes":1,"mail":true,"groups":["windows","windows_defender"],"pci_dss":["5.1","5.2","10.6.1","11.4"],"gpg13":["4.2"],"gdpr":["IV_35.7.d"],"hipaa":["164.312.b"],"nist_800_53":["SI.3","AU.6","SI.4"],"tsc":["A1.2","CC7.2","CC7.3","CC6.1","CC6.8"]},"agent":{"id":"068","name":"WinDev2308Eval","ip":"172.26.161.217","labels":{"customer":"bkomanh1"}},"manager":{"name":"ASHWZHMA"},"id":"1699184556.662819009","decoder":{"name":"windows_eventchannel"},"data":{"win":{"system":{"providerName":"Microsoft-Windows-Windows Defender","providerGuid":"{11cd958a-c507-4ef3-b3f2-5fd9dfbd2c78}","eventID":"1116","version":"0","level":"3","task":"0","opcode":"0","keywords":"0x8000000000000000","systemTime":"2023-11-05T11:42:41.2693093Z","eventRecordID":"10017","processID":"3772","threadID":"1424","channel":"Microsoft-Windows-Windows Defender/Operational","computer":"WinDev2308Eval","severityValue":"WARNING","message":"\\"Microsoft Defender Antivirus has detected malware or other potentially unwanted software.\\r\\n For more information please see the following:\\r\\nhttps://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Wacatac.H!ml&threatid=2147814523&enterprise=0\\r\\n \\tName: Trojan:Win32/Wacatac.H!ml\\r\\n \\tID: 2147814523\\r\\n \\tSeverity: Severe\\r\\n \\tCategory: Trojan\\r\\n \\tPath: containerfile:_C:\\\\Users\\\\User\\\\Desktop\\\\Email Extractor Professional Edition v7.3.3.6 Full Activated - WwW.Dr-FarFar.CoM.zip; file:_C:\\\\Users\\\\User\\\\Desktop\\\\Email Extractor Professional Edition v7.3.3.6 Full Activated - WwW.Dr-FarFar.CoM.zip->Setup/Email Extractor Professional Edition Full Activated.exe->(inno#000059)\\r\\n \\tDetection Origin: Local machine\\r\\n \\tDetection Type: FastPath\\r\\n \\tDetection Source: System\\r\\n \\tUser: NT AUTHORITY\\\\SYSTEM\\r\\n \\tProcess Name: Unknown\\r\\n \\tSecurity intelligence Version: AV: 1.399.1651.0, AS: 1.399.1651.0, NIS: 1.399.1651.0\\r\\n \\tEngine Version: AM: 1.1.23090.2007, NIS: 1.1.23090.2007\\""},"eventdata":{"product Name":"Microsoft Defender Antivirus","product Version":"4.18.23090.2008","detection ID":"{8ECA5A94-47DE-4F30-B462-E46EE7427324}","detection Time":"2023-11-05T11:42:39.792Z","threat ID":"2147814523","threat Name":"Trojan:Win32/Wacatac.H!ml","severity ID":"5","severity Name":"Severe","category ID":"8","category Name":"Trojan","fWLink":"https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Wacatac.H!ml&threatid=2147814523&enterprise=0","status Code":"1","state":"1","source ID":"2","source Name":"System","process Name":"Unknown","detection User":"NT AUTHORITY\\\\\\\\SYSTEM","path":"containerfile:_C:\\\\\\\\Users\\\\\\\\User\\\\\\\\Desktop\\\\\\\\Email Extractor Professional Edition v7.3.3.6 Full Activated - WwW.Dr-FarFar.CoM.zip; file:_C:\\\\\\\\Users\\\\\\\\User\\\\\\\\Desktop\\\\\\\\Email Extractor Professional Edition v7.3.3.6 Full Activated - WwW.Dr-FarFar.CoM.zip->Setup/Email Extractor Professional Edition Full Activated.exe->(inno#000059)","origin ID":"1","origin Name":"Local machine","execution ID":"0","execution Name":"Unknown","type ID":"8","type Name":"FastPath","pre Execution Status":"0","action ID":"9","action Name":"Not Applicable","error Code":"0x00000000","error Description":"The operation completed successfully.","post Clean Status":"0","additional Actions ID":"0","additional Actions String":"No additional actions required","security intelligence Version":"AV: 1.399.1651.0, AS: 1.399.1651.0, NIS: 1.399.1651.0","engine Version":"AM: 1.1.23090.2007, NIS: 1.1.23090.2007"}}},"location":"EventChannel"}', |
| 1158 | rule_id: "62123", |
| 1159 | manager_name: "ASHWZHMA", |
| 1160 | rule_gpg13: "4.2", |
| 1161 | data_win_eventdata_state: "1", |
| 1162 | location: "EventChannel", |
| 1163 | data_win_system_message: |
| 1164 | '"Microsoft Defender Antivirus has detected malware or other potentially unwanted software.\r\n For more information please see the following:\r\nhttps://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Wacatac.H!ml&threatid=2147814523&enterprise=0\r\n \tName: Trojan:Win32/Wacatac.H!ml\r\n \tID: 2147814523\r\n \tSeverity: Severe\r\n \tCategory: Trojan\r\n \tPath: containerfile:_C:\\Users\\User\\Desktop\\Email Extractor Professional Edition v7.3.3.6 Full Activated - WwW.Dr-FarFar.CoM.zip; file:_C:\\Users\\User\\Desktop\\Email Extractor Professional Edition v7.3.3.6 Full Activated - WwW.Dr-FarFar.CoM.zip->Setup/Email Extractor Professional Edition Full Activated.exe->(inno#000059)\r\n \tDetection Origin: Local machine\r\n \tDetection Type: FastPath\r\n \tDetection Source: System\r\n \tUser: NT AUTHORITY\\SYSTEM\r\n \tProcess Name: Unknown\r\n \tSecurity intelligence Version: AV: 1.399.1651.0, AS: 1.399.1651.0, NIS: 1.399.1651.0\r\n \tEngine Version: AM: 1.1.23090.2007, NIS: 1.1.23090.2007"', |
| 1165 | msg_timestamp: "2023-11-05T11:42:36.668Z", |
| 1166 | rule_group2: "windows_defender", |
| 1167 | rule_group1: "windows" |
| 1168 | }, |
| 1169 | sort: [1699184561269] |
| 1170 | }, |
| 1171 | { |
| 1172 | _index: "wazuh-bkomanh1_1", |
| 1173 | _id: "4c764493-7bcf-11ee-93bc-86000046278a", |
| 1174 | _score: null, |
| 1175 | _source: { |
| 1176 | data_win_eventdata_description: "Application Compatibility Database Installer", |
| 1177 | source_reserved_ip: true, |
| 1178 | data_win_system_eventRecordID: "833927", |
| 1179 | data_win_eventdata_user: "NT AUTHORITY\\\\SYSTEM", |
| 1180 | agent_id: "068", |
| 1181 | agent_name: "WinDev2308Eval", |
| 1182 | sha256: "5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77", |
| 1183 | gl2_remote_ip: "10.255.255.13", |
| 1184 | data_win_system_eventID: "1", |
| 1185 | gl2_remote_port: 53864, |
| 1186 | agent_labels_customer: "bkomanh1", |
| 1187 | source: "10.255.255.13", |
| 1188 | gl2_source_input: "6459151dea00fd5d3da2df91", |
| 1189 | rule_level: 12, |
| 1190 | data_win_eventdata_originalFileName: "sdbinst.exe", |
| 1191 | data_win_eventdata_company: "Microsoft Corporation", |
| 1192 | data_win_system_task: "1", |
| 1193 | timestamp_utc: "2023-11-05T11:34:39.282Z", |
| 1194 | syslog_type: AlertSourceSyslogType.Wazuh, |
| 1195 | data_win_system_threadID: "4928", |
| 1196 | rule_description: "Application Compatibility Database launched", |
| 1197 | data_win_eventdata_parentUser: "NT AUTHORITY\\\\SYSTEM", |
| 1198 | gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38", |
| 1199 | id: "1699184073.657048982", |
| 1200 | rule_mitre_tactic: "Privilege Escalation, Persistence", |
| 1201 | gl2_accounted_message_size: 7629, |
| 1202 | data_win_eventdata_integrityLevel: AlertSourceDataWinEventdataIntegrityLevel.System, |
| 1203 | data_win_eventdata_utcTime: "2023-11-05 11:34:39.276", |
| 1204 | streams: ["650b315d5e9a2d550c6687ae"], |
| 1205 | rule_mitre_id: "T1546.011", |
| 1206 | gl2_message_id: "01HEFM6STTQE4PJPF9Q1AC96JZ", |
| 1207 | data_win_system_computer: "WinDev2308Eval", |
| 1208 | data_win_eventdata_currentDirectory: "C:\\\\Windows\\\\system32\\\\", |
| 1209 | agent_ip_reserved_ip: true, |
| 1210 | data_win_eventdata_ruleName: "technique_id=T1546.011,technique_name=Application Shimming", |
| 1211 | data_win_eventdata_hashes: |
| 1212 | "SHA1=C0C9554DCEBF89ABC7DA5332037BC2C88A3B0F1E,MD5=72A442005F409F233C223E60A7A0D868,SHA256=5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77,IMPHASH=999B9DCD61DAB941B1E8D50FE6EF72CD", |
| 1213 | agent_ip: "172.26.161.217", |
| 1214 | data_win_eventdata_image: "C:\\\\Windows\\\\System32\\\\sdbinst.exe", |
| 1215 | data_win_eventdata_parentProcessGuid: "{10906cbf-9e07-6528-8600-000000000e00}", |
| 1216 | true: 1699184073.810394, |
| 1217 | data_win_eventdata_parentProcessId: "5952", |
| 1218 | rule_groups: "sysmon, sysmon_eid1_detections, windows", |
| 1219 | data_win_system_keywords: "0x8000000000000000", |
| 1220 | data_win_system_level: "4", |
| 1221 | data_win_eventdata_fileVersion: "10.0.22621.2361 (WinBuild.160101.0800)", |
| 1222 | data_win_eventdata_parentImage: "C:\\\\Windows\\\\System32\\\\svchost.exe", |
| 1223 | process_id: "1800", |
| 1224 | data_win_system_severityValue: AlertSourceDataWinSystemSeverityValue.Information, |
| 1225 | data_win_eventdata_processGuid: "{10906cbf-7dcf-6547-6284-010000000e00}", |
| 1226 | rule_mitre_technique: "Application Shimming", |
| 1227 | rule_firedtimes: 1, |
| 1228 | data_win_system_systemTime: "2023-11-05T11:34:39.2824291Z", |
| 1229 | rule_mail: true, |
| 1230 | decoder_name: AlertSourceDecoderName.WindowsEventchannel, |
| 1231 | data_win_eventdata_commandLine: "C:\\\\Windows\\\\System32\\\\sdbinst.exe -m -bg", |
| 1232 | data_win_system_processID: "3808", |
| 1233 | data_win_system_channel: "Microsoft-Windows-Sysmon/Operational", |
| 1234 | syslog_level: AlertSourceSyslogLevel.Alert, |
| 1235 | data_win_system_providerName: "Microsoft-Windows-Sysmon", |
| 1236 | data_win_eventdata_processId: "1800", |
| 1237 | data_win_system_version: "5", |
| 1238 | data_win_system_providerGuid: "{5770385f-c22a-43e0-bf4c-06f5698ffbd9}", |
| 1239 | timestamp: "2023-11-05 11:34:36.634", |
| 1240 | data_win_eventdata_parentCommandLine: |
| 1241 | "C:\\\\Windows\\\\system32\\\\svchost.exe -k LocalSystemNetworkRestricted -p -s PcaSvc", |
| 1242 | data_win_system_opcode: "0", |
| 1243 | gl2_processing_error: |
| 1244 | 'Replaced invalid timestamp value in message <4c764493-7bcf-11ee-93bc-86000046278a> with current time - Value <2023-11-05T11:34:33.778+0000> caused exception: Invalid format: "2023-11-05T11:34:33.778+0000" is malformed at "T11:34:33.778+0000".', |
| 1245 | data_win_eventdata_terminalSessionId: "0", |
| 1246 | message: |
| 1247 | '{"true":1699184073.810394,"timestamp":"2023-11-05T11:34:33.778+0000","rule":{"level":12,"description":"Application Compatibility Database launched","id":"92058","mitre":{"id":["T1546.011"],"tactic":["Privilege Escalation","Persistence"],"technique":["Application Shimming"]},"firedtimes":1,"mail":true,"groups":["sysmon","sysmon_eid1_detections","windows"]},"agent":{"id":"068","name":"WinDev2308Eval","ip":"172.26.161.217","labels":{"customer":"bkomanh1"}},"manager":{"name":"ASHWZHMA"},"id":"1699184073.657048982","decoder":{"name":"windows_eventchannel"},"data":{"win":{"system":{"providerName":"Microsoft-Windows-Sysmon","providerGuid":"{5770385f-c22a-43e0-bf4c-06f5698ffbd9}","eventID":"1","version":"5","level":"4","task":"1","opcode":"0","keywords":"0x8000000000000000","systemTime":"2023-11-05T11:34:39.2824291Z","eventRecordID":"833927","processID":"3808","threadID":"4928","channel":"Microsoft-Windows-Sysmon/Operational","computer":"WinDev2308Eval","severityValue":"INFORMATION","message":"\\"Process Create:\\r\\nRuleName: technique_id=T1546.011,technique_name=Application Shimming\\r\\nUtcTime: 2023-11-05 11:34:39.276\\r\\nProcessGuid: {10906cbf-7dcf-6547-6284-010000000e00}\\r\\nProcessId: 1800\\r\\nImage: C:\\\\Windows\\\\System32\\\\sdbinst.exe\\r\\nFileVersion: 10.0.22621.2361 (WinBuild.160101.0800)\\r\\nDescription: Application Compatibility Database Installer\\r\\nProduct: Microsoft® Windows® Operating System\\r\\nCompany: Microsoft Corporation\\r\\nOriginalFileName: sdbinst.exe\\r\\nCommandLine: C:\\\\Windows\\\\System32\\\\sdbinst.exe -m -bg\\r\\nCurrentDirectory: C:\\\\Windows\\\\system32\\\\\\r\\nUser: NT AUTHORITY\\\\SYSTEM\\r\\nLogonGuid: {10906cbf-9df1-6528-e703-000000000000}\\r\\nLogonId: 0x3E7\\r\\nTerminalSessionId: 0\\r\\nIntegrityLevel: System\\r\\nHashes: SHA1=C0C9554DCEBF89ABC7DA5332037BC2C88A3B0F1E,MD5=72A442005F409F233C223E60A7A0D868,SHA256=5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77,IMPHASH=999B9DCD61DAB941B1E8D50FE6EF72CD\\r\\nParentProcessGuid: {10906cbf-9e07-6528-8600-000000000e00}\\r\\nParentProcessId: 5952\\r\\nParentImage: C:\\\\Windows\\\\System32\\\\svchost.exe\\r\\nParentCommandLine: C:\\\\Windows\\\\system32\\\\svchost.exe -k LocalSystemNetworkRestricted -p -s PcaSvc\\r\\nParentUser: NT AUTHORITY\\\\SYSTEM\\""},"eventdata":{"ruleName":"technique_id=T1546.011,technique_name=Application Shimming","utcTime":"2023-11-05 11:34:39.276","processGuid":"{10906cbf-7dcf-6547-6284-010000000e00}","processId":"1800","image":"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\sdbinst.exe","fileVersion":"10.0.22621.2361 (WinBuild.160101.0800)","description":"Application Compatibility Database Installer","product":"Microsoft® Windows® Operating System","company":"Microsoft Corporation","originalFileName":"sdbinst.exe","commandLine":"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\sdbinst.exe -m -bg","currentDirectory":"C:\\\\\\\\Windows\\\\\\\\system32\\\\\\\\","user":"NT AUTHORITY\\\\\\\\SYSTEM","logonGuid":"{10906cbf-9df1-6528-e703-000000000000}","logonId":"0x3e7","terminalSessionId":"0","integrityLevel":"System","hashes":"SHA1=C0C9554DCEBF89ABC7DA5332037BC2C88A3B0F1E,MD5=72A442005F409F233C223E60A7A0D868,SHA256=5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77,IMPHASH=999B9DCD61DAB941B1E8D50FE6EF72CD","parentProcessGuid":"{10906cbf-9e07-6528-8600-000000000e00}","parentProcessId":"5952","parentImage":"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\svchost.exe","parentCommandLine":"C:\\\\\\\\Windows\\\\\\\\system32\\\\\\\\svchost.exe -k LocalSystemNetworkRestricted -p -s PcaSvc","parentUser":"NT AUTHORITY\\\\\\\\SYSTEM"}}},"location":"EventChannel"}', |
| 1248 | rule_id: "92058", |
| 1249 | hash_sha256: "SHA256=5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77", |
| 1250 | manager_name: "ASHWZHMA", |
| 1251 | data_win_eventdata_logonGuid: "{10906cbf-9df1-6528-e703-000000000000}", |
| 1252 | data_win_eventdata_logonId: "0x3e7", |
| 1253 | location: "EventChannel", |
| 1254 | rule_group3: AlertSourceDataLogsourceProduct.Windows, |
| 1255 | data_win_system_message: |
| 1256 | '"Process Create:\r\nRuleName: technique_id=T1546.011,technique_name=Application Shimming\r\nUtcTime: 2023-11-05 11:34:39.276\r\nProcessGuid: {10906cbf-7dcf-6547-6284-010000000e00}\r\nProcessId: 1800\r\nImage: C:\\Windows\\System32\\sdbinst.exe\r\nFileVersion: 10.0.22621.2361 (WinBuild.160101.0800)\r\nDescription: Application Compatibility Database Installer\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: sdbinst.exe\r\nCommandLine: C:\\Windows\\System32\\sdbinst.exe -m -bg\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {10906cbf-9df1-6528-e703-000000000000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: SHA1=C0C9554DCEBF89ABC7DA5332037BC2C88A3B0F1E,MD5=72A442005F409F233C223E60A7A0D868,SHA256=5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77,IMPHASH=999B9DCD61DAB941B1E8D50FE6EF72CD\r\nParentProcessGuid: {10906cbf-9e07-6528-8600-000000000e00}\r\nParentProcessId: 5952\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k LocalSystemNetworkRestricted -p -s PcaSvc\r\nParentUser: NT AUTHORITY\\SYSTEM"', |
| 1257 | msg_timestamp: "2023-11-05T11:34:33.778Z", |
| 1258 | rule_group2: "sysmon_eid1_detections", |
| 1259 | data_win_eventdata_product: "Microsoft® Windows® Operating System", |
| 1260 | rule_group1: "sysmon" |
| 1261 | }, |
| 1262 | sort: [1699184079282] |
| 1263 | }, |
| 1264 | { |
| 1265 | _index: "wazuh-bkomanh1_1", |
| 1266 | _id: "eab278d1-7bc6-11ee-93bc-86000046278a", |
| 1267 | _score: null, |
| 1268 | _source: { |
| 1269 | data_win_eventdata_description: "Application Compatibility Database Installer", |
| 1270 | source_reserved_ip: true, |
| 1271 | data_win_system_eventRecordID: "832940", |
| 1272 | data_win_eventdata_user: "NT AUTHORITY\\\\SYSTEM", |
| 1273 | agent_id: "068", |
| 1274 | agent_name: "WinDev2308Eval", |
| 1275 | sha256: "5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77", |
| 1276 | gl2_remote_ip: "10.255.255.13", |
| 1277 | data_win_system_eventID: "1", |
| 1278 | gl2_remote_port: 55734, |
| 1279 | agent_labels_customer: "bkomanh1", |
| 1280 | source: "10.255.255.13", |
| 1281 | gl2_source_input: "6459151dea00fd5d3da2df91", |
| 1282 | rule_level: 12, |
| 1283 | data_win_eventdata_originalFileName: "sdbinst.exe", |
| 1284 | data_win_eventdata_company: "Microsoft Corporation", |
| 1285 | data_win_system_task: "1", |
| 1286 | timestamp_utc: "2023-11-05T10:34:39.227Z", |
| 1287 | syslog_type: AlertSourceSyslogType.Wazuh, |
| 1288 | data_win_system_threadID: "4928", |
| 1289 | rule_description: "Application Compatibility Database launched", |
| 1290 | data_win_eventdata_parentUser: "NT AUTHORITY\\\\SYSTEM", |
| 1291 | gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38", |
| 1292 | id: "1699180474.607950326", |
| 1293 | rule_mitre_tactic: "Privilege Escalation, Persistence", |
| 1294 | gl2_accounted_message_size: 7634, |
| 1295 | data_win_eventdata_integrityLevel: AlertSourceDataWinEventdataIntegrityLevel.System, |
| 1296 | data_win_eventdata_utcTime: "2023-11-05 10:34:39.223", |
| 1297 | streams: ["650b315d5e9a2d550c6687ae"], |
| 1298 | rule_mitre_id: "T1546.011", |
| 1299 | gl2_message_id: "01HEFGRY6YC425JFCGQFVGDCSB", |
| 1300 | data_win_system_computer: "WinDev2308Eval", |
| 1301 | data_win_eventdata_currentDirectory: "C:\\\\Windows\\\\system32\\\\", |
| 1302 | agent_ip_reserved_ip: true, |
| 1303 | data_win_eventdata_ruleName: "technique_id=T1546.011,technique_name=Application Shimming", |
| 1304 | data_win_eventdata_hashes: |
| 1305 | "SHA1=C0C9554DCEBF89ABC7DA5332037BC2C88A3B0F1E,MD5=72A442005F409F233C223E60A7A0D868,SHA256=5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77,IMPHASH=999B9DCD61DAB941B1E8D50FE6EF72CD", |
| 1306 | agent_ip: "172.26.161.217", |
| 1307 | data_win_eventdata_image: "C:\\\\Windows\\\\System32\\\\sdbinst.exe", |
| 1308 | data_win_eventdata_parentProcessGuid: "{10906cbf-9e07-6528-8600-000000000e00}", |
| 1309 | true: 1699180474.684764, |
| 1310 | data_win_eventdata_parentProcessId: "5952", |
| 1311 | rule_groups: "sysmon, sysmon_eid1_detections, windows", |
| 1312 | data_win_system_keywords: "0x8000000000000000", |
| 1313 | data_win_system_level: "4", |
| 1314 | data_win_eventdata_fileVersion: "10.0.22621.2361 (WinBuild.160101.0800)", |
| 1315 | data_win_eventdata_parentImage: "C:\\\\Windows\\\\System32\\\\svchost.exe", |
| 1316 | process_id: "10456", |
| 1317 | data_win_system_severityValue: AlertSourceDataWinSystemSeverityValue.Information, |
| 1318 | data_win_eventdata_processGuid: "{10906cbf-6fbf-6547-bc83-010000000e00}", |
| 1319 | rule_mitre_technique: "Application Shimming", |
| 1320 | rule_firedtimes: 1, |
| 1321 | data_win_system_systemTime: "2023-11-05T10:34:39.2278008Z", |
| 1322 | rule_mail: true, |
| 1323 | decoder_name: AlertSourceDecoderName.WindowsEventchannel, |
| 1324 | data_win_eventdata_commandLine: "C:\\\\Windows\\\\System32\\\\sdbinst.exe -m -bg", |
| 1325 | data_win_system_processID: "3808", |
| 1326 | data_win_system_channel: "Microsoft-Windows-Sysmon/Operational", |
| 1327 | syslog_level: AlertSourceSyslogLevel.Alert, |
| 1328 | data_win_system_providerName: "Microsoft-Windows-Sysmon", |
| 1329 | data_win_eventdata_processId: "10456", |
| 1330 | data_win_system_version: "5", |
| 1331 | data_win_system_providerGuid: "{5770385f-c22a-43e0-bf4c-06f5698ffbd9}", |
| 1332 | timestamp: "2023-11-05 10:34:36.638", |
| 1333 | data_win_eventdata_parentCommandLine: |
| 1334 | "C:\\\\Windows\\\\system32\\\\svchost.exe -k LocalSystemNetworkRestricted -p -s PcaSvc", |
| 1335 | data_win_system_opcode: "0", |
| 1336 | gl2_processing_error: |
| 1337 | 'Replaced invalid timestamp value in message <eab278d1-7bc6-11ee-93bc-86000046278a> with current time - Value <2023-11-05T10:34:34.669+0000> caused exception: Invalid format: "2023-11-05T10:34:34.669+0000" is malformed at "T10:34:34.669+0000".', |
| 1338 | data_win_eventdata_terminalSessionId: "0", |
| 1339 | message: |
| 1340 | '{"true":1699180474.684764,"timestamp":"2023-11-05T10:34:34.669+0000","rule":{"level":12,"description":"Application Compatibility Database launched","id":"92058","mitre":{"id":["T1546.011"],"tactic":["Privilege Escalation","Persistence"],"technique":["Application Shimming"]},"firedtimes":1,"mail":true,"groups":["sysmon","sysmon_eid1_detections","windows"]},"agent":{"id":"068","name":"WinDev2308Eval","ip":"172.26.161.217","labels":{"customer":"bkomanh1"}},"manager":{"name":"ASHWZHMA"},"id":"1699180474.607950326","decoder":{"name":"windows_eventchannel"},"data":{"win":{"system":{"providerName":"Microsoft-Windows-Sysmon","providerGuid":"{5770385f-c22a-43e0-bf4c-06f5698ffbd9}","eventID":"1","version":"5","level":"4","task":"1","opcode":"0","keywords":"0x8000000000000000","systemTime":"2023-11-05T10:34:39.2278008Z","eventRecordID":"832940","processID":"3808","threadID":"4928","channel":"Microsoft-Windows-Sysmon/Operational","computer":"WinDev2308Eval","severityValue":"INFORMATION","message":"\\"Process Create:\\r\\nRuleName: technique_id=T1546.011,technique_name=Application Shimming\\r\\nUtcTime: 2023-11-05 10:34:39.223\\r\\nProcessGuid: {10906cbf-6fbf-6547-bc83-010000000e00}\\r\\nProcessId: 10456\\r\\nImage: C:\\\\Windows\\\\System32\\\\sdbinst.exe\\r\\nFileVersion: 10.0.22621.2361 (WinBuild.160101.0800)\\r\\nDescription: Application Compatibility Database Installer\\r\\nProduct: Microsoft® Windows® Operating System\\r\\nCompany: Microsoft Corporation\\r\\nOriginalFileName: sdbinst.exe\\r\\nCommandLine: C:\\\\Windows\\\\System32\\\\sdbinst.exe -m -bg\\r\\nCurrentDirectory: C:\\\\Windows\\\\system32\\\\\\r\\nUser: NT AUTHORITY\\\\SYSTEM\\r\\nLogonGuid: {10906cbf-9df1-6528-e703-000000000000}\\r\\nLogonId: 0x3E7\\r\\nTerminalSessionId: 0\\r\\nIntegrityLevel: System\\r\\nHashes: SHA1=C0C9554DCEBF89ABC7DA5332037BC2C88A3B0F1E,MD5=72A442005F409F233C223E60A7A0D868,SHA256=5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77,IMPHASH=999B9DCD61DAB941B1E8D50FE6EF72CD\\r\\nParentProcessGuid: {10906cbf-9e07-6528-8600-000000000e00}\\r\\nParentProcessId: 5952\\r\\nParentImage: C:\\\\Windows\\\\System32\\\\svchost.exe\\r\\nParentCommandLine: C:\\\\Windows\\\\system32\\\\svchost.exe -k LocalSystemNetworkRestricted -p -s PcaSvc\\r\\nParentUser: NT AUTHORITY\\\\SYSTEM\\""},"eventdata":{"ruleName":"technique_id=T1546.011,technique_name=Application Shimming","utcTime":"2023-11-05 10:34:39.223","processGuid":"{10906cbf-6fbf-6547-bc83-010000000e00}","processId":"10456","image":"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\sdbinst.exe","fileVersion":"10.0.22621.2361 (WinBuild.160101.0800)","description":"Application Compatibility Database Installer","product":"Microsoft® Windows® Operating System","company":"Microsoft Corporation","originalFileName":"sdbinst.exe","commandLine":"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\sdbinst.exe -m -bg","currentDirectory":"C:\\\\\\\\Windows\\\\\\\\system32\\\\\\\\","user":"NT AUTHORITY\\\\\\\\SYSTEM","logonGuid":"{10906cbf-9df1-6528-e703-000000000000}","logonId":"0x3e7","terminalSessionId":"0","integrityLevel":"System","hashes":"SHA1=C0C9554DCEBF89ABC7DA5332037BC2C88A3B0F1E,MD5=72A442005F409F233C223E60A7A0D868,SHA256=5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77,IMPHASH=999B9DCD61DAB941B1E8D50FE6EF72CD","parentProcessGuid":"{10906cbf-9e07-6528-8600-000000000e00}","parentProcessId":"5952","parentImage":"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\svchost.exe","parentCommandLine":"C:\\\\\\\\Windows\\\\\\\\system32\\\\\\\\svchost.exe -k LocalSystemNetworkRestricted -p -s PcaSvc","parentUser":"NT AUTHORITY\\\\\\\\SYSTEM"}}},"location":"EventChannel"}', |
| 1341 | rule_id: "92058", |
| 1342 | hash_sha256: "SHA256=5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77", |
| 1343 | manager_name: "ASHWZHMA", |
| 1344 | data_win_eventdata_logonGuid: "{10906cbf-9df1-6528-e703-000000000000}", |
| 1345 | data_win_eventdata_logonId: "0x3e7", |
| 1346 | location: "EventChannel", |
| 1347 | rule_group3: AlertSourceDataLogsourceProduct.Windows, |
| 1348 | data_win_system_message: |
| 1349 | '"Process Create:\r\nRuleName: technique_id=T1546.011,technique_name=Application Shimming\r\nUtcTime: 2023-11-05 10:34:39.223\r\nProcessGuid: {10906cbf-6fbf-6547-bc83-010000000e00}\r\nProcessId: 10456\r\nImage: C:\\Windows\\System32\\sdbinst.exe\r\nFileVersion: 10.0.22621.2361 (WinBuild.160101.0800)\r\nDescription: Application Compatibility Database Installer\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: sdbinst.exe\r\nCommandLine: C:\\Windows\\System32\\sdbinst.exe -m -bg\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {10906cbf-9df1-6528-e703-000000000000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: SHA1=C0C9554DCEBF89ABC7DA5332037BC2C88A3B0F1E,MD5=72A442005F409F233C223E60A7A0D868,SHA256=5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77,IMPHASH=999B9DCD61DAB941B1E8D50FE6EF72CD\r\nParentProcessGuid: {10906cbf-9e07-6528-8600-000000000e00}\r\nParentProcessId: 5952\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k LocalSystemNetworkRestricted -p -s PcaSvc\r\nParentUser: NT AUTHORITY\\SYSTEM"', |
| 1350 | msg_timestamp: "2023-11-05T10:34:34.669Z", |
| 1351 | rule_group2: "sysmon_eid1_detections", |
| 1352 | data_win_eventdata_product: "Microsoft® Windows® Operating System", |
| 1353 | rule_group1: "sysmon" |
| 1354 | }, |
| 1355 | sort: [1699180479227] |
| 1356 | }, |
| 1357 | { |
| 1358 | _index: "wazuh-bkomanh1_1", |
| 1359 | _id: "88ee10d0-7bbe-11ee-93bc-86000046278a", |
| 1360 | _score: null, |
| 1361 | _source: { |
| 1362 | data_win_eventdata_description: "Application Compatibility Database Installer", |
| 1363 | source_reserved_ip: true, |
| 1364 | data_win_system_eventRecordID: "832368", |
| 1365 | data_win_eventdata_user: "NT AUTHORITY\\\\SYSTEM", |
| 1366 | agent_id: "068", |
| 1367 | agent_name: "WinDev2308Eval", |
| 1368 | sha256: "5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77", |
| 1369 | gl2_remote_ip: "10.255.255.13", |
| 1370 | data_win_system_eventID: "1", |
| 1371 | gl2_remote_port: 41488, |
| 1372 | agent_labels_customer: "bkomanh1", |
| 1373 | source: "10.255.255.13", |
| 1374 | gl2_source_input: "6459151dea00fd5d3da2df91", |
| 1375 | rule_level: 12, |
| 1376 | data_win_eventdata_originalFileName: "sdbinst.exe", |
| 1377 | data_win_eventdata_company: "Microsoft Corporation", |
| 1378 | data_win_system_task: "1", |
| 1379 | timestamp_utc: "2023-11-05T09:34:39.164Z", |
| 1380 | syslog_type: AlertSourceSyslogType.Wazuh, |
| 1381 | data_win_system_threadID: "4928", |
| 1382 | rule_description: "Application Compatibility Database launched", |
| 1383 | data_win_eventdata_parentUser: "NT AUTHORITY\\\\SYSTEM", |
| 1384 | gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38", |
| 1385 | id: "1699176874.562050141", |
| 1386 | rule_mitre_tactic: "Privilege Escalation, Persistence", |
| 1387 | gl2_accounted_message_size: 7629, |
| 1388 | data_win_eventdata_integrityLevel: AlertSourceDataWinEventdataIntegrityLevel.System, |
| 1389 | data_win_eventdata_utcTime: "2023-11-05 09:34:39.158", |
| 1390 | streams: ["650b315d5e9a2d550c6687ae"], |
| 1391 | rule_mitre_id: "T1546.011", |
| 1392 | gl2_message_id: "01HEFDB2JYZDYQZM86QYF1YYTJ", |
| 1393 | data_win_system_computer: "WinDev2308Eval", |
| 1394 | data_win_eventdata_currentDirectory: "C:\\\\Windows\\\\system32\\\\", |
| 1395 | agent_ip_reserved_ip: true, |
| 1396 | data_win_eventdata_ruleName: "technique_id=T1546.011,technique_name=Application Shimming", |
| 1397 | data_win_eventdata_hashes: |
| 1398 | "SHA1=C0C9554DCEBF89ABC7DA5332037BC2C88A3B0F1E,MD5=72A442005F409F233C223E60A7A0D868,SHA256=5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77,IMPHASH=999B9DCD61DAB941B1E8D50FE6EF72CD", |
| 1399 | agent_ip: "172.26.161.217", |
| 1400 | data_win_eventdata_image: "C:\\\\Windows\\\\System32\\\\sdbinst.exe", |
| 1401 | data_win_eventdata_parentProcessGuid: "{10906cbf-9e07-6528-8600-000000000e00}", |
| 1402 | true: 1699176874.657827, |
| 1403 | data_win_eventdata_parentProcessId: "5952", |
| 1404 | rule_groups: "sysmon, sysmon_eid1_detections, windows", |
| 1405 | data_win_system_keywords: "0x8000000000000000", |
| 1406 | data_win_system_level: "4", |
| 1407 | data_win_eventdata_fileVersion: "10.0.22621.2361 (WinBuild.160101.0800)", |
| 1408 | data_win_eventdata_parentImage: "C:\\\\Windows\\\\System32\\\\svchost.exe", |
| 1409 | process_id: "1368", |
| 1410 | data_win_system_severityValue: AlertSourceDataWinSystemSeverityValue.Information, |
| 1411 | data_win_eventdata_processGuid: "{10906cbf-61af-6547-4683-010000000e00}", |
| 1412 | rule_mitre_technique: "Application Shimming", |
| 1413 | rule_firedtimes: 1, |
| 1414 | data_win_system_systemTime: "2023-11-05T09:34:39.1640751Z", |
| 1415 | rule_mail: true, |
| 1416 | decoder_name: AlertSourceDecoderName.WindowsEventchannel, |
| 1417 | data_win_eventdata_commandLine: "C:\\\\Windows\\\\System32\\\\sdbinst.exe -m -bg", |
| 1418 | data_win_system_processID: "3808", |
| 1419 | data_win_system_channel: "Microsoft-Windows-Sysmon/Operational", |
| 1420 | syslog_level: AlertSourceSyslogLevel.Alert, |
| 1421 | data_win_system_providerName: "Microsoft-Windows-Sysmon", |
| 1422 | data_win_eventdata_processId: "1368", |
| 1423 | data_win_system_version: "5", |
| 1424 | data_win_system_providerGuid: "{5770385f-c22a-43e0-bf4c-06f5698ffbd9}", |
| 1425 | timestamp: "2023-11-05 09:34:36.638", |
| 1426 | data_win_eventdata_parentCommandLine: |
| 1427 | "C:\\\\Windows\\\\system32\\\\svchost.exe -k LocalSystemNetworkRestricted -p -s PcaSvc", |
| 1428 | data_win_system_opcode: "0", |
| 1429 | gl2_processing_error: |
| 1430 | 'Replaced invalid timestamp value in message <88ee10d0-7bbe-11ee-93bc-86000046278a> with current time - Value <2023-11-05T09:34:34.642+0000> caused exception: Invalid format: "2023-11-05T09:34:34.642+0000" is malformed at "T09:34:34.642+0000".', |
| 1431 | data_win_eventdata_terminalSessionId: "0", |
| 1432 | message: |
| 1433 | '{"true":1699176874.657827,"timestamp":"2023-11-05T09:34:34.642+0000","rule":{"level":12,"description":"Application Compatibility Database launched","id":"92058","mitre":{"id":["T1546.011"],"tactic":["Privilege Escalation","Persistence"],"technique":["Application Shimming"]},"firedtimes":1,"mail":true,"groups":["sysmon","sysmon_eid1_detections","windows"]},"agent":{"id":"068","name":"WinDev2308Eval","ip":"172.26.161.217","labels":{"customer":"bkomanh1"}},"manager":{"name":"ASHWZHMA"},"id":"1699176874.562050141","decoder":{"name":"windows_eventchannel"},"data":{"win":{"system":{"providerName":"Microsoft-Windows-Sysmon","providerGuid":"{5770385f-c22a-43e0-bf4c-06f5698ffbd9}","eventID":"1","version":"5","level":"4","task":"1","opcode":"0","keywords":"0x8000000000000000","systemTime":"2023-11-05T09:34:39.1640751Z","eventRecordID":"832368","processID":"3808","threadID":"4928","channel":"Microsoft-Windows-Sysmon/Operational","computer":"WinDev2308Eval","severityValue":"INFORMATION","message":"\\"Process Create:\\r\\nRuleName: technique_id=T1546.011,technique_name=Application Shimming\\r\\nUtcTime: 2023-11-05 09:34:39.158\\r\\nProcessGuid: {10906cbf-61af-6547-4683-010000000e00}\\r\\nProcessId: 1368\\r\\nImage: C:\\\\Windows\\\\System32\\\\sdbinst.exe\\r\\nFileVersion: 10.0.22621.2361 (WinBuild.160101.0800)\\r\\nDescription: Application Compatibility Database Installer\\r\\nProduct: Microsoft® Windows® Operating System\\r\\nCompany: Microsoft Corporation\\r\\nOriginalFileName: sdbinst.exe\\r\\nCommandLine: C:\\\\Windows\\\\System32\\\\sdbinst.exe -m -bg\\r\\nCurrentDirectory: C:\\\\Windows\\\\system32\\\\\\r\\nUser: NT AUTHORITY\\\\SYSTEM\\r\\nLogonGuid: {10906cbf-9df1-6528-e703-000000000000}\\r\\nLogonId: 0x3E7\\r\\nTerminalSessionId: 0\\r\\nIntegrityLevel: System\\r\\nHashes: SHA1=C0C9554DCEBF89ABC7DA5332037BC2C88A3B0F1E,MD5=72A442005F409F233C223E60A7A0D868,SHA256=5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77,IMPHASH=999B9DCD61DAB941B1E8D50FE6EF72CD\\r\\nParentProcessGuid: {10906cbf-9e07-6528-8600-000000000e00}\\r\\nParentProcessId: 5952\\r\\nParentImage: C:\\\\Windows\\\\System32\\\\svchost.exe\\r\\nParentCommandLine: C:\\\\Windows\\\\system32\\\\svchost.exe -k LocalSystemNetworkRestricted -p -s PcaSvc\\r\\nParentUser: NT AUTHORITY\\\\SYSTEM\\""},"eventdata":{"ruleName":"technique_id=T1546.011,technique_name=Application Shimming","utcTime":"2023-11-05 09:34:39.158","processGuid":"{10906cbf-61af-6547-4683-010000000e00}","processId":"1368","image":"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\sdbinst.exe","fileVersion":"10.0.22621.2361 (WinBuild.160101.0800)","description":"Application Compatibility Database Installer","product":"Microsoft® Windows® Operating System","company":"Microsoft Corporation","originalFileName":"sdbinst.exe","commandLine":"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\sdbinst.exe -m -bg","currentDirectory":"C:\\\\\\\\Windows\\\\\\\\system32\\\\\\\\","user":"NT AUTHORITY\\\\\\\\SYSTEM","logonGuid":"{10906cbf-9df1-6528-e703-000000000000}","logonId":"0x3e7","terminalSessionId":"0","integrityLevel":"System","hashes":"SHA1=C0C9554DCEBF89ABC7DA5332037BC2C88A3B0F1E,MD5=72A442005F409F233C223E60A7A0D868,SHA256=5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77,IMPHASH=999B9DCD61DAB941B1E8D50FE6EF72CD","parentProcessGuid":"{10906cbf-9e07-6528-8600-000000000e00}","parentProcessId":"5952","parentImage":"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\svchost.exe","parentCommandLine":"C:\\\\\\\\Windows\\\\\\\\system32\\\\\\\\svchost.exe -k LocalSystemNetworkRestricted -p -s PcaSvc","parentUser":"NT AUTHORITY\\\\\\\\SYSTEM"}}},"location":"EventChannel"}', |
| 1434 | rule_id: "92058", |
| 1435 | hash_sha256: "SHA256=5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77", |
| 1436 | manager_name: "ASHWZHMA", |
| 1437 | data_win_eventdata_logonGuid: "{10906cbf-9df1-6528-e703-000000000000}", |
| 1438 | data_win_eventdata_logonId: "0x3e7", |
| 1439 | location: "EventChannel", |
| 1440 | rule_group3: AlertSourceDataLogsourceProduct.Windows, |
| 1441 | data_win_system_message: |
| 1442 | '"Process Create:\r\nRuleName: technique_id=T1546.011,technique_name=Application Shimming\r\nUtcTime: 2023-11-05 09:34:39.158\r\nProcessGuid: {10906cbf-61af-6547-4683-010000000e00}\r\nProcessId: 1368\r\nImage: C:\\Windows\\System32\\sdbinst.exe\r\nFileVersion: 10.0.22621.2361 (WinBuild.160101.0800)\r\nDescription: Application Compatibility Database Installer\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: sdbinst.exe\r\nCommandLine: C:\\Windows\\System32\\sdbinst.exe -m -bg\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {10906cbf-9df1-6528-e703-000000000000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: SHA1=C0C9554DCEBF89ABC7DA5332037BC2C88A3B0F1E,MD5=72A442005F409F233C223E60A7A0D868,SHA256=5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77,IMPHASH=999B9DCD61DAB941B1E8D50FE6EF72CD\r\nParentProcessGuid: {10906cbf-9e07-6528-8600-000000000e00}\r\nParentProcessId: 5952\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k LocalSystemNetworkRestricted -p -s PcaSvc\r\nParentUser: NT AUTHORITY\\SYSTEM"', |
| 1443 | msg_timestamp: "2023-11-05T09:34:34.642Z", |
| 1444 | rule_group2: "sysmon_eid1_detections", |
| 1445 | data_win_eventdata_product: "Microsoft® Windows® Operating System", |
| 1446 | rule_group1: "sysmon" |
| 1447 | }, |
| 1448 | sort: [1699176879164] |
| 1449 | } |
| 1450 | ] |
| 1451 | }, |
| 1452 | { |
| 1453 | index_name: "wazuh-toafb68l_2", |
| 1454 | total_alerts: 2, |
| 1455 | alerts: [ |
| 1456 | { |
| 1457 | _index: "wazuh-toafb68l_2", |
| 1458 | _id: "15d6dd81-7ba4-11ee-93bc-86000046278a", |
| 1459 | _score: null, |
| 1460 | _source: { |
| 1461 | parent_process_id: "214455", |
| 1462 | source_reserved_ip: true, |
| 1463 | agent_id: "077", |
| 1464 | agent_name: "ssdnodes-zabbix", |
| 1465 | gl2_remote_ip: "10.255.255.13", |
| 1466 | gl2_remote_port: 53816, |
| 1467 | data_columns_cwd: "/", |
| 1468 | agent_labels_customer: "toafb68l", |
| 1469 | agent_ip_city_name: "Sydney", |
| 1470 | source: "10.255.255.13", |
| 1471 | gl2_source_input: "6459151dea00fd5d3da2df91", |
| 1472 | rule_level: 12, |
| 1473 | data_calendarTime: "Sun Nov 5 06:25:09 2023 UTC", |
| 1474 | data_counter: "19295", |
| 1475 | data_columns_duration: "2809889", |
| 1476 | timestamp_utc: "2023-11-05T06:25:09.000Z", |
| 1477 | syslog_type: AlertSourceSyslogType.Wazuh, |
| 1478 | process_name: "/bin/dd", |
| 1479 | process_cmd_line: "dd if=/dev/urandom bs=2 count=1", |
| 1480 | data_hostIdentifier: "ssdnodes-zabbix", |
| 1481 | data_columns_probe_error: "0", |
| 1482 | rule_description: |
| 1483 | "Adversaries may use binary padding to add junk data and change the on-disk representation of malware. This rule detect using dd and truncate to add a junk data to file.", |
| 1484 | gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38", |
| 1485 | id: "1699165511.370373429", |
| 1486 | rule_mitre_tactic: "Defense Evasion", |
| 1487 | process_image: "/bin/dd", |
| 1488 | gl2_accounted_message_size: 2736, |
| 1489 | data_columns_uid: "0", |
| 1490 | streams: ["6518f9c15e9a2d550c8a49f1"], |
| 1491 | rule_mitre_id: "T1027", |
| 1492 | gl2_message_id: "01HEF2GCTSQMHY4KKXANGM0WNP", |
| 1493 | agent_ip: "208.87.135.165", |
| 1494 | data_columns_gid: "0", |
| 1495 | data_columns_syscall: "exec", |
| 1496 | true: 1699165511.829736, |
| 1497 | data_columns_cid: "42132", |
| 1498 | rule_groups: "osquery, bpf_process_events", |
| 1499 | data_columns_exit_code: "0", |
| 1500 | process_id: "214456", |
| 1501 | agent_ip_geolocation: "-33.8715,151.2006", |
| 1502 | rule_mitre_technique: "Obfuscated Files or Information", |
| 1503 | rule_firedtimes: 1, |
| 1504 | rule_mail: true, |
| 1505 | data_name: "bpf_process_events", |
| 1506 | decoder_name: AlertSourceDecoderName.JSON, |
| 1507 | agent_ip_country_code: "AU", |
| 1508 | data_columns_ntime: "3024028081495260", |
| 1509 | syslog_level: AlertSourceSyslogLevel.Alert, |
| 1510 | timestamp: "2023-11-05 06:25:16.633", |
| 1511 | data_columns_cmdline: "dd if=/dev/urandom bs=2 count=1", |
| 1512 | data_columns_tid: "214456", |
| 1513 | gl2_processing_error: |
| 1514 | 'Replaced invalid timestamp value in message <15d6dd81-7ba4-11ee-93bc-86000046278a> with current time - Value <2023-11-05T06:25:11.808+0000> caused exception: Invalid format: "2023-11-05T06:25:11.808+0000" is malformed at "T06:25:11.808+0000".', |
| 1515 | data_columns_pid: "214456", |
| 1516 | message: |
| 1517 | '{"true":1699165511.829736,"timestamp":"2023-11-05T06:25:11.808+0000","rule":{"level":12,"description":"Adversaries may use binary padding to add junk data and change the on-disk representation of malware. This rule detect using dd and truncate to add a junk data to file.","id":"200243","mitre":{"id":["T1027"],"tactic":["Defense Evasion"],"technique":["Obfuscated Files or Information"]},"firedtimes":1,"mail":true,"groups":["osquery","bpf_process_events"]},"agent":{"id":"077","name":"ssdnodes-zabbix","ip":"208.87.135.165","labels":{"customer":"toafb68l"}},"manager":{"name":"ASHWZHMA"},"id":"1699165511.370373429","decoder":{"name":"json"},"data":{"action":"added","name":"bpf_process_events","hostIdentifier":"ssdnodes-zabbix","calendarTime":"Sun Nov 5 06:25:09 2023 UTC","unixTime":"1699165509","epoch":"0","counter":"19295","numerics":"false","columns":{"cid":"42132","cmdline":"dd if=/dev/urandom bs=2 count=1","cwd":"/","duration":"2809889","exit_code":"0","gid":"0","ntime":"3024028081495260","parent":"214455","path":"/bin/dd","pid":"214456","probe_error":"0","syscall":"exec","tid":"214456","uid":"0"}},"location":"/var/log/osquery/osqueryd.results.log"}', |
| 1518 | data_numerics: "false", |
| 1519 | rule_id: "200243", |
| 1520 | manager_name: "ASHWZHMA", |
| 1521 | data_columns_path: "/bin/dd", |
| 1522 | data_unixTime: "1699165509", |
| 1523 | data_action: "added", |
| 1524 | data_epoch: "0", |
| 1525 | location: "/var/log/osquery/osqueryd.results.log", |
| 1526 | data_columns_parent: "214455", |
| 1527 | msg_timestamp: "2023-11-05T06:25:11.808Z", |
| 1528 | rule_group2: "bpf_process_events", |
| 1529 | rule_group1: "osquery" |
| 1530 | }, |
| 1531 | sort: [1699165509000] |
| 1532 | }, |
| 1533 | { |
| 1534 | _index: "wazuh-toafb68l_2", |
| 1535 | _id: "fd5fcbb2-7b83-11ee-93bc-86000046278a", |
| 1536 | _score: null, |
| 1537 | _source: { |
| 1538 | parent_process_id: "98528", |
| 1539 | source_reserved_ip: true, |
| 1540 | agent_id: "077", |
| 1541 | agent_name: "ssdnodes-zabbix", |
| 1542 | gl2_remote_ip: "10.255.255.13", |
| 1543 | gl2_remote_port: 54994, |
| 1544 | data_columns_cwd: "/tmp", |
| 1545 | agent_labels_customer: "toafb68l", |
| 1546 | agent_ip_city_name: "Sydney", |
| 1547 | source: "10.255.255.13", |
| 1548 | gl2_source_input: "6459151dea00fd5d3da2df91", |
| 1549 | rule_level: 12, |
| 1550 | data_calendarTime: "Sun Nov 5 02:35:28 2023 UTC", |
| 1551 | data_counter: "18098", |
| 1552 | data_columns_duration: "134246", |
| 1553 | timestamp_utc: "2023-11-05T02:35:28.000Z", |
| 1554 | syslog_type: AlertSourceSyslogType.Wazuh, |
| 1555 | process_name: "/usr/bin/chmod", |
| 1556 | process_cmd_line: "chmod +r /var/lib/update-notifier/updates-available", |
| 1557 | data_hostIdentifier: "ssdnodes-zabbix", |
| 1558 | data_columns_probe_error: "0", |
| 1559 | rule_description: "Detects file and folder permission changes.", |
| 1560 | gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38", |
| 1561 | id: "1699151730.117474775", |
| 1562 | rule_mitre_tactic: "Defense Evasion", |
| 1563 | process_image: "/usr/bin/chmod", |
| 1564 | gl2_accounted_message_size: 2594, |
| 1565 | data_columns_uid: "0", |
| 1566 | streams: ["6518f9c15e9a2d550c8a49f1"], |
| 1567 | rule_mitre_id: "T1222", |
| 1568 | gl2_message_id: "01HEENBPZC4ZK59R2RWMZ3AK9K", |
| 1569 | agent_ip: "208.87.135.165", |
| 1570 | data_columns_gid: "0", |
| 1571 | data_columns_syscall: "exec", |
| 1572 | true: 1699151730.737527, |
| 1573 | data_columns_cid: "66927", |
| 1574 | rule_groups: "osquery, bpf_process_events", |
| 1575 | data_columns_exit_code: "0", |
| 1576 | process_id: "98594", |
| 1577 | agent_ip_geolocation: "-33.8715,151.2006", |
| 1578 | rule_mitre_technique: "File and Directory Permissions Modification", |
| 1579 | rule_firedtimes: 1, |
| 1580 | rule_mail: true, |
| 1581 | data_name: "bpf_process_events", |
| 1582 | decoder_name: AlertSourceDecoderName.JSON, |
| 1583 | agent_ip_country_code: "AU", |
| 1584 | data_columns_ntime: "3010249590404014", |
| 1585 | syslog_level: AlertSourceSyslogLevel.Alert, |
| 1586 | timestamp: "2023-11-05 02:35:31.692", |
| 1587 | data_columns_cmdline: "chmod +r /var/lib/update-notifier/updates-available", |
| 1588 | data_columns_tid: "98594", |
| 1589 | gl2_processing_error: |
| 1590 | 'Replaced invalid timestamp value in message <fd5fcbb2-7b83-11ee-93bc-86000046278a> with current time - Value <2023-11-05T02:35:30.736+0000> caused exception: Invalid format: "2023-11-05T02:35:30.736+0000" is malformed at "T02:35:30.736+0000".', |
| 1591 | data_columns_pid: "98594", |
| 1592 | message: |
| 1593 | '{"true":1699151730.737527,"timestamp":"2023-11-05T02:35:30.736+0000","rule":{"level":12,"description":"Detects file and folder permission changes.","id":"200259","mitre":{"id":["T1222"],"tactic":["Defense Evasion"],"technique":["File and Directory Permissions Modification"]},"firedtimes":1,"mail":true,"groups":["osquery","bpf_process_events"]},"agent":{"id":"077","name":"ssdnodes-zabbix","ip":"208.87.135.165","labels":{"customer":"toafb68l"}},"manager":{"name":"ASHWZHMA"},"id":"1699151730.117474775","decoder":{"name":"json"},"data":{"action":"added","name":"bpf_process_events","hostIdentifier":"ssdnodes-zabbix","calendarTime":"Sun Nov 5 02:35:28 2023 UTC","unixTime":"1699151728","epoch":"0","counter":"18098","numerics":"false","columns":{"cid":"66927","cmdline":"chmod +r /var/lib/update-notifier/updates-available","cwd":"/tmp","duration":"134246","exit_code":"0","gid":"0","ntime":"3010249590404014","parent":"98528","path":"/usr/bin/chmod","pid":"98594","probe_error":"0","syscall":"exec","tid":"98594","uid":"0"}},"location":"/var/log/osquery/osqueryd.results.log"}', |
| 1594 | data_numerics: "false", |
| 1595 | rule_id: "200259", |
| 1596 | manager_name: "ASHWZHMA", |
| 1597 | data_columns_path: "/usr/bin/chmod", |
| 1598 | data_unixTime: "1699151728", |
| 1599 | data_action: "added", |
| 1600 | data_epoch: "0", |
| 1601 | location: "/var/log/osquery/osqueryd.results.log", |
| 1602 | data_columns_parent: "98528", |
| 1603 | msg_timestamp: "2023-11-05T02:35:30.736Z", |
| 1604 | rule_group2: "bpf_process_events", |
| 1605 | rule_group1: "osquery" |
| 1606 | }, |
| 1607 | sort: [1699151728000] |
| 1608 | } |
| 1609 | ] |
| 1610 | }, |
| 1611 | { |
| 1612 | index_name: "wazuh-wso4vxhq_8", |
| 1613 | total_alerts: 5, |
| 1614 | alerts: [ |
| 1615 | { |
| 1616 | _index: "wazuh-wso4vxhq_8", |
| 1617 | _id: "e1c93161-7bda-11ee-93bc-86000046278a", |
| 1618 | _score: null, |
| 1619 | _source: { |
| 1620 | source_reserved_ip: true, |
| 1621 | data_win_system_eventRecordID: "4882778", |
| 1622 | agent_id: "070", |
| 1623 | agent_name: "web1", |
| 1624 | data_win_eventdata_sourceProcessGUID: "{d9ab9ebb-7e1a-6544-44e0-010000003000}", |
| 1625 | gl2_remote_ip: "10.255.255.13", |
| 1626 | data_win_system_eventID: "10", |
| 1627 | gl2_remote_port: 57078, |
| 1628 | agent_labels_customer: "wso4vxhq", |
| 1629 | agent_ip_city_name: "N/A", |
| 1630 | source: "10.255.255.13", |
| 1631 | data_win_eventdata_targetImage: "C:\\\\Windows\\\\explorer.exe", |
| 1632 | gl2_source_input: "6459151dea00fd5d3da2df91", |
| 1633 | rule_level: 12, |
| 1634 | data_win_eventdata_sourceUser: "WEB1\\\\Administrator", |
| 1635 | data_win_system_task: "10", |
| 1636 | timestamp_utc: "2023-11-05T12:57:26.938Z", |
| 1637 | syslog_type: AlertSourceSyslogType.Wazuh, |
| 1638 | data_win_system_threadID: "5576", |
| 1639 | rule_description: |
| 1640 | "Explorer process was accessed by C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe, possible process injection", |
| 1641 | gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38", |
| 1642 | id: "1699189047.740504296", |
| 1643 | data_win_eventdata_grantedAccess: "0x40", |
| 1644 | data_win_eventdata_sourceImage: |
| 1645 | "C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe", |
| 1646 | rule_mitre_tactic: "Defense Evasion, Privilege Escalation", |
| 1647 | gl2_accounted_message_size: 11454, |
| 1648 | data_win_eventdata_utcTime: "2023-11-05 12:57:26.937", |
| 1649 | streams: ["650d3da25e9a2d550c6d6491"], |
| 1650 | rule_mitre_id: "T1055", |
| 1651 | gl2_message_id: "01HEFRYM77XPQT25DBE9HD17DT", |
| 1652 | data_win_system_computer: "web1", |
| 1653 | data_win_eventdata_ruleName: "technique_id=T1036,technique_name=Masquerading", |
| 1654 | agent_ip: "202.43.110.138", |
| 1655 | true: 1699189047.88765, |
| 1656 | rule_groups: "sysmon, sysmon_eid10_detections, windows", |
| 1657 | data_win_system_keywords: "0x8000000000000000", |
| 1658 | data_win_system_level: "4", |
| 1659 | data_win_eventdata_targetProcessGUID: "{d9ab9ebb-62bb-6547-601c-020000003000}", |
| 1660 | data_win_system_severityValue: AlertSourceDataWinSystemSeverityValue.Information, |
| 1661 | data_win_eventdata_targetUser: "WEB1\\\\Administrator", |
| 1662 | agent_ip_geolocation: "16.1667,107.8333", |
| 1663 | rule_mitre_technique: "Process Injection", |
| 1664 | rule_firedtimes: 86, |
| 1665 | data_win_system_systemTime: "2023-11-05T12:57:26.938209400Z", |
| 1666 | rule_mail: true, |
| 1667 | decoder_name: AlertSourceDecoderName.WindowsEventchannel, |
| 1668 | agent_ip_country_code: "VN", |
| 1669 | data_win_system_processID: "3468", |
| 1670 | data_win_system_channel: "Microsoft-Windows-Sysmon/Operational", |
| 1671 | syslog_level: AlertSourceSyslogLevel.Alert, |
| 1672 | data_win_system_providerName: "Microsoft-Windows-Sysmon", |
| 1673 | data_win_system_version: "3", |
| 1674 | data_win_system_providerGuid: "{5770385f-c22a-43e0-bf4c-06f5698ffbd9}", |
| 1675 | timestamp: "2023-11-05 12:57:31.623", |
| 1676 | data_win_eventdata_callTrace: |
| 1677 | "C:\\\\Windows\\\\SYSTEM32\\\\ntdll.dll+9ff24|C:\\\\Windows\\\\System32\\\\KERNELBASE.dll+1668e|C:\\\\Windows\\\\System32\\\\shcore.dll+cca8|C:\\\\Windows\\\\System32\\\\shcore.dll+ba62|C:\\\\Windows\\\\System32\\\\shcore.dll+b585|C:\\\\Windows\\\\System32\\\\shcore.dll+b275|C:\\\\Windows\\\\System32\\\\shcore.dll+b209|C:\\\\Windows\\\\System32\\\\shcore.dll+b104|C:\\\\Windows\\\\system32\\\\explorerframe.dll+12b986|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+157bd8c|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+18051ce|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2e1a17|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2dfdfe|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+130216a|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a566ec|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a5695f|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3e93b|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c40433|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb8e|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3d62541|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb68|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c942dd|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3db94|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a52491", |
| 1678 | data_win_system_opcode: "0", |
| 1679 | gl2_processing_error: |
| 1680 | 'Replaced invalid timestamp value in message <e1c93161-7bda-11ee-93bc-86000046278a> with current time - Value <2023-11-05T12:57:27.609+0000> caused exception: Invalid format: "2023-11-05T12:57:27.609+0000" is malformed at "T12:57:27.609+0000".', |
| 1681 | data_win_eventdata_sourceProcessId: "1652", |
| 1682 | message: |
| 1683 | '{"true":1699189047.88765,"timestamp":"2023-11-05T12:57:27.609+0000","rule":{"level":12,"description":"Explorer process was accessed by C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe, possible process injection","id":"92910","mitre":{"id":["T1055"],"tactic":["Defense Evasion","Privilege Escalation"],"technique":["Process Injection"]},"firedtimes":86,"mail":true,"groups":["sysmon","sysmon_eid10_detections","windows"]},"agent":{"id":"070","name":"web1","ip":"202.43.110.138","labels":{"customer":"wso4vxhq"}},"manager":{"name":"ASHWZHMA"},"id":"1699189047.740504296","decoder":{"name":"windows_eventchannel"},"data":{"win":{"system":{"providerName":"Microsoft-Windows-Sysmon","providerGuid":"{5770385f-c22a-43e0-bf4c-06f5698ffbd9}","eventID":"10","version":"3","level":"4","task":"10","opcode":"0","keywords":"0x8000000000000000","systemTime":"2023-11-05T12:57:26.938209400Z","eventRecordID":"4882778","processID":"3468","threadID":"5576","channel":"Microsoft-Windows-Sysmon/Operational","computer":"web1","severityValue":"INFORMATION","message":"\\"Process accessed:\\r\\nRuleName: technique_id=T1036,technique_name=Masquerading\\r\\nUtcTime: 2023-11-05 12:57:26.937\\r\\nSourceProcessGUID: {d9ab9ebb-7e1a-6544-44e0-010000003000}\\r\\nSourceProcessId: 1652\\r\\nSourceThreadId: 1284\\r\\nSourceImage: C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe\\r\\nTargetProcessGUID: {d9ab9ebb-62bb-6547-601c-020000003000}\\r\\nTargetProcessId: 4384\\r\\nTargetImage: C:\\\\Windows\\\\explorer.exe\\r\\nGrantedAccess: 0x40\\r\\nCallTrace: C:\\\\Windows\\\\SYSTEM32\\\\ntdll.dll+9ff24|C:\\\\Windows\\\\System32\\\\KERNELBASE.dll+1668e|C:\\\\Windows\\\\System32\\\\shcore.dll+cca8|C:\\\\Windows\\\\System32\\\\shcore.dll+ba62|C:\\\\Windows\\\\System32\\\\shcore.dll+b585|C:\\\\Windows\\\\System32\\\\shcore.dll+b275|C:\\\\Windows\\\\System32\\\\shcore.dll+b209|C:\\\\Windows\\\\System32\\\\shcore.dll+b104|C:\\\\Windows\\\\system32\\\\explorerframe.dll+12b986|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+157bd8c|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+18051ce|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2e1a17|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2dfdfe|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+130216a|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a566ec|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a5695f|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3e93b|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c40433|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb8e|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3d62541|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb68|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c942dd|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3db94|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a52491\\r\\nSourceUser: WEB1\\\\Administrator\\r\\nTargetUser: WEB1\\\\Administrator\\""},"eventdata":{"ruleName":"technique_id=T1036,technique_name=Masquerading","utcTime":"2023-11-05 12:57:26.937","sourceProcessGUID":"{d9ab9ebb-7e1a-6544-44e0-010000003000}","sourceProcessId":"1652","sourceThreadId":"1284","sourceImage":"C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe","targetProcessGUID":"{d9ab9ebb-62bb-6547-601c-020000003000}","targetProcessId":"4384","targetImage":"C:\\\\\\\\Windows\\\\\\\\explorer.exe","grantedAccess":"0x40","callTrace":"C:\\\\\\\\Windows\\\\\\\\SYSTEM32\\\\\\\\ntdll.dll+9ff24|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\KERNELBASE.dll+1668e|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+cca8|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+ba62|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+b585|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+b275|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+b209|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+b104|C:\\\\\\\\Windows\\\\\\\\system32\\\\\\\\explorerframe.dll+12b986|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+157bd8c|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+18051ce|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+2e1a17|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+2dfdfe|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+130216a|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+a566ec|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+a5695f|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c3e93b|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c40433|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3fbdb8e|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3d62541|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3fbdb68|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c942dd|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c3db94|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+a52491","sourceUser":"WEB1\\\\\\\\Administrator","targetUser":"WEB1\\\\\\\\Administrator"}}},"location":"EventChannel"}', |
| 1684 | rule_id: "92910", |
| 1685 | manager_name: "ASHWZHMA", |
| 1686 | location: "EventChannel", |
| 1687 | data_win_eventdata_targetProcessId: "4384", |
| 1688 | rule_group3: AlertSourceDataLogsourceProduct.Windows, |
| 1689 | data_win_system_message: |
| 1690 | '"Process accessed:\r\nRuleName: technique_id=T1036,technique_name=Masquerading\r\nUtcTime: 2023-11-05 12:57:26.937\r\nSourceProcessGUID: {d9ab9ebb-7e1a-6544-44e0-010000003000}\r\nSourceProcessId: 1652\r\nSourceThreadId: 1284\r\nSourceImage: C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe\r\nTargetProcessGUID: {d9ab9ebb-62bb-6547-601c-020000003000}\r\nTargetProcessId: 4384\r\nTargetImage: C:\\Windows\\explorer.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+9ff24|C:\\Windows\\System32\\KERNELBASE.dll+1668e|C:\\Windows\\System32\\shcore.dll+cca8|C:\\Windows\\System32\\shcore.dll+ba62|C:\\Windows\\System32\\shcore.dll+b585|C:\\Windows\\System32\\shcore.dll+b275|C:\\Windows\\System32\\shcore.dll+b209|C:\\Windows\\System32\\shcore.dll+b104|C:\\Windows\\system32\\explorerframe.dll+12b986|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+157bd8c|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+18051ce|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+2e1a17|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+2dfdfe|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+130216a|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+a566ec|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+a5695f|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c3e93b|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c40433|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3fbdb8e|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3d62541|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3fbdb68|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c942dd|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c3db94|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+a52491\r\nSourceUser: WEB1\\Administrator\r\nTargetUser: WEB1\\Administrator"', |
| 1691 | data_win_eventdata_sourceThreadId: "1284", |
| 1692 | msg_timestamp: "2023-11-05T12:57:27.609Z", |
| 1693 | rule_group2: "sysmon_eid10_detections", |
| 1694 | rule_group1: "sysmon" |
| 1695 | }, |
| 1696 | sort: [1699189046938] |
| 1697 | }, |
| 1698 | { |
| 1699 | _index: "wazuh-wso4vxhq_8", |
| 1700 | _id: "e1c97f73-7bda-11ee-93bc-86000046278a", |
| 1701 | _score: null, |
| 1702 | _source: { |
| 1703 | source_reserved_ip: true, |
| 1704 | data_win_system_eventRecordID: "4882779", |
| 1705 | agent_id: "070", |
| 1706 | agent_name: "web1", |
| 1707 | data_win_eventdata_sourceProcessGUID: "{d9ab9ebb-7e1a-6544-44e0-010000003000}", |
| 1708 | gl2_remote_ip: "10.255.255.13", |
| 1709 | data_win_system_eventID: "10", |
| 1710 | gl2_remote_port: 57078, |
| 1711 | agent_labels_customer: "wso4vxhq", |
| 1712 | agent_ip_city_name: "N/A", |
| 1713 | source: "10.255.255.13", |
| 1714 | data_win_eventdata_targetImage: "C:\\\\Windows\\\\explorer.exe", |
| 1715 | gl2_source_input: "6459151dea00fd5d3da2df91", |
| 1716 | rule_level: 12, |
| 1717 | data_win_eventdata_sourceUser: "WEB1\\\\Administrator", |
| 1718 | data_win_system_task: "10", |
| 1719 | timestamp_utc: "2023-11-05T12:57:26.938Z", |
| 1720 | syslog_type: AlertSourceSyslogType.Wazuh, |
| 1721 | data_win_system_threadID: "5576", |
| 1722 | rule_description: |
| 1723 | "Explorer process was accessed by C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe, possible process injection", |
| 1724 | gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38", |
| 1725 | id: "1699189047.740509955", |
| 1726 | data_win_eventdata_grantedAccess: "0x40", |
| 1727 | data_win_eventdata_sourceImage: |
| 1728 | "C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe", |
| 1729 | rule_mitre_tactic: "Defense Evasion, Privilege Escalation", |
| 1730 | gl2_accounted_message_size: 11630, |
| 1731 | data_win_eventdata_utcTime: "2023-11-05 12:57:26.937", |
| 1732 | streams: ["650d3da25e9a2d550c6d6491"], |
| 1733 | rule_mitre_id: "T1055", |
| 1734 | gl2_message_id: "01HEFRYM78C4GA33W2VN2H1WWS", |
| 1735 | data_win_system_computer: "web1", |
| 1736 | data_win_eventdata_ruleName: "technique_id=T1036,technique_name=Masquerading", |
| 1737 | agent_ip: "202.43.110.138", |
| 1738 | true: 1699189048.147682, |
| 1739 | rule_groups: "sysmon, sysmon_eid10_detections, windows", |
| 1740 | data_win_system_keywords: "0x8000000000000000", |
| 1741 | data_win_system_level: "4", |
| 1742 | data_win_eventdata_targetProcessGUID: "{d9ab9ebb-62bb-6547-601c-020000003000}", |
| 1743 | data_win_system_severityValue: AlertSourceDataWinSystemSeverityValue.Information, |
| 1744 | data_win_eventdata_targetUser: "WEB1\\\\Administrator", |
| 1745 | agent_ip_geolocation: "16.1667,107.8333", |
| 1746 | rule_mitre_technique: "Process Injection", |
| 1747 | rule_firedtimes: 87, |
| 1748 | data_win_system_systemTime: "2023-11-05T12:57:26.938692200Z", |
| 1749 | rule_mail: true, |
| 1750 | decoder_name: AlertSourceDecoderName.WindowsEventchannel, |
| 1751 | agent_ip_country_code: "VN", |
| 1752 | data_win_system_processID: "3468", |
| 1753 | data_win_system_channel: "Microsoft-Windows-Sysmon/Operational", |
| 1754 | syslog_level: AlertSourceSyslogLevel.Alert, |
| 1755 | data_win_system_providerName: "Microsoft-Windows-Sysmon", |
| 1756 | data_win_system_version: "3", |
| 1757 | data_win_system_providerGuid: "{5770385f-c22a-43e0-bf4c-06f5698ffbd9}", |
| 1758 | timestamp: "2023-11-05 12:57:31.624", |
| 1759 | data_win_eventdata_callTrace: |
| 1760 | "C:\\\\Windows\\\\SYSTEM32\\\\ntdll.dll+9ff24|C:\\\\Windows\\\\System32\\\\KERNELBASE.dll+1668e|C:\\\\Windows\\\\System32\\\\shcore.dll+cca8|C:\\\\Windows\\\\System32\\\\shcore.dll+ba77|C:\\\\Windows\\\\System32\\\\shcore.dll+b967|C:\\\\Windows\\\\System32\\\\shcore.dll+b8f1|C:\\\\Windows\\\\System32\\\\shcore.dll+b61a|C:\\\\Windows\\\\system32\\\\explorerframe.dll+12b9d0|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+157bd8c|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+18051ce|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2e1a17|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2dfdfe|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+130216a|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a566ec|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a5695f|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3e93b|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c40433|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb8e|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3d62541|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb68|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c942dd|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3db94|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a52491|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a3e4a9", |
| 1761 | data_win_system_opcode: "0", |
| 1762 | gl2_processing_error: |
| 1763 | 'Replaced invalid timestamp value in message <e1c97f73-7bda-11ee-93bc-86000046278a> with current time - Value <2023-11-05T12:57:27.886+0000> caused exception: Invalid format: "2023-11-05T12:57:27.886+0000" is malformed at "T12:57:27.886+0000".', |
| 1764 | data_win_eventdata_sourceProcessId: "1652", |
| 1765 | message: |
| 1766 | '{"true":1699189048.147682,"timestamp":"2023-11-05T12:57:27.886+0000","rule":{"level":12,"description":"Explorer process was accessed by C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe, possible process injection","id":"92910","mitre":{"id":["T1055"],"tactic":["Defense Evasion","Privilege Escalation"],"technique":["Process Injection"]},"firedtimes":87,"mail":true,"groups":["sysmon","sysmon_eid10_detections","windows"]},"agent":{"id":"070","name":"web1","ip":"202.43.110.138","labels":{"customer":"wso4vxhq"}},"manager":{"name":"ASHWZHMA"},"id":"1699189047.740509955","decoder":{"name":"windows_eventchannel"},"data":{"win":{"system":{"providerName":"Microsoft-Windows-Sysmon","providerGuid":"{5770385f-c22a-43e0-bf4c-06f5698ffbd9}","eventID":"10","version":"3","level":"4","task":"10","opcode":"0","keywords":"0x8000000000000000","systemTime":"2023-11-05T12:57:26.938692200Z","eventRecordID":"4882779","processID":"3468","threadID":"5576","channel":"Microsoft-Windows-Sysmon/Operational","computer":"web1","severityValue":"INFORMATION","message":"\\"Process accessed:\\r\\nRuleName: technique_id=T1036,technique_name=Masquerading\\r\\nUtcTime: 2023-11-05 12:57:26.937\\r\\nSourceProcessGUID: {d9ab9ebb-7e1a-6544-44e0-010000003000}\\r\\nSourceProcessId: 1652\\r\\nSourceThreadId: 1284\\r\\nSourceImage: C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe\\r\\nTargetProcessGUID: {d9ab9ebb-62bb-6547-601c-020000003000}\\r\\nTargetProcessId: 4384\\r\\nTargetImage: C:\\\\Windows\\\\explorer.exe\\r\\nGrantedAccess: 0x40\\r\\nCallTrace: C:\\\\Windows\\\\SYSTEM32\\\\ntdll.dll+9ff24|C:\\\\Windows\\\\System32\\\\KERNELBASE.dll+1668e|C:\\\\Windows\\\\System32\\\\shcore.dll+cca8|C:\\\\Windows\\\\System32\\\\shcore.dll+ba77|C:\\\\Windows\\\\System32\\\\shcore.dll+b967|C:\\\\Windows\\\\System32\\\\shcore.dll+b8f1|C:\\\\Windows\\\\System32\\\\shcore.dll+b61a|C:\\\\Windows\\\\system32\\\\explorerframe.dll+12b9d0|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+157bd8c|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+18051ce|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2e1a17|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2dfdfe|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+130216a|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a566ec|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a5695f|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3e93b|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c40433|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb8e|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3d62541|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb68|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c942dd|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3db94|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a52491|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a3e4a9\\r\\nSourceUser: WEB1\\\\Administrator\\r\\nTargetUser: WEB1\\\\Administrator\\""},"eventdata":{"ruleName":"technique_id=T1036,technique_name=Masquerading","utcTime":"2023-11-05 12:57:26.937","sourceProcessGUID":"{d9ab9ebb-7e1a-6544-44e0-010000003000}","sourceProcessId":"1652","sourceThreadId":"1284","sourceImage":"C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe","targetProcessGUID":"{d9ab9ebb-62bb-6547-601c-020000003000}","targetProcessId":"4384","targetImage":"C:\\\\\\\\Windows\\\\\\\\explorer.exe","grantedAccess":"0x40","callTrace":"C:\\\\\\\\Windows\\\\\\\\SYSTEM32\\\\\\\\ntdll.dll+9ff24|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\KERNELBASE.dll+1668e|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+cca8|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+ba77|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+b967|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+b8f1|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+b61a|C:\\\\\\\\Windows\\\\\\\\system32\\\\\\\\explorerframe.dll+12b9d0|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+157bd8c|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+18051ce|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+2e1a17|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+2dfdfe|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+130216a|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+a566ec|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+a5695f|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c3e93b|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c40433|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3fbdb8e|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3d62541|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3fbdb68|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c942dd|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c3db94|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+a52491|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+a3e4a9","sourceUser":"WEB1\\\\\\\\Administrator","targetUser":"WEB1\\\\\\\\Administrator"}}},"location":"EventChannel"}', |
| 1767 | rule_id: "92910", |
| 1768 | manager_name: "ASHWZHMA", |
| 1769 | location: "EventChannel", |
| 1770 | data_win_eventdata_targetProcessId: "4384", |
| 1771 | rule_group3: AlertSourceDataLogsourceProduct.Windows, |
| 1772 | data_win_system_message: |
| 1773 | '"Process accessed:\r\nRuleName: technique_id=T1036,technique_name=Masquerading\r\nUtcTime: 2023-11-05 12:57:26.937\r\nSourceProcessGUID: {d9ab9ebb-7e1a-6544-44e0-010000003000}\r\nSourceProcessId: 1652\r\nSourceThreadId: 1284\r\nSourceImage: C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe\r\nTargetProcessGUID: {d9ab9ebb-62bb-6547-601c-020000003000}\r\nTargetProcessId: 4384\r\nTargetImage: C:\\Windows\\explorer.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+9ff24|C:\\Windows\\System32\\KERNELBASE.dll+1668e|C:\\Windows\\System32\\shcore.dll+cca8|C:\\Windows\\System32\\shcore.dll+ba77|C:\\Windows\\System32\\shcore.dll+b967|C:\\Windows\\System32\\shcore.dll+b8f1|C:\\Windows\\System32\\shcore.dll+b61a|C:\\Windows\\system32\\explorerframe.dll+12b9d0|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+157bd8c|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+18051ce|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+2e1a17|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+2dfdfe|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+130216a|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+a566ec|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+a5695f|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c3e93b|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c40433|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3fbdb8e|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3d62541|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3fbdb68|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c942dd|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c3db94|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+a52491|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+a3e4a9\r\nSourceUser: WEB1\\Administrator\r\nTargetUser: WEB1\\Administrator"', |
| 1774 | data_win_eventdata_sourceThreadId: "1284", |
| 1775 | msg_timestamp: "2023-11-05T12:57:27.886Z", |
| 1776 | rule_group2: "sysmon_eid10_detections", |
| 1777 | rule_group1: "sysmon" |
| 1778 | }, |
| 1779 | sort: [1699189046938] |
| 1780 | }, |
| 1781 | { |
| 1782 | _index: "wazuh-wso4vxhq_8", |
| 1783 | _id: "e1c93160-7bda-11ee-93bc-86000046278a", |
| 1784 | _score: null, |
| 1785 | _source: { |
| 1786 | source_reserved_ip: true, |
| 1787 | data_win_system_eventRecordID: "4882777", |
| 1788 | agent_id: "070", |
| 1789 | agent_name: "web1", |
| 1790 | data_win_eventdata_sourceProcessGUID: "{d9ab9ebb-7e1a-6544-44e0-010000003000}", |
| 1791 | gl2_remote_ip: "10.255.255.13", |
| 1792 | data_win_system_eventID: "10", |
| 1793 | gl2_remote_port: 57078, |
| 1794 | agent_labels_customer: "wso4vxhq", |
| 1795 | agent_ip_city_name: "N/A", |
| 1796 | source: "10.255.255.13", |
| 1797 | data_win_eventdata_targetImage: "C:\\\\Windows\\\\explorer.exe", |
| 1798 | gl2_source_input: "6459151dea00fd5d3da2df91", |
| 1799 | rule_level: 12, |
| 1800 | data_win_eventdata_sourceUser: "WEB1\\\\Administrator", |
| 1801 | data_win_system_task: "10", |
| 1802 | timestamp_utc: "2023-11-05T12:57:26.937Z", |
| 1803 | syslog_type: AlertSourceSyslogType.Wazuh, |
| 1804 | data_win_system_threadID: "5576", |
| 1805 | rule_description: |
| 1806 | "Explorer process was accessed by C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe, possible process injection", |
| 1807 | gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38", |
| 1808 | id: "1699189047.740498545", |
| 1809 | data_win_eventdata_grantedAccess: "0x40", |
| 1810 | data_win_eventdata_sourceImage: |
| 1811 | "C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe", |
| 1812 | rule_mitre_tactic: "Defense Evasion, Privilege Escalation", |
| 1813 | gl2_accounted_message_size: 11630, |
| 1814 | data_win_eventdata_utcTime: "2023-11-05 12:57:26.937", |
| 1815 | streams: ["650d3da25e9a2d550c6d6491"], |
| 1816 | rule_mitre_id: "T1055", |
| 1817 | gl2_message_id: "01HEFRYM7700MP8Y22100S2SEW", |
| 1818 | data_win_system_computer: "web1", |
| 1819 | data_win_eventdata_ruleName: "technique_id=T1036,technique_name=Masquerading", |
| 1820 | agent_ip: "202.43.110.138", |
| 1821 | true: 1699189047.610539, |
| 1822 | rule_groups: "sysmon, sysmon_eid10_detections, windows", |
| 1823 | data_win_system_keywords: "0x8000000000000000", |
| 1824 | data_win_system_level: "4", |
| 1825 | data_win_eventdata_targetProcessGUID: "{d9ab9ebb-62bb-6547-601c-020000003000}", |
| 1826 | data_win_system_severityValue: AlertSourceDataWinSystemSeverityValue.Information, |
| 1827 | data_win_eventdata_targetUser: "WEB1\\\\Administrator", |
| 1828 | agent_ip_geolocation: "16.1667,107.8333", |
| 1829 | rule_mitre_technique: "Process Injection", |
| 1830 | rule_firedtimes: 85, |
| 1831 | data_win_system_systemTime: "2023-11-05T12:57:26.937850100Z", |
| 1832 | rule_mail: true, |
| 1833 | decoder_name: AlertSourceDecoderName.WindowsEventchannel, |
| 1834 | agent_ip_country_code: "VN", |
| 1835 | data_win_system_processID: "3468", |
| 1836 | data_win_system_channel: "Microsoft-Windows-Sysmon/Operational", |
| 1837 | syslog_level: AlertSourceSyslogLevel.Alert, |
| 1838 | data_win_system_providerName: "Microsoft-Windows-Sysmon", |
| 1839 | data_win_system_version: "3", |
| 1840 | data_win_system_providerGuid: "{5770385f-c22a-43e0-bf4c-06f5698ffbd9}", |
| 1841 | timestamp: "2023-11-05 12:57:31.623", |
| 1842 | data_win_eventdata_callTrace: |
| 1843 | "C:\\\\Windows\\\\SYSTEM32\\\\ntdll.dll+9ff24|C:\\\\Windows\\\\System32\\\\KERNELBASE.dll+1668e|C:\\\\Windows\\\\System32\\\\shcore.dll+cca8|C:\\\\Windows\\\\System32\\\\shcore.dll+b55c|C:\\\\Windows\\\\System32\\\\shcore.dll+b275|C:\\\\Windows\\\\System32\\\\shcore.dll+b209|C:\\\\Windows\\\\System32\\\\shcore.dll+b104|C:\\\\Windows\\\\system32\\\\explorerframe.dll+12b986|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+157bd8c|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+18051ce|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2e1a17|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2dfdfe|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+130216a|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a566ec|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a5695f|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3e93b|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c40433|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb8e|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3d62541|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb68|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c942dd|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3db94|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a52491|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a3e4a9", |
| 1844 | data_win_system_opcode: "0", |
| 1845 | gl2_processing_error: |
| 1846 | 'Replaced invalid timestamp value in message <e1c93160-7bda-11ee-93bc-86000046278a> with current time - Value <2023-11-05T12:57:27.609+0000> caused exception: Invalid format: "2023-11-05T12:57:27.609+0000" is malformed at "T12:57:27.609+0000".', |
| 1847 | data_win_eventdata_sourceProcessId: "1652", |
| 1848 | message: |
| 1849 | '{"true":1699189047.610539,"timestamp":"2023-11-05T12:57:27.609+0000","rule":{"level":12,"description":"Explorer process was accessed by C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe, possible process injection","id":"92910","mitre":{"id":["T1055"],"tactic":["Defense Evasion","Privilege Escalation"],"technique":["Process Injection"]},"firedtimes":85,"mail":true,"groups":["sysmon","sysmon_eid10_detections","windows"]},"agent":{"id":"070","name":"web1","ip":"202.43.110.138","labels":{"customer":"wso4vxhq"}},"manager":{"name":"ASHWZHMA"},"id":"1699189047.740498545","decoder":{"name":"windows_eventchannel"},"data":{"win":{"system":{"providerName":"Microsoft-Windows-Sysmon","providerGuid":"{5770385f-c22a-43e0-bf4c-06f5698ffbd9}","eventID":"10","version":"3","level":"4","task":"10","opcode":"0","keywords":"0x8000000000000000","systemTime":"2023-11-05T12:57:26.937850100Z","eventRecordID":"4882777","processID":"3468","threadID":"5576","channel":"Microsoft-Windows-Sysmon/Operational","computer":"web1","severityValue":"INFORMATION","message":"\\"Process accessed:\\r\\nRuleName: technique_id=T1036,technique_name=Masquerading\\r\\nUtcTime: 2023-11-05 12:57:26.937\\r\\nSourceProcessGUID: {d9ab9ebb-7e1a-6544-44e0-010000003000}\\r\\nSourceProcessId: 1652\\r\\nSourceThreadId: 1284\\r\\nSourceImage: C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe\\r\\nTargetProcessGUID: {d9ab9ebb-62bb-6547-601c-020000003000}\\r\\nTargetProcessId: 4384\\r\\nTargetImage: C:\\\\Windows\\\\explorer.exe\\r\\nGrantedAccess: 0x40\\r\\nCallTrace: C:\\\\Windows\\\\SYSTEM32\\\\ntdll.dll+9ff24|C:\\\\Windows\\\\System32\\\\KERNELBASE.dll+1668e|C:\\\\Windows\\\\System32\\\\shcore.dll+cca8|C:\\\\Windows\\\\System32\\\\shcore.dll+b55c|C:\\\\Windows\\\\System32\\\\shcore.dll+b275|C:\\\\Windows\\\\System32\\\\shcore.dll+b209|C:\\\\Windows\\\\System32\\\\shcore.dll+b104|C:\\\\Windows\\\\system32\\\\explorerframe.dll+12b986|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+157bd8c|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+18051ce|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2e1a17|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2dfdfe|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+130216a|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a566ec|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a5695f|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3e93b|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c40433|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb8e|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3d62541|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb68|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c942dd|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3db94|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a52491|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a3e4a9\\r\\nSourceUser: WEB1\\\\Administrator\\r\\nTargetUser: WEB1\\\\Administrator\\""},"eventdata":{"ruleName":"technique_id=T1036,technique_name=Masquerading","utcTime":"2023-11-05 12:57:26.937","sourceProcessGUID":"{d9ab9ebb-7e1a-6544-44e0-010000003000}","sourceProcessId":"1652","sourceThreadId":"1284","sourceImage":"C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe","targetProcessGUID":"{d9ab9ebb-62bb-6547-601c-020000003000}","targetProcessId":"4384","targetImage":"C:\\\\\\\\Windows\\\\\\\\explorer.exe","grantedAccess":"0x40","callTrace":"C:\\\\\\\\Windows\\\\\\\\SYSTEM32\\\\\\\\ntdll.dll+9ff24|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\KERNELBASE.dll+1668e|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+cca8|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+b55c|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+b275|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+b209|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+b104|C:\\\\\\\\Windows\\\\\\\\system32\\\\\\\\explorerframe.dll+12b986|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+157bd8c|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+18051ce|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+2e1a17|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+2dfdfe|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+130216a|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+a566ec|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+a5695f|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c3e93b|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c40433|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3fbdb8e|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3d62541|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3fbdb68|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c942dd|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c3db94|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+a52491|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+a3e4a9","sourceUser":"WEB1\\\\\\\\Administrator","targetUser":"WEB1\\\\\\\\Administrator"}}},"location":"EventChannel"}', |
| 1850 | rule_id: "92910", |
| 1851 | manager_name: "ASHWZHMA", |
| 1852 | location: "EventChannel", |
| 1853 | data_win_eventdata_targetProcessId: "4384", |
| 1854 | rule_group3: AlertSourceDataLogsourceProduct.Windows, |
| 1855 | data_win_system_message: |
| 1856 | '"Process accessed:\r\nRuleName: technique_id=T1036,technique_name=Masquerading\r\nUtcTime: 2023-11-05 12:57:26.937\r\nSourceProcessGUID: {d9ab9ebb-7e1a-6544-44e0-010000003000}\r\nSourceProcessId: 1652\r\nSourceThreadId: 1284\r\nSourceImage: C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe\r\nTargetProcessGUID: {d9ab9ebb-62bb-6547-601c-020000003000}\r\nTargetProcessId: 4384\r\nTargetImage: C:\\Windows\\explorer.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+9ff24|C:\\Windows\\System32\\KERNELBASE.dll+1668e|C:\\Windows\\System32\\shcore.dll+cca8|C:\\Windows\\System32\\shcore.dll+b55c|C:\\Windows\\System32\\shcore.dll+b275|C:\\Windows\\System32\\shcore.dll+b209|C:\\Windows\\System32\\shcore.dll+b104|C:\\Windows\\system32\\explorerframe.dll+12b986|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+157bd8c|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+18051ce|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+2e1a17|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+2dfdfe|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+130216a|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+a566ec|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+a5695f|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c3e93b|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c40433|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3fbdb8e|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3d62541|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3fbdb68|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c942dd|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c3db94|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+a52491|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+a3e4a9\r\nSourceUser: WEB1\\Administrator\r\nTargetUser: WEB1\\Administrator"', |
| 1857 | data_win_eventdata_sourceThreadId: "1284", |
| 1858 | msg_timestamp: "2023-11-05T12:57:27.609Z", |
| 1859 | rule_group2: "sysmon_eid10_detections", |
| 1860 | rule_group1: "sysmon" |
| 1861 | }, |
| 1862 | sort: [1699189046937] |
| 1863 | }, |
| 1864 | { |
| 1865 | _index: "wazuh-wso4vxhq_8", |
| 1866 | _id: "85668701-7bda-11ee-93bc-86000046278a", |
| 1867 | _score: null, |
| 1868 | _source: { |
| 1869 | data_win_eventdata_newThreadId: "10040", |
| 1870 | source_reserved_ip: true, |
| 1871 | data_win_system_eventRecordID: "4882503", |
| 1872 | agent_id: "070", |
| 1873 | agent_name: "web1", |
| 1874 | gl2_remote_ip: "10.255.255.13", |
| 1875 | data_win_system_eventID: "8", |
| 1876 | gl2_remote_port: 48272, |
| 1877 | agent_labels_customer: "wso4vxhq", |
| 1878 | agent_ip_city_name: "N/A", |
| 1879 | source: "10.255.255.13", |
| 1880 | data_win_eventdata_targetImage: "C:\\\\Windows\\\\explorer.exe", |
| 1881 | gl2_source_input: "6459151dea00fd5d3da2df91", |
| 1882 | rule_level: 12, |
| 1883 | data_win_eventdata_sourceUser: "NT AUTHORITY\\\\SYSTEM", |
| 1884 | data_win_system_task: "8", |
| 1885 | timestamp_utc: "2023-11-05T12:54:51.363Z", |
| 1886 | syslog_type: AlertSourceSyslogType.Wazuh, |
| 1887 | data_win_system_threadID: "5576", |
| 1888 | rule_description: |
| 1889 | "Possible code injection on explorer.exe by C:\\\\Program Files\\\\VMware\\\\VMware Tools\\\\vmtoolsd.exe", |
| 1890 | gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38", |
| 1891 | id: "1699188892.737055402", |
| 1892 | data_win_eventdata_sourceImage: "C:\\\\Program Files\\\\VMware\\\\VMware Tools\\\\vmtoolsd.exe", |
| 1893 | rule_mitre_tactic: "Defense Evasion, Privilege Escalation", |
| 1894 | data_win_eventdata_targetProcessGuid: "{d9ab9ebb-62bb-6547-601c-020000003000}", |
| 1895 | gl2_accounted_message_size: 5134, |
| 1896 | data_win_eventdata_utcTime: "2023-11-05 12:54:51.363", |
| 1897 | streams: ["650d3da25e9a2d550c6d6491"], |
| 1898 | rule_mitre_id: "T1055", |
| 1899 | gl2_message_id: "01HEFRSWVHDK18DFBYAWFFH0Q5", |
| 1900 | data_win_system_computer: "web1", |
| 1901 | data_win_eventdata_ruleName: "technique_id=T1055,technique_name=Process Injection", |
| 1902 | agent_ip: "202.43.110.138", |
| 1903 | data_win_eventdata_startAddress: "0x00007FFDE5CCE720", |
| 1904 | true: 1699188892.065792, |
| 1905 | rule_groups: "sysmon, sysmon_eid8_detections, windows", |
| 1906 | data_win_system_keywords: "0x8000000000000000", |
| 1907 | data_win_system_level: "4", |
| 1908 | data_win_system_severityValue: AlertSourceDataWinSystemSeverityValue.Information, |
| 1909 | data_win_eventdata_targetUser: "WEB1\\\\Administrator", |
| 1910 | agent_ip_geolocation: "16.1667,107.8333", |
| 1911 | rule_mitre_technique: "Process Injection", |
| 1912 | rule_firedtimes: 2, |
| 1913 | data_win_system_systemTime: "2023-11-05T12:54:51.363981300Z", |
| 1914 | rule_mail: true, |
| 1915 | decoder_name: AlertSourceDecoderName.WindowsEventchannel, |
| 1916 | agent_ip_country_code: "VN", |
| 1917 | data_win_system_processID: "3468", |
| 1918 | data_win_system_channel: "Microsoft-Windows-Sysmon/Operational", |
| 1919 | syslog_level: AlertSourceSyslogLevel.Alert, |
| 1920 | data_win_system_providerName: "Microsoft-Windows-Sysmon", |
| 1921 | data_win_system_version: "2", |
| 1922 | data_win_system_providerGuid: "{5770385f-c22a-43e0-bf4c-06f5698ffbd9}", |
| 1923 | timestamp: "2023-11-05 12:54:56.625", |
| 1924 | data_win_system_opcode: "0", |
| 1925 | gl2_processing_error: |
| 1926 | 'Replaced invalid timestamp value in message <85668701-7bda-11ee-93bc-86000046278a> with current time - Value <2023-11-05T12:54:52.014+0000> caused exception: Invalid format: "2023-11-05T12:54:52.014+0000" is malformed at "T12:54:52.014+0000".', |
| 1927 | data_win_eventdata_sourceProcessId: "3368", |
| 1928 | data_win_eventdata_startModule: "C:\\\\Windows\\\\System32\\\\KERNEL32.DLL", |
| 1929 | message: |
| 1930 | '{"true":1699188892.065792,"timestamp":"2023-11-05T12:54:52.014+0000","rule":{"level":12,"description":"Possible code injection on explorer.exe by C:\\\\\\\\Program Files\\\\\\\\VMware\\\\\\\\VMware Tools\\\\\\\\vmtoolsd.exe","id":"92400","mitre":{"id":["T1055"],"tactic":["Defense Evasion","Privilege Escalation"],"technique":["Process Injection"]},"firedtimes":2,"mail":true,"groups":["sysmon","sysmon_eid8_detections","windows"]},"agent":{"id":"070","name":"web1","ip":"202.43.110.138","labels":{"customer":"wso4vxhq"}},"manager":{"name":"ASHWZHMA"},"id":"1699188892.737055402","decoder":{"name":"windows_eventchannel"},"data":{"win":{"system":{"providerName":"Microsoft-Windows-Sysmon","providerGuid":"{5770385f-c22a-43e0-bf4c-06f5698ffbd9}","eventID":"8","version":"2","level":"4","task":"8","opcode":"0","keywords":"0x8000000000000000","systemTime":"2023-11-05T12:54:51.363981300Z","eventRecordID":"4882503","processID":"3468","threadID":"5576","channel":"Microsoft-Windows-Sysmon/Operational","computer":"web1","severityValue":"INFORMATION","message":"\\"CreateRemoteThread detected:\\r\\nRuleName: technique_id=T1055,technique_name=Process Injection\\r\\nUtcTime: 2023-11-05 12:54:51.363\\r\\nSourceProcessGuid: {d9ab9ebb-48da-652f-4900-000000003000}\\r\\nSourceProcessId: 3368\\r\\nSourceImage: C:\\\\Program Files\\\\VMware\\\\VMware Tools\\\\vmtoolsd.exe\\r\\nTargetProcessGuid: {d9ab9ebb-62bb-6547-601c-020000003000}\\r\\nTargetProcessId: 4384\\r\\nTargetImage: C:\\\\Windows\\\\explorer.exe\\r\\nNewThreadId: 10040\\r\\nStartAddress: 0x00007FFDE5CCE720\\r\\nStartModule: C:\\\\Windows\\\\System32\\\\KERNEL32.DLL\\r\\nStartFunction: GetCommandLineW\\r\\nSourceUser: NT AUTHORITY\\\\SYSTEM\\r\\nTargetUser: WEB1\\\\Administrator\\""},"eventdata":{"ruleName":"technique_id=T1055,technique_name=Process Injection","utcTime":"2023-11-05 12:54:51.363","sourceProcessGuid":"{d9ab9ebb-48da-652f-4900-000000003000}","sourceProcessId":"3368","sourceImage":"C:\\\\\\\\Program Files\\\\\\\\VMware\\\\\\\\VMware Tools\\\\\\\\vmtoolsd.exe","targetProcessGuid":"{d9ab9ebb-62bb-6547-601c-020000003000}","targetProcessId":"4384","targetImage":"C:\\\\\\\\Windows\\\\\\\\explorer.exe","newThreadId":"10040","startAddress":"0x00007FFDE5CCE720","startModule":"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\KERNEL32.DLL","startFunction":"GetCommandLineW","sourceUser":"NT AUTHORITY\\\\\\\\SYSTEM","targetUser":"WEB1\\\\\\\\Administrator"}}},"location":"EventChannel"}', |
| 1931 | rule_id: "92400", |
| 1932 | manager_name: "ASHWZHMA", |
| 1933 | data_win_eventdata_sourceProcessGuid: "{d9ab9ebb-48da-652f-4900-000000003000}", |
| 1934 | location: "EventChannel", |
| 1935 | data_win_eventdata_targetProcessId: "4384", |
| 1936 | data_win_eventdata_startFunction: "GetCommandLineW", |
| 1937 | rule_group3: AlertSourceDataLogsourceProduct.Windows, |
| 1938 | data_win_system_message: |
| 1939 | '"CreateRemoteThread detected:\r\nRuleName: technique_id=T1055,technique_name=Process Injection\r\nUtcTime: 2023-11-05 12:54:51.363\r\nSourceProcessGuid: {d9ab9ebb-48da-652f-4900-000000003000}\r\nSourceProcessId: 3368\r\nSourceImage: C:\\Program Files\\VMware\\VMware Tools\\vmtoolsd.exe\r\nTargetProcessGuid: {d9ab9ebb-62bb-6547-601c-020000003000}\r\nTargetProcessId: 4384\r\nTargetImage: C:\\Windows\\explorer.exe\r\nNewThreadId: 10040\r\nStartAddress: 0x00007FFDE5CCE720\r\nStartModule: C:\\Windows\\System32\\KERNEL32.DLL\r\nStartFunction: GetCommandLineW\r\nSourceUser: NT AUTHORITY\\SYSTEM\r\nTargetUser: WEB1\\Administrator"', |
| 1940 | msg_timestamp: "2023-11-05T12:54:52.014Z", |
| 1941 | rule_group2: "sysmon_eid8_detections", |
| 1942 | rule_group1: "sysmon" |
| 1943 | }, |
| 1944 | sort: [1699188891363] |
| 1945 | }, |
| 1946 | { |
| 1947 | _index: "wazuh-wso4vxhq_8", |
| 1948 | _id: "797bfd81-7bda-11ee-93bc-86000046278a", |
| 1949 | _score: null, |
| 1950 | _source: { |
| 1951 | data_win_eventdata_newThreadId: "13164", |
| 1952 | source_reserved_ip: true, |
| 1953 | data_win_system_eventRecordID: "4882339", |
| 1954 | agent_id: "070", |
| 1955 | agent_name: "web1", |
| 1956 | gl2_remote_ip: "10.255.255.13", |
| 1957 | data_win_system_eventID: "8", |
| 1958 | gl2_remote_port: 44978, |
| 1959 | agent_labels_customer: "wso4vxhq", |
| 1960 | agent_ip_city_name: "N/A", |
| 1961 | source: "10.255.255.13", |
| 1962 | data_win_eventdata_targetImage: "C:\\\\Windows\\\\System32\\\\lsass.exe", |
| 1963 | gl2_source_input: "6459151dea00fd5d3da2df91", |
| 1964 | rule_level: 12, |
| 1965 | data_win_eventdata_sourceUser: "NT AUTHORITY\\\\SYSTEM", |
| 1966 | data_win_system_task: "8", |
| 1967 | timestamp_utc: "2023-11-05T12:54:32.314Z", |
| 1968 | syslog_type: AlertSourceSyslogType.Wazuh, |
| 1969 | data_win_system_threadID: "5576", |
| 1970 | rule_description: |
| 1971 | "Local Security Authority Subsystem Service (LSASS) process was accessed by C:\\\\Program Files\\\\VMware\\\\VMware Tools\\\\vmtoolsd.exe, possible code injection for credential dumping", |
| 1972 | gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38", |
| 1973 | id: "1699188873.736407303", |
| 1974 | data_win_eventdata_sourceImage: "C:\\\\Program Files\\\\VMware\\\\VMware Tools\\\\vmtoolsd.exe", |
| 1975 | rule_mitre_tactic: "Defense Evasion, Privilege Escalation", |
| 1976 | data_win_eventdata_targetProcessGuid: "{d9ab9ebb-48d7-652f-0c00-000000003000}", |
| 1977 | gl2_accounted_message_size: 5323, |
| 1978 | data_win_eventdata_utcTime: "2023-11-05 12:54:32.313", |
| 1979 | streams: ["650d3da25e9a2d550c6d6491"], |
| 1980 | rule_mitre_id: "T1055", |
| 1981 | gl2_message_id: "01HEFRS9ASFK4K72X8JPRDYJS6", |
| 1982 | data_win_system_computer: "web1", |
| 1983 | data_win_eventdata_ruleName: "technique_id=T1055,technique_name=Process Injection", |
| 1984 | agent_ip: "202.43.110.138", |
| 1985 | data_win_eventdata_startAddress: "0x00007FFDE5CCE720", |
| 1986 | true: 1699188873.447718, |
| 1987 | rule_groups: "sysmon, sysmon_eid8_detections, windows", |
| 1988 | data_win_system_keywords: "0x8000000000000000", |
| 1989 | data_win_system_level: "4", |
| 1990 | data_win_system_severityValue: AlertSourceDataWinSystemSeverityValue.Information, |
| 1991 | data_win_eventdata_targetUser: "NT AUTHORITY\\\\SYSTEM", |
| 1992 | agent_ip_geolocation: "16.1667,107.8333", |
| 1993 | rule_mitre_technique: "Process Injection", |
| 1994 | rule_firedtimes: 2, |
| 1995 | data_win_system_systemTime: "2023-11-05T12:54:32.314179900Z", |
| 1996 | rule_mail: true, |
| 1997 | decoder_name: AlertSourceDecoderName.WindowsEventchannel, |
| 1998 | agent_ip_country_code: "VN", |
| 1999 | data_win_system_processID: "3468", |
| 2000 | data_win_system_channel: "Microsoft-Windows-Sysmon/Operational", |
| 2001 | syslog_level: AlertSourceSyslogLevel.Alert, |
| 2002 | data_win_system_providerName: "Microsoft-Windows-Sysmon", |
| 2003 | data_win_system_version: "2", |
| 2004 | data_win_system_providerGuid: "{5770385f-c22a-43e0-bf4c-06f5698ffbd9}", |
| 2005 | timestamp: "2023-11-05 12:54:36.633", |
| 2006 | data_win_system_opcode: "0", |
| 2007 | gl2_processing_error: |
| 2008 | 'Replaced invalid timestamp value in message <797bfd81-7bda-11ee-93bc-86000046278a> with current time - Value <2023-11-05T12:54:33.443+0000> caused exception: Invalid format: "2023-11-05T12:54:33.443+0000" is malformed at "T12:54:33.443+0000".', |
| 2009 | data_win_eventdata_sourceProcessId: "3368", |
| 2010 | data_win_eventdata_startModule: "C:\\\\Windows\\\\System32\\\\KERNEL32.DLL", |
| 2011 | message: |
| 2012 | '{"true":1699188873.447718,"timestamp":"2023-11-05T12:54:33.443+0000","rule":{"level":12,"description":"Local Security Authority Subsystem Service (LSASS) process was accessed by C:\\\\\\\\Program Files\\\\\\\\VMware\\\\\\\\VMware Tools\\\\\\\\vmtoolsd.exe, possible code injection for credential dumping","id":"92403","mitre":{"id":["T1055"],"tactic":["Defense Evasion","Privilege Escalation"],"technique":["Process Injection"]},"firedtimes":2,"mail":true,"groups":["sysmon","sysmon_eid8_detections","windows"]},"agent":{"id":"070","name":"web1","ip":"202.43.110.138","labels":{"customer":"wso4vxhq"}},"manager":{"name":"ASHWZHMA"},"id":"1699188873.736407303","decoder":{"name":"windows_eventchannel"},"data":{"win":{"system":{"providerName":"Microsoft-Windows-Sysmon","providerGuid":"{5770385f-c22a-43e0-bf4c-06f5698ffbd9}","eventID":"8","version":"2","level":"4","task":"8","opcode":"0","keywords":"0x8000000000000000","systemTime":"2023-11-05T12:54:32.314179900Z","eventRecordID":"4882339","processID":"3468","threadID":"5576","channel":"Microsoft-Windows-Sysmon/Operational","computer":"web1","severityValue":"INFORMATION","message":"\\"CreateRemoteThread detected:\\r\\nRuleName: technique_id=T1055,technique_name=Process Injection\\r\\nUtcTime: 2023-11-05 12:54:32.313\\r\\nSourceProcessGuid: {d9ab9ebb-48da-652f-4900-000000003000}\\r\\nSourceProcessId: 3368\\r\\nSourceImage: C:\\\\Program Files\\\\VMware\\\\VMware Tools\\\\vmtoolsd.exe\\r\\nTargetProcessGuid: {d9ab9ebb-48d7-652f-0c00-000000003000}\\r\\nTargetProcessId: 740\\r\\nTargetImage: C:\\\\Windows\\\\System32\\\\lsass.exe\\r\\nNewThreadId: 13164\\r\\nStartAddress: 0x00007FFDE5CCE720\\r\\nStartModule: C:\\\\Windows\\\\System32\\\\KERNEL32.DLL\\r\\nStartFunction: GetCommandLineW\\r\\nSourceUser: NT AUTHORITY\\\\SYSTEM\\r\\nTargetUser: NT AUTHORITY\\\\SYSTEM\\""},"eventdata":{"ruleName":"technique_id=T1055,technique_name=Process Injection","utcTime":"2023-11-05 12:54:32.313","sourceProcessGuid":"{d9ab9ebb-48da-652f-4900-000000003000}","sourceProcessId":"3368","sourceImage":"C:\\\\\\\\Program Files\\\\\\\\VMware\\\\\\\\VMware Tools\\\\\\\\vmtoolsd.exe","targetProcessGuid":"{d9ab9ebb-48d7-652f-0c00-000000003000}","targetProcessId":"740","targetImage":"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\lsass.exe","newThreadId":"13164","startAddress":"0x00007FFDE5CCE720","startModule":"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\KERNEL32.DLL","startFunction":"GetCommandLineW","sourceUser":"NT AUTHORITY\\\\\\\\SYSTEM","targetUser":"NT AUTHORITY\\\\\\\\SYSTEM"}}},"location":"EventChannel"}', |
| 2013 | rule_id: "92403", |
| 2014 | manager_name: "ASHWZHMA", |
| 2015 | data_win_eventdata_sourceProcessGuid: "{d9ab9ebb-48da-652f-4900-000000003000}", |
| 2016 | location: "EventChannel", |
| 2017 | data_win_eventdata_targetProcessId: "740", |
| 2018 | data_win_eventdata_startFunction: "GetCommandLineW", |
| 2019 | rule_group3: AlertSourceDataLogsourceProduct.Windows, |
| 2020 | data_win_system_message: |
| 2021 | '"CreateRemoteThread detected:\r\nRuleName: technique_id=T1055,technique_name=Process Injection\r\nUtcTime: 2023-11-05 12:54:32.313\r\nSourceProcessGuid: {d9ab9ebb-48da-652f-4900-000000003000}\r\nSourceProcessId: 3368\r\nSourceImage: C:\\Program Files\\VMware\\VMware Tools\\vmtoolsd.exe\r\nTargetProcessGuid: {d9ab9ebb-48d7-652f-0c00-000000003000}\r\nTargetProcessId: 740\r\nTargetImage: C:\\Windows\\System32\\lsass.exe\r\nNewThreadId: 13164\r\nStartAddress: 0x00007FFDE5CCE720\r\nStartModule: C:\\Windows\\System32\\KERNEL32.DLL\r\nStartFunction: GetCommandLineW\r\nSourceUser: NT AUTHORITY\\SYSTEM\r\nTargetUser: NT AUTHORITY\\SYSTEM"', |
| 2022 | msg_timestamp: "2023-11-05T12:54:33.443Z", |
| 2023 | rule_group2: "sysmon_eid8_detections", |
| 2024 | rule_group1: "sysmon" |
| 2025 | }, |
| 2026 | sort: [1699188872314] |
| 2027 | } |
| 2028 | ] |
| 2029 | } |
| 2030 | ] |
| 2031 | |
| 2032 | export const alerts_by_host = [ |
| 2033 | { |
| 2034 | agent_name: "ip-178-216-201-141", |
| 2035 | number_of_alerts: 4 |
| 2036 | }, |
| 2037 | { |
| 2038 | agent_name: "WinDev2308Eval", |
| 2039 | number_of_alerts: 10 |
| 2040 | }, |
| 2041 | { |
| 2042 | agent_name: "ANSYDWDC01", |
| 2043 | number_of_alerts: 20 |
| 2044 | }, |
| 2045 | { |
| 2046 | agent_name: "web1", |
| 2047 | number_of_alerts: 10 |
| 2048 | }, |
| 2049 | { |
| 2050 | agent_name: "ssdnodes-zabbix", |
| 2051 | number_of_alerts: 4 |
| 2052 | } |
| 2053 | ] |
| 2054 | |
| 2055 | export const alerts_by_rule = [ |
| 2056 | { |
| 2057 | rule: "Explorer process was accessed by C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe, possible process injection", |
| 2058 | number_of_alerts: 6 |
| 2059 | }, |
| 2060 | { |
| 2061 | rule: "Explorer process was accessed by C:\\\\Users\\\\Administrator\\\\AppData\\\\Local\\\\Programs\\\\Messenger\\\\Messenger.exe, possible process injection", |
| 2062 | number_of_alerts: 4 |
| 2063 | }, |
| 2064 | { |
| 2065 | rule: "Adversaries may use binary padding to add junk data and change the on-disk representation of malware. This rule detect using dd and truncate to add a junk data to file.", |
| 2066 | number_of_alerts: 1 |
| 2067 | }, |
| 2068 | { |
| 2069 | rule: "Detects file and folder permission changes.", |
| 2070 | number_of_alerts: 7 |
| 2071 | }, |
| 2072 | { |
| 2073 | rule: "Process Explorer Driver Creation By Non-Sysinternals Binary", |
| 2074 | number_of_alerts: 20 |
| 2075 | }, |
| 2076 | { |
| 2077 | rule: "Application Compatibility Database launched", |
| 2078 | number_of_alerts: 10 |
| 2079 | } |
| 2080 | ] |
| 2081 | |
| 2082 | export const alerts_by_rule_per_host = [ |
| 2083 | { |
| 2084 | agent_name: "ANSYDWDC01", |
| 2085 | number_of_alerts: 20, |
| 2086 | rule: "Process Explorer Driver Creation By Non-Sysinternals Binary" |
| 2087 | }, |
| 2088 | { |
| 2089 | agent_name: "WinDev2308Eval", |
| 2090 | number_of_alerts: 10, |
| 2091 | rule: "Application Compatibility Database launched" |
| 2092 | }, |
| 2093 | { |
| 2094 | agent_name: "ip-178-216-201-141", |
| 2095 | number_of_alerts: 4, |
| 2096 | rule: "Detects file and folder permission changes." |
| 2097 | }, |
| 2098 | { |
| 2099 | agent_name: "web1", |
| 2100 | number_of_alerts: 9, |
| 2101 | rule: "Explorer process was accessed by C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe, possible process injection" |
| 2102 | }, |
| 2103 | { |
| 2104 | agent_name: "web1", |
| 2105 | number_of_alerts: 1, |
| 2106 | rule: "Explorer process was accessed by C:\\\\Users\\\\Administrator\\\\AppData\\\\Local\\\\Programs\\\\Messenger\\\\Messenger.exe, possible process injection" |
| 2107 | }, |
| 2108 | { |
| 2109 | agent_name: "ssdnodes-zabbix", |
| 2110 | number_of_alerts: 1, |
| 2111 | rule: "Adversaries may use binary padding to add junk data and change the on-disk representation of malware. This rule detect using dd and truncate to add a junk data to file." |
| 2112 | }, |
| 2113 | { |
| 2114 | agent_name: "ssdnodes-zabbix", |
| 2115 | number_of_alerts: 3, |
| 2116 | rule: "Detects file and folder permission changes." |
| 2117 | } |
| 2118 | ] |