main
ts 2,118 lines 236 KB
Raw
1 import type { AlertsSummary } from "@/types/alerts.d"
2 import {
3 AlertSourceDataGroup,
4 AlertSourceDataKind,
5 AlertSourceDataLevelEnum,
6 AlertSourceDataLogsourceCategory,
7 AlertSourceDataLogsourceProduct,
8 AlertSourceDataStatus,
9 AlertSourceDataWinEventdataIntegrityLevel,
10 AlertSourceDataWinSystemSeverityValue,
11 AlertSourceDecoderName,
12 AlertSourceSyslogLevel,
13 AlertSourceSyslogType
14 } from "@/types/alerts.d"
15
16 export const alerts_summary: AlertsSummary[] = [
17 {
18 index_name: "wazuh-wso4vxhq_7",
19 total_alerts: 5,
20 alerts: [
21 {
22 _index: "wazuh-wso4vxhq_7",
23 _id: "54842c0a-7bd6-11ee-93bc-86000046278a",
24 _score: null,
25 _source: {
26 rule_level: 12,
27 rule_description:
28 "Possible code injection on explorer.exe by C:\\\\Program Files\\\\VMware\\\\VMware Tools\\\\vmtoolsd.exe",
29 rule_groups: "sysmon, sysmon_eid8_detections, windows",
30 rule_firedtimes: 1,
31 rule_id: "92400",
32 rule_mail: true,
33
34 syslog_type: AlertSourceSyslogType.Wazuh,
35 syslog_level: AlertSourceSyslogLevel.Alert,
36
37 agent_id: "070",
38 agent_ip: "202.43.110.138",
39 agent_name: "web1",
40 agent_labels_customer: "wso4vxhq",
41
42 alert_url:
43 "https://ashirs01.socfortress.local/alerts?cid=1&page=1&per_page=10&sort=desc&alert_ids=2751",
44
45 source: "10.255.255.13",
46 streams: ["650d3da25e9a2d550c6d6491"],
47 decoder_name: AlertSourceDecoderName.WindowsEventchannel,
48 manager_name: "ASHWZHMA",
49 location: "EventChannel",
50
51 data_win_eventdata_newThreadId: "16400",
52 source_reserved_ip: true,
53 data_win_system_eventRecordID: "4879057",
54 gl2_remote_ip: "10.255.255.13",
55 data_win_system_eventID: "8",
56 gl2_remote_port: 50576,
57 agent_ip_city_name: "N/A",
58 data_win_eventdata_targetImage: "C:\\\\Windows\\\\explorer.exe",
59 gl2_source_input: "6459151dea00fd5d3da2df91",
60 data_win_eventdata_sourceUser: "NT AUTHORITY\\\\SYSTEM",
61 data_win_system_task: "8",
62 timestamp_utc: "2023-11-05T12:24:50.567Z",
63 data_win_system_threadID: "5576",
64 gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38",
65 id: "1699187091.698192264",
66 data_win_eventdata_sourceImage: "C:\\\\Program Files\\\\VMware\\\\VMware Tools\\\\vmtoolsd.exe",
67 rule_mitre_tactic: "Defense Evasion, Privilege Escalation",
68 data_win_eventdata_targetProcessGuid: "{d9ab9ebb-62bb-6547-601c-020000003000}",
69 gl2_accounted_message_size: 5134,
70 data_win_eventdata_utcTime: "2023-11-05 12:24:50.567",
71 rule_mitre_id: "T1055",
72 gl2_message_id: "01HEFQ2Z1GF61945NDN156XZRD",
73 data_win_system_computer: "web1",
74 data_win_eventdata_ruleName: "technique_id=T1055,technique_name=Process Injection",
75 data_win_eventdata_startAddress: "0x00007FFDE5CCE720",
76 true: 1699187091.846419,
77 data_win_system_keywords: "0x8000000000000000",
78 data_win_system_level: "4",
79 data_win_system_severityValue: AlertSourceDataWinSystemSeverityValue.Information,
80 data_win_eventdata_targetUser: "WEB1\\\\Administrator",
81 agent_ip_geolocation: "16.1667,107.8333",
82 rule_mitre_technique: "Process Injection",
83 data_win_system_systemTime: "2023-11-05T12:24:50.567370300Z",
84 agent_ip_country_code: "VN",
85 data_win_system_processID: "3468",
86 data_win_system_channel: "Microsoft-Windows-Sysmon/Operational",
87 data_win_system_providerName: "Microsoft-Windows-Sysmon",
88 data_win_system_version: "2",
89 data_win_system_providerGuid: "{5770385f-c22a-43e0-bf4c-06f5698ffbd9}",
90 timestamp: "2023-11-05 12:24:56.624",
91 data_win_system_opcode: "0",
92 gl2_processing_error:
93 'Replaced invalid timestamp value in message <54842c0a-7bd6-11ee-93bc-86000046278a> with current time - Value <2023-11-05T12:24:51.691+0000> caused exception: Invalid format: "2023-11-05T12:24:51.691+0000" is malformed at "T12:24:51.691+0000".',
94 data_win_eventdata_sourceProcessId: "3368",
95 data_win_eventdata_startModule: "C:\\\\Windows\\\\System32\\\\KERNEL32.DLL",
96 message:
97 '{"true":1699187091.846419,"timestamp":"2023-11-05T12:24:51.691+0000","rule":{"level":12,"description":"Possible code injection on explorer.exe by C:\\\\\\\\Program Files\\\\\\\\VMware\\\\\\\\VMware Tools\\\\\\\\vmtoolsd.exe","id":"92400","mitre":{"id":["T1055"],"tactic":["Defense Evasion","Privilege Escalation"],"technique":["Process Injection"]},"firedtimes":1,"mail":true,"groups":["sysmon","sysmon_eid8_detections","windows"]},"agent":{"id":"070","name":"web1","ip":"202.43.110.138","labels":{"customer":"wso4vxhq"}},"manager":{"name":"ASHWZHMA"},"id":"1699187091.698192264","decoder":{"name":"windows_eventchannel"},"data":{"win":{"system":{"providerName":"Microsoft-Windows-Sysmon","providerGuid":"{5770385f-c22a-43e0-bf4c-06f5698ffbd9}","eventID":"8","version":"2","level":"4","task":"8","opcode":"0","keywords":"0x8000000000000000","systemTime":"2023-11-05T12:24:50.567370300Z","eventRecordID":"4879057","processID":"3468","threadID":"5576","channel":"Microsoft-Windows-Sysmon/Operational","computer":"web1","severityValue":"INFORMATION","message":"\\"CreateRemoteThread detected:\\r\\nRuleName: technique_id=T1055,technique_name=Process Injection\\r\\nUtcTime: 2023-11-05 12:24:50.567\\r\\nSourceProcessGuid: {d9ab9ebb-48da-652f-4900-000000003000}\\r\\nSourceProcessId: 3368\\r\\nSourceImage: C:\\\\Program Files\\\\VMware\\\\VMware Tools\\\\vmtoolsd.exe\\r\\nTargetProcessGuid: {d9ab9ebb-62bb-6547-601c-020000003000}\\r\\nTargetProcessId: 4384\\r\\nTargetImage: C:\\\\Windows\\\\explorer.exe\\r\\nNewThreadId: 16400\\r\\nStartAddress: 0x00007FFDE5CCE720\\r\\nStartModule: C:\\\\Windows\\\\System32\\\\KERNEL32.DLL\\r\\nStartFunction: GetCommandLineW\\r\\nSourceUser: NT AUTHORITY\\\\SYSTEM\\r\\nTargetUser: WEB1\\\\Administrator\\""},"eventdata":{"ruleName":"technique_id=T1055,technique_name=Process Injection","utcTime":"2023-11-05 12:24:50.567","sourceProcessGuid":"{d9ab9ebb-48da-652f-4900-000000003000}","sourceProcessId":"3368","sourceImage":"C:\\\\\\\\Program Files\\\\\\\\VMware\\\\\\\\VMware Tools\\\\\\\\vmtoolsd.exe","targetProcessGuid":"{d9ab9ebb-62bb-6547-601c-020000003000}","targetProcessId":"4384","targetImage":"C:\\\\\\\\Windows\\\\\\\\explorer.exe","newThreadId":"16400","startAddress":"0x00007FFDE5CCE720","startModule":"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\KERNEL32.DLL","startFunction":"GetCommandLineW","sourceUser":"NT AUTHORITY\\\\\\\\SYSTEM","targetUser":"WEB1\\\\\\\\Administrator"}}},"location":"EventChannel"}',
98 data_win_eventdata_sourceProcessGuid: "{d9ab9ebb-48da-652f-4900-000000003000}",
99 data_win_eventdata_targetProcessId: "4384",
100 data_win_eventdata_startFunction: "GetCommandLineW",
101 rule_group3: AlertSourceDataLogsourceProduct.Windows,
102 data_win_system_message:
103 '"CreateRemoteThread detected:\r\nRuleName: technique_id=T1055,technique_name=Process Injection\r\nUtcTime: 2023-11-05 12:24:50.567\r\nSourceProcessGuid: {d9ab9ebb-48da-652f-4900-000000003000}\r\nSourceProcessId: 3368\r\nSourceImage: C:\\Program Files\\VMware\\VMware Tools\\vmtoolsd.exe\r\nTargetProcessGuid: {d9ab9ebb-62bb-6547-601c-020000003000}\r\nTargetProcessId: 4384\r\nTargetImage: C:\\Windows\\explorer.exe\r\nNewThreadId: 16400\r\nStartAddress: 0x00007FFDE5CCE720\r\nStartModule: C:\\Windows\\System32\\KERNEL32.DLL\r\nStartFunction: GetCommandLineW\r\nSourceUser: NT AUTHORITY\\SYSTEM\r\nTargetUser: WEB1\\Administrator"',
104 msg_timestamp: "2023-11-05T12:24:51.691Z",
105 rule_group2: "sysmon_eid8_detections",
106 rule_group1: "sysmon"
107 },
108 sort: [1699187090567]
109 },
110 {
111 _index: "wazuh-wso4vxhq_7",
112 _id: "48a2f142-7bd6-11ee-93bc-86000046278a",
113 _score: null,
114 _source: {
115 data_win_eventdata_newThreadId: "17292",
116 source_reserved_ip: true,
117 data_win_system_eventRecordID: "4878905",
118 agent_id: "070",
119 agent_name: "web1",
120 gl2_remote_ip: "10.255.255.13",
121 data_win_system_eventID: "8",
122 gl2_remote_port: 57222,
123 agent_labels_customer: "wso4vxhq",
124 agent_ip_city_name: "N/A",
125 source: "10.255.255.13",
126 data_win_eventdata_targetImage: "C:\\\\Windows\\\\System32\\\\lsass.exe",
127 gl2_source_input: "6459151dea00fd5d3da2df91",
128 rule_level: 12,
129 data_win_eventdata_sourceUser: "NT AUTHORITY\\\\SYSTEM",
130 data_win_system_task: "8",
131 timestamp_utc: "2023-11-05T12:24:32.015Z",
132 syslog_type: AlertSourceSyslogType.Wazuh,
133 data_win_system_threadID: "5576",
134 rule_description:
135 "Local Security Authority Subsystem Service (LSASS) process was accessed by C:\\\\Program Files\\\\VMware\\\\VMware Tools\\\\vmtoolsd.exe, possible code injection for credential dumping",
136 gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38",
137 id: "1699187072.697473214",
138 data_win_eventdata_sourceImage: "C:\\\\Program Files\\\\VMware\\\\VMware Tools\\\\vmtoolsd.exe",
139 rule_mitre_tactic: "Defense Evasion, Privilege Escalation",
140 data_win_eventdata_targetProcessGuid: "{d9ab9ebb-48d7-652f-0c00-000000003000}",
141 gl2_accounted_message_size: 5323,
142 data_win_eventdata_utcTime: "2023-11-05 12:24:32.013",
143 streams: ["650d3da25e9a2d550c6d6491"],
144 rule_mitre_id: "T1055",
145 gl2_message_id: "01HEFQ2BJMQ6D8ZQD9SW96GKRJ",
146 data_win_system_computer: "web1",
147 data_win_eventdata_ruleName: "technique_id=T1055,technique_name=Process Injection",
148 agent_ip: "202.43.110.138",
149 data_win_eventdata_startAddress: "0x00007FFDE5CCE720",
150 true: 1699187072.493505,
151 rule_groups: "sysmon, sysmon_eid8_detections, windows",
152 data_win_system_keywords: "0x8000000000000000",
153 data_win_system_level: "4",
154 data_win_system_severityValue: AlertSourceDataWinSystemSeverityValue.Information,
155 data_win_eventdata_targetUser: "NT AUTHORITY\\\\SYSTEM",
156 agent_ip_geolocation: "16.1667,107.8333",
157 rule_mitre_technique: "Process Injection",
158 rule_firedtimes: 1,
159 data_win_system_systemTime: "2023-11-05T12:24:32.015055900Z",
160 rule_mail: true,
161 decoder_name: AlertSourceDecoderName.WindowsEventchannel,
162 agent_ip_country_code: "VN",
163 data_win_system_processID: "3468",
164 data_win_system_channel: "Microsoft-Windows-Sysmon/Operational",
165 syslog_level: AlertSourceSyslogLevel.Alert,
166 data_win_system_providerName: "Microsoft-Windows-Sysmon",
167 data_win_system_version: "2",
168 data_win_system_providerGuid: "{5770385f-c22a-43e0-bf4c-06f5698ffbd9}",
169 timestamp: "2023-11-05 12:24:36.692",
170 data_win_system_opcode: "0",
171 gl2_processing_error:
172 'Replaced invalid timestamp value in message <48a2f142-7bd6-11ee-93bc-86000046278a> with current time - Value <2023-11-05T12:24:32.489+0000> caused exception: Invalid format: "2023-11-05T12:24:32.489+0000" is malformed at "T12:24:32.489+0000".',
173 data_win_eventdata_sourceProcessId: "3368",
174 data_win_eventdata_startModule: "C:\\\\Windows\\\\System32\\\\KERNEL32.DLL",
175 message:
176 '{"true":1699187072.493505,"timestamp":"2023-11-05T12:24:32.489+0000","rule":{"level":12,"description":"Local Security Authority Subsystem Service (LSASS) process was accessed by C:\\\\\\\\Program Files\\\\\\\\VMware\\\\\\\\VMware Tools\\\\\\\\vmtoolsd.exe, possible code injection for credential dumping","id":"92403","mitre":{"id":["T1055"],"tactic":["Defense Evasion","Privilege Escalation"],"technique":["Process Injection"]},"firedtimes":1,"mail":true,"groups":["sysmon","sysmon_eid8_detections","windows"]},"agent":{"id":"070","name":"web1","ip":"202.43.110.138","labels":{"customer":"wso4vxhq"}},"manager":{"name":"ASHWZHMA"},"id":"1699187072.697473214","decoder":{"name":"windows_eventchannel"},"data":{"win":{"system":{"providerName":"Microsoft-Windows-Sysmon","providerGuid":"{5770385f-c22a-43e0-bf4c-06f5698ffbd9}","eventID":"8","version":"2","level":"4","task":"8","opcode":"0","keywords":"0x8000000000000000","systemTime":"2023-11-05T12:24:32.015055900Z","eventRecordID":"4878905","processID":"3468","threadID":"5576","channel":"Microsoft-Windows-Sysmon/Operational","computer":"web1","severityValue":"INFORMATION","message":"\\"CreateRemoteThread detected:\\r\\nRuleName: technique_id=T1055,technique_name=Process Injection\\r\\nUtcTime: 2023-11-05 12:24:32.013\\r\\nSourceProcessGuid: {d9ab9ebb-48da-652f-4900-000000003000}\\r\\nSourceProcessId: 3368\\r\\nSourceImage: C:\\\\Program Files\\\\VMware\\\\VMware Tools\\\\vmtoolsd.exe\\r\\nTargetProcessGuid: {d9ab9ebb-48d7-652f-0c00-000000003000}\\r\\nTargetProcessId: 740\\r\\nTargetImage: C:\\\\Windows\\\\System32\\\\lsass.exe\\r\\nNewThreadId: 17292\\r\\nStartAddress: 0x00007FFDE5CCE720\\r\\nStartModule: C:\\\\Windows\\\\System32\\\\KERNEL32.DLL\\r\\nStartFunction: GetCommandLineW\\r\\nSourceUser: NT AUTHORITY\\\\SYSTEM\\r\\nTargetUser: NT AUTHORITY\\\\SYSTEM\\""},"eventdata":{"ruleName":"technique_id=T1055,technique_name=Process Injection","utcTime":"2023-11-05 12:24:32.013","sourceProcessGuid":"{d9ab9ebb-48da-652f-4900-000000003000}","sourceProcessId":"3368","sourceImage":"C:\\\\\\\\Program Files\\\\\\\\VMware\\\\\\\\VMware Tools\\\\\\\\vmtoolsd.exe","targetProcessGuid":"{d9ab9ebb-48d7-652f-0c00-000000003000}","targetProcessId":"740","targetImage":"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\lsass.exe","newThreadId":"17292","startAddress":"0x00007FFDE5CCE720","startModule":"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\KERNEL32.DLL","startFunction":"GetCommandLineW","sourceUser":"NT AUTHORITY\\\\\\\\SYSTEM","targetUser":"NT AUTHORITY\\\\\\\\SYSTEM"}}},"location":"EventChannel"}',
177 rule_id: "92403",
178 manager_name: "ASHWZHMA",
179 data_win_eventdata_sourceProcessGuid: "{d9ab9ebb-48da-652f-4900-000000003000}",
180 location: "EventChannel",
181 data_win_eventdata_targetProcessId: "740",
182 data_win_eventdata_startFunction: "GetCommandLineW",
183 rule_group3: AlertSourceDataLogsourceProduct.Windows,
184 data_win_system_message:
185 '"CreateRemoteThread detected:\r\nRuleName: technique_id=T1055,technique_name=Process Injection\r\nUtcTime: 2023-11-05 12:24:32.013\r\nSourceProcessGuid: {d9ab9ebb-48da-652f-4900-000000003000}\r\nSourceProcessId: 3368\r\nSourceImage: C:\\Program Files\\VMware\\VMware Tools\\vmtoolsd.exe\r\nTargetProcessGuid: {d9ab9ebb-48d7-652f-0c00-000000003000}\r\nTargetProcessId: 740\r\nTargetImage: C:\\Windows\\System32\\lsass.exe\r\nNewThreadId: 17292\r\nStartAddress: 0x00007FFDE5CCE720\r\nStartModule: C:\\Windows\\System32\\KERNEL32.DLL\r\nStartFunction: GetCommandLineW\r\nSourceUser: NT AUTHORITY\\SYSTEM\r\nTargetUser: NT AUTHORITY\\SYSTEM"',
186 msg_timestamp: "2023-11-05T12:24:32.489Z",
187 rule_group2: "sysmon_eid8_detections",
188 rule_group1: "sysmon"
189 },
190 sort: [1699187072015]
191 },
192 {
193 _index: "wazuh-wso4vxhq_7",
194 _id: "18e9b012-7bd6-11ee-93bc-86000046278a",
195 _score: null,
196 _source: {
197 source_reserved_ip: true,
198 data_win_system_eventRecordID: "4878784",
199 agent_id: "070",
200 agent_name: "web1",
201 data_win_eventdata_sourceProcessGUID: "{d9ab9ebb-7e1a-6544-44e0-010000003000}",
202 gl2_remote_ip: "10.255.255.13",
203 data_win_system_eventID: "10",
204 gl2_remote_port: 60342,
205 agent_labels_customer: "wso4vxhq",
206 agent_ip_city_name: "N/A",
207 source: "10.255.255.13",
208 data_win_eventdata_targetImage: "C:\\\\Windows\\\\explorer.exe",
209 gl2_source_input: "6459151dea00fd5d3da2df91",
210 rule_level: 12,
211 data_win_eventdata_sourceUser: "WEB1\\\\Administrator",
212 data_win_system_task: "10",
213 timestamp_utc: "2023-11-05T12:23:11.139Z",
214 syslog_type: AlertSourceSyslogType.Wazuh,
215 data_win_system_threadID: "5576",
216 rule_description:
217 "Explorer process was accessed by C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe, possible process injection",
218 gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38",
219 id: "1699186992.695685886",
220 data_win_eventdata_grantedAccess: "0x40",
221 data_win_eventdata_sourceImage:
222 "C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe",
223 rule_mitre_tactic: "Defense Evasion, Privilege Escalation",
224 gl2_accounted_message_size: 11630,
225 data_win_eventdata_utcTime: "2023-11-05 12:23:11.138",
226 streams: ["650d3da25e9a2d550c6d6491"],
227 rule_mitre_id: "T1055",
228 gl2_message_id: "01HEFPZXCJZA24HYV8G8E45ND1",
229 data_win_system_computer: "web1",
230 data_win_eventdata_ruleName: "technique_id=T1036,technique_name=Masquerading",
231 agent_ip: "202.43.110.138",
232 true: 1699186992.569563,
233 rule_groups: "sysmon, sysmon_eid10_detections, windows",
234 data_win_system_keywords: "0x8000000000000000",
235 data_win_system_level: "4",
236 data_win_eventdata_targetProcessGUID: "{d9ab9ebb-62bb-6547-601c-020000003000}",
237 data_win_system_severityValue: AlertSourceDataWinSystemSeverityValue.Information,
238 data_win_eventdata_targetUser: "WEB1\\\\Administrator",
239 agent_ip_geolocation: "16.1667,107.8333",
240 rule_mitre_technique: "Process Injection",
241 rule_firedtimes: 33,
242 data_win_system_systemTime: "2023-11-05T12:23:11.139487000Z",
243 rule_mail: true,
244 decoder_name: AlertSourceDecoderName.WindowsEventchannel,
245 agent_ip_country_code: "VN",
246 data_win_system_processID: "3468",
247 data_win_system_channel: "Microsoft-Windows-Sysmon/Operational",
248 syslog_level: AlertSourceSyslogLevel.Alert,
249 data_win_system_providerName: "Microsoft-Windows-Sysmon",
250 data_win_system_version: "3",
251 data_win_system_providerGuid: "{5770385f-c22a-43e0-bf4c-06f5698ffbd9}",
252 timestamp: "2023-11-05 12:23:16.626",
253 data_win_eventdata_callTrace:
254 "C:\\\\Windows\\\\SYSTEM32\\\\ntdll.dll+9ff24|C:\\\\Windows\\\\System32\\\\KERNELBASE.dll+1668e|C:\\\\Windows\\\\System32\\\\shcore.dll+cca8|C:\\\\Windows\\\\System32\\\\shcore.dll+ba77|C:\\\\Windows\\\\System32\\\\shcore.dll+b967|C:\\\\Windows\\\\System32\\\\shcore.dll+b8f1|C:\\\\Windows\\\\System32\\\\shcore.dll+b61a|C:\\\\Windows\\\\system32\\\\explorerframe.dll+12b9d0|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+157bd8c|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+18051ce|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2e1a17|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2dfdfe|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+130216a|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a566ec|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a5695f|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3e93b|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c40433|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb8e|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3d62541|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb68|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c942dd|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3db94|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a52491|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a3e4a9",
255 data_win_system_opcode: "0",
256 gl2_processing_error:
257 'Replaced invalid timestamp value in message <18e9b012-7bd6-11ee-93bc-86000046278a> with current time - Value <2023-11-05T12:23:12.276+0000> caused exception: Invalid format: "2023-11-05T12:23:12.276+0000" is malformed at "T12:23:12.276+0000".',
258 data_win_eventdata_sourceProcessId: "1652",
259 message:
260 '{"true":1699186992.569563,"timestamp":"2023-11-05T12:23:12.276+0000","rule":{"level":12,"description":"Explorer process was accessed by C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe, possible process injection","id":"92910","mitre":{"id":["T1055"],"tactic":["Defense Evasion","Privilege Escalation"],"technique":["Process Injection"]},"firedtimes":33,"mail":true,"groups":["sysmon","sysmon_eid10_detections","windows"]},"agent":{"id":"070","name":"web1","ip":"202.43.110.138","labels":{"customer":"wso4vxhq"}},"manager":{"name":"ASHWZHMA"},"id":"1699186992.695685886","decoder":{"name":"windows_eventchannel"},"data":{"win":{"system":{"providerName":"Microsoft-Windows-Sysmon","providerGuid":"{5770385f-c22a-43e0-bf4c-06f5698ffbd9}","eventID":"10","version":"3","level":"4","task":"10","opcode":"0","keywords":"0x8000000000000000","systemTime":"2023-11-05T12:23:11.139487000Z","eventRecordID":"4878784","processID":"3468","threadID":"5576","channel":"Microsoft-Windows-Sysmon/Operational","computer":"web1","severityValue":"INFORMATION","message":"\\"Process accessed:\\r\\nRuleName: technique_id=T1036,technique_name=Masquerading\\r\\nUtcTime: 2023-11-05 12:23:11.138\\r\\nSourceProcessGUID: {d9ab9ebb-7e1a-6544-44e0-010000003000}\\r\\nSourceProcessId: 1652\\r\\nSourceThreadId: 1284\\r\\nSourceImage: C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe\\r\\nTargetProcessGUID: {d9ab9ebb-62bb-6547-601c-020000003000}\\r\\nTargetProcessId: 4384\\r\\nTargetImage: C:\\\\Windows\\\\explorer.exe\\r\\nGrantedAccess: 0x40\\r\\nCallTrace: C:\\\\Windows\\\\SYSTEM32\\\\ntdll.dll+9ff24|C:\\\\Windows\\\\System32\\\\KERNELBASE.dll+1668e|C:\\\\Windows\\\\System32\\\\shcore.dll+cca8|C:\\\\Windows\\\\System32\\\\shcore.dll+ba77|C:\\\\Windows\\\\System32\\\\shcore.dll+b967|C:\\\\Windows\\\\System32\\\\shcore.dll+b8f1|C:\\\\Windows\\\\System32\\\\shcore.dll+b61a|C:\\\\Windows\\\\system32\\\\explorerframe.dll+12b9d0|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+157bd8c|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+18051ce|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2e1a17|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2dfdfe|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+130216a|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a566ec|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a5695f|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3e93b|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c40433|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb8e|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3d62541|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb68|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c942dd|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3db94|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a52491|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a3e4a9\\r\\nSourceUser: WEB1\\\\Administrator\\r\\nTargetUser: WEB1\\\\Administrator\\""},"eventdata":{"ruleName":"technique_id=T1036,technique_name=Masquerading","utcTime":"2023-11-05 12:23:11.138","sourceProcessGUID":"{d9ab9ebb-7e1a-6544-44e0-010000003000}","sourceProcessId":"1652","sourceThreadId":"1284","sourceImage":"C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe","targetProcessGUID":"{d9ab9ebb-62bb-6547-601c-020000003000}","targetProcessId":"4384","targetImage":"C:\\\\\\\\Windows\\\\\\\\explorer.exe","grantedAccess":"0x40","callTrace":"C:\\\\\\\\Windows\\\\\\\\SYSTEM32\\\\\\\\ntdll.dll+9ff24|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\KERNELBASE.dll+1668e|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+cca8|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+ba77|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+b967|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+b8f1|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+b61a|C:\\\\\\\\Windows\\\\\\\\system32\\\\\\\\explorerframe.dll+12b9d0|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+157bd8c|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+18051ce|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+2e1a17|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+2dfdfe|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+130216a|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+a566ec|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+a5695f|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c3e93b|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c40433|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3fbdb8e|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3d62541|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3fbdb68|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c942dd|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c3db94|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+a52491|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+a3e4a9","sourceUser":"WEB1\\\\\\\\Administrator","targetUser":"WEB1\\\\\\\\Administrator"}}},"location":"EventChannel"}',
261 rule_id: "92910",
262 manager_name: "ASHWZHMA",
263 location: "EventChannel",
264 data_win_eventdata_targetProcessId: "4384",
265 rule_group3: AlertSourceDataLogsourceProduct.Windows,
266 data_win_system_message:
267 '"Process accessed:\r\nRuleName: technique_id=T1036,technique_name=Masquerading\r\nUtcTime: 2023-11-05 12:23:11.138\r\nSourceProcessGUID: {d9ab9ebb-7e1a-6544-44e0-010000003000}\r\nSourceProcessId: 1652\r\nSourceThreadId: 1284\r\nSourceImage: C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe\r\nTargetProcessGUID: {d9ab9ebb-62bb-6547-601c-020000003000}\r\nTargetProcessId: 4384\r\nTargetImage: C:\\Windows\\explorer.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+9ff24|C:\\Windows\\System32\\KERNELBASE.dll+1668e|C:\\Windows\\System32\\shcore.dll+cca8|C:\\Windows\\System32\\shcore.dll+ba77|C:\\Windows\\System32\\shcore.dll+b967|C:\\Windows\\System32\\shcore.dll+b8f1|C:\\Windows\\System32\\shcore.dll+b61a|C:\\Windows\\system32\\explorerframe.dll+12b9d0|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+157bd8c|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+18051ce|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+2e1a17|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+2dfdfe|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+130216a|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+a566ec|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+a5695f|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c3e93b|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c40433|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3fbdb8e|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3d62541|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3fbdb68|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c942dd|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c3db94|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+a52491|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+a3e4a9\r\nSourceUser: WEB1\\Administrator\r\nTargetUser: WEB1\\Administrator"',
268 data_win_eventdata_sourceThreadId: "1284",
269 msg_timestamp: "2023-11-05T12:23:12.276Z",
270 rule_group2: "sysmon_eid10_detections",
271 rule_group1: "sysmon"
272 },
273 sort: [1699186991139]
274 },
275 {
276 _index: "wazuh-wso4vxhq_7",
277 _id: "18e9b010-7bd6-11ee-93bc-86000046278a",
278 _score: null,
279 _source: {
280 source_reserved_ip: true,
281 data_win_system_eventRecordID: "4878783",
282 agent_id: "070",
283 agent_name: "web1",
284 data_win_eventdata_sourceProcessGUID: "{d9ab9ebb-7e1a-6544-44e0-010000003000}",
285 gl2_remote_ip: "10.255.255.13",
286 data_win_system_eventID: "10",
287 gl2_remote_port: 60342,
288 agent_labels_customer: "wso4vxhq",
289 agent_ip_city_name: "N/A",
290 source: "10.255.255.13",
291 data_win_eventdata_targetImage: "C:\\\\Windows\\\\explorer.exe",
292 gl2_source_input: "6459151dea00fd5d3da2df91",
293 rule_level: 12,
294 data_win_eventdata_sourceUser: "WEB1\\\\Administrator",
295 data_win_system_task: "10",
296 timestamp_utc: "2023-11-05T12:23:11.139Z",
297 syslog_type: AlertSourceSyslogType.Wazuh,
298 data_win_system_threadID: "5576",
299 rule_description:
300 "Explorer process was accessed by C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe, possible process injection",
301 gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38",
302 id: "1699186992.695678238",
303 data_win_eventdata_grantedAccess: "0x40",
304 data_win_eventdata_sourceImage:
305 "C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe",
306 rule_mitre_tactic: "Defense Evasion, Privilege Escalation",
307 gl2_accounted_message_size: 11455,
308 data_win_eventdata_utcTime: "2023-11-05 12:23:11.137",
309 streams: ["650d3da25e9a2d550c6d6491"],
310 rule_mitre_id: "T1055",
311 gl2_message_id: "01HEFPZXCJWE7EJ5BK46QKR67G",
312 data_win_system_computer: "web1",
313 data_win_eventdata_ruleName: "technique_id=T1036,technique_name=Masquerading",
314 agent_ip: "202.43.110.138",
315 true: 1699186992.277071,
316 rule_groups: "sysmon, sysmon_eid10_detections, windows",
317 data_win_system_keywords: "0x8000000000000000",
318 data_win_system_level: "4",
319 data_win_eventdata_targetProcessGUID: "{d9ab9ebb-62bb-6547-601c-020000003000}",
320 data_win_system_severityValue: AlertSourceDataWinSystemSeverityValue.Information,
321 data_win_eventdata_targetUser: "WEB1\\\\Administrator",
322 agent_ip_geolocation: "16.1667,107.8333",
323 rule_mitre_technique: "Process Injection",
324 rule_firedtimes: 32,
325 data_win_system_systemTime: "2023-11-05T12:23:11.139039000Z",
326 rule_mail: true,
327 decoder_name: AlertSourceDecoderName.WindowsEventchannel,
328 agent_ip_country_code: "VN",
329 data_win_system_processID: "3468",
330 data_win_system_channel: "Microsoft-Windows-Sysmon/Operational",
331 syslog_level: AlertSourceSyslogLevel.Alert,
332 data_win_system_providerName: "Microsoft-Windows-Sysmon",
333 data_win_system_version: "3",
334 data_win_system_providerGuid: "{5770385f-c22a-43e0-bf4c-06f5698ffbd9}",
335 timestamp: "2023-11-05 12:23:16.626",
336 data_win_eventdata_callTrace:
337 "C:\\\\Windows\\\\SYSTEM32\\\\ntdll.dll+9ff24|C:\\\\Windows\\\\System32\\\\KERNELBASE.dll+1668e|C:\\\\Windows\\\\System32\\\\shcore.dll+cca8|C:\\\\Windows\\\\System32\\\\shcore.dll+ba62|C:\\\\Windows\\\\System32\\\\shcore.dll+b585|C:\\\\Windows\\\\System32\\\\shcore.dll+b275|C:\\\\Windows\\\\System32\\\\shcore.dll+b209|C:\\\\Windows\\\\System32\\\\shcore.dll+b104|C:\\\\Windows\\\\system32\\\\explorerframe.dll+12b986|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+157bd8c|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+18051ce|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2e1a17|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2dfdfe|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+130216a|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a566ec|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a5695f|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3e93b|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c40433|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb8e|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3d62541|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb68|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c942dd|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3db94|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a52491",
338 data_win_system_opcode: "0",
339 gl2_processing_error:
340 'Replaced invalid timestamp value in message <18e9b010-7bd6-11ee-93bc-86000046278a> with current time - Value <2023-11-05T12:23:12.272+0000> caused exception: Invalid format: "2023-11-05T12:23:12.272+0000" is malformed at "T12:23:12.272+0000".',
341 data_win_eventdata_sourceProcessId: "1652",
342 message:
343 '{"true":1699186992.277071,"timestamp":"2023-11-05T12:23:12.272+0000","rule":{"level":12,"description":"Explorer process was accessed by C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe, possible process injection","id":"92910","mitre":{"id":["T1055"],"tactic":["Defense Evasion","Privilege Escalation"],"technique":["Process Injection"]},"firedtimes":32,"mail":true,"groups":["sysmon","sysmon_eid10_detections","windows"]},"agent":{"id":"070","name":"web1","ip":"202.43.110.138","labels":{"customer":"wso4vxhq"}},"manager":{"name":"ASHWZHMA"},"id":"1699186992.695678238","decoder":{"name":"windows_eventchannel"},"data":{"win":{"system":{"providerName":"Microsoft-Windows-Sysmon","providerGuid":"{5770385f-c22a-43e0-bf4c-06f5698ffbd9}","eventID":"10","version":"3","level":"4","task":"10","opcode":"0","keywords":"0x8000000000000000","systemTime":"2023-11-05T12:23:11.139039000Z","eventRecordID":"4878783","processID":"3468","threadID":"5576","channel":"Microsoft-Windows-Sysmon/Operational","computer":"web1","severityValue":"INFORMATION","message":"\\"Process accessed:\\r\\nRuleName: technique_id=T1036,technique_name=Masquerading\\r\\nUtcTime: 2023-11-05 12:23:11.137\\r\\nSourceProcessGUID: {d9ab9ebb-7e1a-6544-44e0-010000003000}\\r\\nSourceProcessId: 1652\\r\\nSourceThreadId: 1284\\r\\nSourceImage: C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe\\r\\nTargetProcessGUID: {d9ab9ebb-62bb-6547-601c-020000003000}\\r\\nTargetProcessId: 4384\\r\\nTargetImage: C:\\\\Windows\\\\explorer.exe\\r\\nGrantedAccess: 0x40\\r\\nCallTrace: C:\\\\Windows\\\\SYSTEM32\\\\ntdll.dll+9ff24|C:\\\\Windows\\\\System32\\\\KERNELBASE.dll+1668e|C:\\\\Windows\\\\System32\\\\shcore.dll+cca8|C:\\\\Windows\\\\System32\\\\shcore.dll+ba62|C:\\\\Windows\\\\System32\\\\shcore.dll+b585|C:\\\\Windows\\\\System32\\\\shcore.dll+b275|C:\\\\Windows\\\\System32\\\\shcore.dll+b209|C:\\\\Windows\\\\System32\\\\shcore.dll+b104|C:\\\\Windows\\\\system32\\\\explorerframe.dll+12b986|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+157bd8c|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+18051ce|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2e1a17|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2dfdfe|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+130216a|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a566ec|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a5695f|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3e93b|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c40433|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb8e|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3d62541|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb68|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c942dd|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3db94|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a52491\\r\\nSourceUser: WEB1\\\\Administrator\\r\\nTargetUser: WEB1\\\\Administrator\\""},"eventdata":{"ruleName":"technique_id=T1036,technique_name=Masquerading","utcTime":"2023-11-05 12:23:11.137","sourceProcessGUID":"{d9ab9ebb-7e1a-6544-44e0-010000003000}","sourceProcessId":"1652","sourceThreadId":"1284","sourceImage":"C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe","targetProcessGUID":"{d9ab9ebb-62bb-6547-601c-020000003000}","targetProcessId":"4384","targetImage":"C:\\\\\\\\Windows\\\\\\\\explorer.exe","grantedAccess":"0x40","callTrace":"C:\\\\\\\\Windows\\\\\\\\SYSTEM32\\\\\\\\ntdll.dll+9ff24|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\KERNELBASE.dll+1668e|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+cca8|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+ba62|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+b585|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+b275|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+b209|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+b104|C:\\\\\\\\Windows\\\\\\\\system32\\\\\\\\explorerframe.dll+12b986|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+157bd8c|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+18051ce|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+2e1a17|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+2dfdfe|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+130216a|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+a566ec|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+a5695f|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c3e93b|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c40433|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3fbdb8e|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3d62541|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3fbdb68|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c942dd|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c3db94|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+a52491","sourceUser":"WEB1\\\\\\\\Administrator","targetUser":"WEB1\\\\\\\\Administrator"}}},"location":"EventChannel"}',
344 rule_id: "92910",
345 manager_name: "ASHWZHMA",
346 location: "EventChannel",
347 data_win_eventdata_targetProcessId: "4384",
348 rule_group3: AlertSourceDataLogsourceProduct.Windows,
349 data_win_system_message:
350 '"Process accessed:\r\nRuleName: technique_id=T1036,technique_name=Masquerading\r\nUtcTime: 2023-11-05 12:23:11.137\r\nSourceProcessGUID: {d9ab9ebb-7e1a-6544-44e0-010000003000}\r\nSourceProcessId: 1652\r\nSourceThreadId: 1284\r\nSourceImage: C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe\r\nTargetProcessGUID: {d9ab9ebb-62bb-6547-601c-020000003000}\r\nTargetProcessId: 4384\r\nTargetImage: C:\\Windows\\explorer.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+9ff24|C:\\Windows\\System32\\KERNELBASE.dll+1668e|C:\\Windows\\System32\\shcore.dll+cca8|C:\\Windows\\System32\\shcore.dll+ba62|C:\\Windows\\System32\\shcore.dll+b585|C:\\Windows\\System32\\shcore.dll+b275|C:\\Windows\\System32\\shcore.dll+b209|C:\\Windows\\System32\\shcore.dll+b104|C:\\Windows\\system32\\explorerframe.dll+12b986|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+157bd8c|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+18051ce|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+2e1a17|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+2dfdfe|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+130216a|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+a566ec|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+a5695f|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c3e93b|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c40433|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3fbdb8e|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3d62541|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3fbdb68|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c942dd|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c3db94|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+a52491\r\nSourceUser: WEB1\\Administrator\r\nTargetUser: WEB1\\Administrator"',
351 data_win_eventdata_sourceThreadId: "1284",
352 msg_timestamp: "2023-11-05T12:23:12.272Z",
353 rule_group2: "sysmon_eid10_detections",
354 rule_group1: "sysmon"
355 },
356 sort: [1699186991139]
357 },
358 {
359 _index: "wazuh-wso4vxhq_7",
360 _id: "18e98900-7bd6-11ee-93bc-86000046278a",
361 _score: null,
362 _source: {
363 source_reserved_ip: true,
364 data_win_system_eventRecordID: "4878782",
365 agent_id: "070",
366 agent_name: "web1",
367 data_win_eventdata_sourceProcessGUID: "{d9ab9ebb-7e1a-6544-44e0-010000003000}",
368 gl2_remote_ip: "10.255.255.13",
369 data_win_system_eventID: "10",
370 gl2_remote_port: 60342,
371 agent_labels_customer: "wso4vxhq",
372 agent_ip_city_name: "N/A",
373 source: "10.255.255.13",
374 data_win_eventdata_targetImage: "C:\\\\Windows\\\\explorer.exe",
375 gl2_source_input: "6459151dea00fd5d3da2df91",
376 rule_level: 12,
377 data_win_eventdata_sourceUser: "WEB1\\\\Administrator",
378 data_win_system_task: "10",
379 timestamp_utc: "2023-11-05T12:23:11.138Z",
380 syslog_type: AlertSourceSyslogType.Wazuh,
381 data_win_system_threadID: "5576",
382 rule_description:
383 "Explorer process was accessed by C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe, possible process injection",
384 gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38",
385 id: "1699186992.695672487",
386 data_win_eventdata_grantedAccess: "0x40",
387 data_win_eventdata_sourceImage:
388 "C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe",
389 rule_mitre_tactic: "Defense Evasion, Privilege Escalation",
390 gl2_accounted_message_size: 11630,
391 data_win_eventdata_utcTime: "2023-11-05 12:23:11.137",
392 streams: ["650d3da25e9a2d550c6d6491"],
393 rule_mitre_id: "T1055",
394 gl2_message_id: "01HEFPZXCH0JEEF6TT8BQK4XJR",
395 data_win_system_computer: "web1",
396 data_win_eventdata_ruleName: "technique_id=T1036,technique_name=Masquerading",
397 agent_ip: "202.43.110.138",
398 true: 1699186992.273304,
399 rule_groups: "sysmon, sysmon_eid10_detections, windows",
400 data_win_system_keywords: "0x8000000000000000",
401 data_win_system_level: "4",
402 data_win_eventdata_targetProcessGUID: "{d9ab9ebb-62bb-6547-601c-020000003000}",
403 data_win_system_severityValue: AlertSourceDataWinSystemSeverityValue.Information,
404 data_win_eventdata_targetUser: "WEB1\\\\Administrator",
405 agent_ip_geolocation: "16.1667,107.8333",
406 rule_mitre_technique: "Process Injection",
407 rule_firedtimes: 31,
408 data_win_system_systemTime: "2023-11-05T12:23:11.138753100Z",
409 rule_mail: true,
410 decoder_name: AlertSourceDecoderName.WindowsEventchannel,
411 agent_ip_country_code: "VN",
412 data_win_system_processID: "3468",
413 data_win_system_channel: "Microsoft-Windows-Sysmon/Operational",
414 syslog_level: AlertSourceSyslogLevel.Alert,
415 data_win_system_providerName: "Microsoft-Windows-Sysmon",
416 data_win_system_version: "3",
417 data_win_system_providerGuid: "{5770385f-c22a-43e0-bf4c-06f5698ffbd9}",
418 timestamp: "2023-11-05 12:23:16.625",
419 data_win_eventdata_callTrace:
420 "C:\\\\Windows\\\\SYSTEM32\\\\ntdll.dll+9ff24|C:\\\\Windows\\\\System32\\\\KERNELBASE.dll+1668e|C:\\\\Windows\\\\System32\\\\shcore.dll+cca8|C:\\\\Windows\\\\System32\\\\shcore.dll+b55c|C:\\\\Windows\\\\System32\\\\shcore.dll+b275|C:\\\\Windows\\\\System32\\\\shcore.dll+b209|C:\\\\Windows\\\\System32\\\\shcore.dll+b104|C:\\\\Windows\\\\system32\\\\explorerframe.dll+12b986|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+157bd8c|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+18051ce|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2e1a17|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2dfdfe|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+130216a|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a566ec|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a5695f|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3e93b|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c40433|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb8e|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3d62541|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb68|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c942dd|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3db94|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a52491|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a3e4a9",
421 data_win_system_opcode: "0",
422 gl2_processing_error:
423 'Replaced invalid timestamp value in message <18e98900-7bd6-11ee-93bc-86000046278a> with current time - Value <2023-11-05T12:23:12.272+0000> caused exception: Invalid format: "2023-11-05T12:23:12.272+0000" is malformed at "T12:23:12.272+0000".',
424 data_win_eventdata_sourceProcessId: "1652",
425 message:
426 '{"true":1699186992.273304,"timestamp":"2023-11-05T12:23:12.272+0000","rule":{"level":12,"description":"Explorer process was accessed by C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe, possible process injection","id":"92910","mitre":{"id":["T1055"],"tactic":["Defense Evasion","Privilege Escalation"],"technique":["Process Injection"]},"firedtimes":31,"mail":true,"groups":["sysmon","sysmon_eid10_detections","windows"]},"agent":{"id":"070","name":"web1","ip":"202.43.110.138","labels":{"customer":"wso4vxhq"}},"manager":{"name":"ASHWZHMA"},"id":"1699186992.695672487","decoder":{"name":"windows_eventchannel"},"data":{"win":{"system":{"providerName":"Microsoft-Windows-Sysmon","providerGuid":"{5770385f-c22a-43e0-bf4c-06f5698ffbd9}","eventID":"10","version":"3","level":"4","task":"10","opcode":"0","keywords":"0x8000000000000000","systemTime":"2023-11-05T12:23:11.138753100Z","eventRecordID":"4878782","processID":"3468","threadID":"5576","channel":"Microsoft-Windows-Sysmon/Operational","computer":"web1","severityValue":"INFORMATION","message":"\\"Process accessed:\\r\\nRuleName: technique_id=T1036,technique_name=Masquerading\\r\\nUtcTime: 2023-11-05 12:23:11.137\\r\\nSourceProcessGUID: {d9ab9ebb-7e1a-6544-44e0-010000003000}\\r\\nSourceProcessId: 1652\\r\\nSourceThreadId: 1284\\r\\nSourceImage: C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe\\r\\nTargetProcessGUID: {d9ab9ebb-62bb-6547-601c-020000003000}\\r\\nTargetProcessId: 4384\\r\\nTargetImage: C:\\\\Windows\\\\explorer.exe\\r\\nGrantedAccess: 0x40\\r\\nCallTrace: C:\\\\Windows\\\\SYSTEM32\\\\ntdll.dll+9ff24|C:\\\\Windows\\\\System32\\\\KERNELBASE.dll+1668e|C:\\\\Windows\\\\System32\\\\shcore.dll+cca8|C:\\\\Windows\\\\System32\\\\shcore.dll+b55c|C:\\\\Windows\\\\System32\\\\shcore.dll+b275|C:\\\\Windows\\\\System32\\\\shcore.dll+b209|C:\\\\Windows\\\\System32\\\\shcore.dll+b104|C:\\\\Windows\\\\system32\\\\explorerframe.dll+12b986|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+157bd8c|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+18051ce|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2e1a17|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2dfdfe|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+130216a|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a566ec|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a5695f|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3e93b|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c40433|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb8e|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3d62541|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb68|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c942dd|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3db94|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a52491|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a3e4a9\\r\\nSourceUser: WEB1\\\\Administrator\\r\\nTargetUser: WEB1\\\\Administrator\\""},"eventdata":{"ruleName":"technique_id=T1036,technique_name=Masquerading","utcTime":"2023-11-05 12:23:11.137","sourceProcessGUID":"{d9ab9ebb-7e1a-6544-44e0-010000003000}","sourceProcessId":"1652","sourceThreadId":"1284","sourceImage":"C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe","targetProcessGUID":"{d9ab9ebb-62bb-6547-601c-020000003000}","targetProcessId":"4384","targetImage":"C:\\\\\\\\Windows\\\\\\\\explorer.exe","grantedAccess":"0x40","callTrace":"C:\\\\\\\\Windows\\\\\\\\SYSTEM32\\\\\\\\ntdll.dll+9ff24|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\KERNELBASE.dll+1668e|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+cca8|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+b55c|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+b275|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+b209|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+b104|C:\\\\\\\\Windows\\\\\\\\system32\\\\\\\\explorerframe.dll+12b986|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+157bd8c|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+18051ce|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+2e1a17|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+2dfdfe|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+130216a|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+a566ec|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+a5695f|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c3e93b|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c40433|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3fbdb8e|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3d62541|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3fbdb68|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c942dd|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c3db94|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+a52491|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+a3e4a9","sourceUser":"WEB1\\\\\\\\Administrator","targetUser":"WEB1\\\\\\\\Administrator"}}},"location":"EventChannel"}',
427 rule_id: "92910",
428 manager_name: "ASHWZHMA",
429 location: "EventChannel",
430 data_win_eventdata_targetProcessId: "4384",
431 rule_group3: AlertSourceDataLogsourceProduct.Windows,
432 data_win_system_message:
433 '"Process accessed:\r\nRuleName: technique_id=T1036,technique_name=Masquerading\r\nUtcTime: 2023-11-05 12:23:11.137\r\nSourceProcessGUID: {d9ab9ebb-7e1a-6544-44e0-010000003000}\r\nSourceProcessId: 1652\r\nSourceThreadId: 1284\r\nSourceImage: C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe\r\nTargetProcessGUID: {d9ab9ebb-62bb-6547-601c-020000003000}\r\nTargetProcessId: 4384\r\nTargetImage: C:\\Windows\\explorer.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+9ff24|C:\\Windows\\System32\\KERNELBASE.dll+1668e|C:\\Windows\\System32\\shcore.dll+cca8|C:\\Windows\\System32\\shcore.dll+b55c|C:\\Windows\\System32\\shcore.dll+b275|C:\\Windows\\System32\\shcore.dll+b209|C:\\Windows\\System32\\shcore.dll+b104|C:\\Windows\\system32\\explorerframe.dll+12b986|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+157bd8c|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+18051ce|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+2e1a17|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+2dfdfe|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+130216a|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+a566ec|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+a5695f|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c3e93b|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c40433|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3fbdb8e|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3d62541|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3fbdb68|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c942dd|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c3db94|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+a52491|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+a3e4a9\r\nSourceUser: WEB1\\Administrator\r\nTargetUser: WEB1\\Administrator"',
434 data_win_eventdata_sourceThreadId: "1284",
435 msg_timestamp: "2023-11-05T12:23:12.272Z",
436 rule_group2: "sysmon_eid10_detections",
437 rule_group1: "sysmon"
438 },
439 sort: [1699186991138]
440 }
441 ]
442 },
443 {
444 index_name: "wazuh-zaff3p5c_0",
445 total_alerts: 1,
446 alerts: [
447 {
448 _index: "wazuh-zaff3p5c_0",
449 _id: "4978eea4-7bc5-11ee-93bc-86000046278a",
450 _score: null,
451 _source: {
452 parent_process_id: "3565733",
453 source_reserved_ip: true,
454 agent_id: "072",
455 agent_name: "ip-178-216-201-141",
456 gl2_remote_ip: "10.255.255.13",
457 gl2_remote_port: 46242,
458 agent_labels_customer: "zaff3p5c",
459 agent_ip_city_name: "N/A",
460 source: "10.255.255.13",
461 gl2_source_input: "6459151dea00fd5d3da2df91",
462 rule_level: 12,
463 data_calendarTime: "Sun Nov 5 10:22:52 2023 UTC",
464 data_counter: "8287",
465 data_columns_duration: "132210",
466 timestamp_utc: "2023-11-05T10:22:52.000Z",
467 syslog_type: AlertSourceSyslogType.Wazuh,
468 process_name: "/usr/bin/chmod",
469 process_cmd_line: "chmod +r /var/lib/update-notifier/updates-available",
470 data_hostIdentifier: "ip-178-216-201-141",
471 data_columns_probe_error: "0",
472 rule_description: "Detects file and folder permission changes.",
473 gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38",
474 id: "1699179774.599228705",
475 rule_mitre_tactic: "Defense Evasion",
476 process_image: "/usr/bin/chmod",
477 gl2_accounted_message_size: 2584,
478 data_columns_uid: "0",
479 streams: ["651176ee5e9a2d550c79fa32"],
480 rule_mitre_id: "T1222",
481 gl2_message_id: "01HEFG3JMB8FK2YN4EYWBQ5FSS",
482 agent_ip: "178.216.201.141",
483 data_columns_gid: "0",
484 data_columns_syscall: "exec",
485 true: 1699179774.197991,
486 data_columns_cid: "30181",
487 rule_groups: "osquery, bpf_process_events",
488 data_columns_exit_code: "0",
489 process_id: "3565780",
490 agent_ip_geolocation: "52.2394,21.0362",
491 rule_mitre_technique: "File and Directory Permissions Modification",
492 rule_firedtimes: 1,
493 rule_mail: true,
494 data_name: "bpf_process_events",
495 decoder_name: AlertSourceDecoderName.JSON,
496 agent_ip_country_code: "PL",
497 data_columns_ntime: "3515969404589692",
498 syslog_level: AlertSourceSyslogLevel.Alert,
499 timestamp: "2023-11-05 10:22:56.651",
500 data_columns_cmdline: "chmod +r /var/lib/update-notifier/updates-available",
501 data_columns_tid: "3565780",
502 gl2_processing_error:
503 'Replaced invalid timestamp value in message <4978eea4-7bc5-11ee-93bc-86000046278a> with current time - Value <2023-11-05T10:22:54.197+0000> caused exception: Invalid format: "2023-11-05T10:22:54.197+0000" is malformed at "T10:22:54.197+0000".',
504 data_columns_pid: "3565780",
505 message:
506 '{"true":1699179774.197991,"timestamp":"2023-11-05T10:22:54.197+0000","rule":{"level":12,"description":"Detects file and folder permission changes.","id":"200259","mitre":{"id":["T1222"],"tactic":["Defense Evasion"],"technique":["File and Directory Permissions Modification"]},"firedtimes":1,"mail":true,"groups":["osquery","bpf_process_events"]},"agent":{"id":"072","name":"ip-178-216-201-141","ip":"178.216.201.141","labels":{"customer":"zaff3p5c"}},"manager":{"name":"ASHWZHMA"},"id":"1699179774.599228705","decoder":{"name":"json"},"data":{"action":"added","name":"bpf_process_events","hostIdentifier":"ip-178-216-201-141","calendarTime":"Sun Nov 5 10:22:52 2023 UTC","unixTime":"1699179772","epoch":"0","counter":"8287","numerics":"false","columns":{"cid":"30181","cmdline":"chmod +r /var/lib/update-notifier/updates-available","duration":"132210","exit_code":"0","gid":"0","ntime":"3515969404589692","parent":"3565733","path":"/usr/bin/chmod","pid":"3565780","probe_error":"0","syscall":"exec","tid":"3565780","uid":"0"}},"location":"/var/log/osquery/osqueryd.results.log"}',
507 data_numerics: "false",
508 rule_id: "200259",
509 manager_name: "ASHWZHMA",
510 data_columns_path: "/usr/bin/chmod",
511 data_unixTime: "1699179772",
512 data_action: "added",
513 data_epoch: "0",
514 location: "/var/log/osquery/osqueryd.results.log",
515 data_columns_parent: "3565733",
516 msg_timestamp: "2023-11-05T10:22:54.197Z",
517 rule_group2: "bpf_process_events",
518 rule_group1: "osquery"
519 },
520 sort: [1699179772000]
521 }
522 ]
523 },
524 {
525 index_name: "wazuh_00002_201",
526 total_alerts: 5,
527 alerts: [
528 {
529 _index: "wazuh_00002_201",
530 _id: "366ba9a0-7bd5-11ee-93bc-86000046278a",
531 _score: null,
532 _source: {
533 data_system_Task: "11",
534 source_reserved_ip: true,
535 agent_id: "097",
536 agent_name: "ANSYDWDC01",
537 data_system_Correlation: "null",
538 gl2_remote_ip: "10.255.255.13",
539 gl2_remote_port: 50678,
540 agent_labels_customer: "00002",
541 data_system_Version: "2",
542 agent_ip_city_name: "Singapore",
543 source: "10.255.255.13",
544 gl2_source_input: "6459151dea00fd5d3da2df91",
545 rule_level: 12,
546 data_level: AlertSourceDataLevelEnum.High,
547 timestamp_utc: "2023-11-05T12:16:02.043Z",
548 data_event_ProcessId: "4684",
549 syslog_type: AlertSourceSyslogType.Wazuh,
550 data_system_Opcode: "0",
551 rule_description: "Process Explorer Driver Creation By Non-Sysinternals Binary",
552 gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38",
553 id: "1699186616.690805701",
554 data_status: AlertSourceDataStatus.Experimental,
555 data_system_Computer: "ANSYDWDC01.ANMS.LOCAL",
556 gl2_accounted_message_size: 10712,
557 data_document:
558 '{"kind":"evtx","path":"C:\\\\Windows\\\\System32\\\\winevt\\\\Logs\\\\Microsoft-Windows-Sysmon%4Operational.evtx","data":{"Event":{"EventData":{"CreationUtcTime":"2023-11-01 06:52:11.733","Image":"C:\\\\Program Files\\\\socfortress\\\\sysinternals\\\\logonsessions64.exe","ProcessGuid":"6D0AAEFA-8781-6547-C4BB-000000004200","ProcessId":4684,"RuleName":"-","TargetFilename":"C:\\\\Windows\\\\System32\\\\drivers\\\\PROCEXP152.SYS","User":"NT AUTHORITY\\\\SYSTEM","UtcTime":"2023-11-05 12:16:02.043"},"System":{"Channel":"Microsoft-Windows-Sysmon/Operational","Computer":"ANSYDWDC01.ANMS.LOCAL","Correlation":null,"EventID":11,"EventRecordID":18141034,"Execution_attributes":{"ProcessID":2564,"ThreadID":3804},"Keywords":"0x8000000000000000","Level":4,"Opcode":0,"Provider_attributes":{"Guid":"5770385F-C22A-43E0-BF4C-06F5698FFBD9","Name":"Microsoft-Windows-Sysmon"},"Security_attributes":{"UserID":"S-1-5-18"},"Task":11,"TimeCreated_attributes":{"SystemTime":"2023-11-05T12:16:02.045670Z"},"Version":2}},"Event_attributes":{"xmlns":"http://schemas.microsoft.com/win/2004/08/events/event"}}}',
559 data_event_UtcTime: "2023-11-05 12:16:02.043",
560 streams: ["645a3a6123e5cc30bbc0e5dc"],
561 gl2_message_id: "01HEFPMAE4N8YW57K4Q6P44CKB",
562 data_source: AlertSourceDataLogsourceProduct.Sigma,
563 agent_ip: "139.180.134.102",
564 data_system_Security_attributes_UserID: "S-1-5-18",
565 true: 1699186616.142398,
566 data_timestamp: "2023-11-05T12:16:02.045670+00:00",
567 data_system_Level: "4",
568 data_event_CreationUtcTime: "2023-11-01 06:52:11.733",
569 data_system_Execution_attributes_ProcessID: "2564",
570 rule_groups: "windows, chainsaw, sigma",
571 data_system_EventRecordID: "18141034",
572 process_id: "4684",
573 data_system_TimeCreated_attributes_SystemTime: "2023-11-05T12:16:02.045670Z",
574 data_event_RuleName: "-",
575 data_logsource_category: AlertSourceDataLogsourceCategory.FileEvent,
576 data_system_Keywords: "0x8000000000000000",
577 sigma_name_encoded: "Process%20Explorer%20Driver%20Creation%20By%20Non-Sysinternals%20Binary",
578 agent_ip_geolocation: "1.3078,103.6818",
579 data_group: AlertSourceDataGroup.Sigma,
580 rule_firedtimes: 1,
581 data_event_User: "NT AUTHORITY\\SYSTEM",
582 data_path: "C:\\Windows\\System32\\winevt\\Logs\\Microsoft-Windows-Sysmon%4Operational.evtx",
583 rule_mail: true,
584 data_system_Provider_attributes_Name: "Microsoft-Windows-Sysmon",
585 data_name: "Process Explorer Driver Creation By Non-Sysinternals Binary",
586 decoder_name: AlertSourceDecoderName.JSON,
587 data_id: "de46c52b-0bf8-4936-a327-aace94f94ac6",
588 agent_ip_country_code: "SG",
589 syslog_level: AlertSourceSyslogLevel.Alert,
590 data_tags: "attack.persistence, attack.privilege_escalation, attack.t1068",
591 data_kind: AlertSourceDataKind.Individual,
592 data_logsource_product: AlertSourceDataLogsourceProduct.Windows,
593 timestamp: "2023-11-05 12:16:56.772",
594 ask_socfortress_message:
595 "The SIGMA alert \"Process Explorer Driver Creation By Non-Sysinternals Binary\" suggests that a non-Sysinternals binary has attempted to create a Process Explorer driver on a Windows endpoint. Process Explorer is a widely used system monitoring tool developed by Sysinternals (now part of Microsoft). The creation of a Process Explorer driver by a non-Sysinternals binary could indicate suspicious or potentially malicious activity.\n\nTo investigate this alert and determine an appropriate response, you should focus on the following key aspects:\n\n1. Validate the Alert: Verify the accuracy of the alert by checking if it was triggered by legitimate activity or if it is a false positive. Ensure that your detection system is properly configured and up to date.\n\n2. Identify the Binary: Determine which specific binary attempted to create the Process Explorer driver. Look for any unusual or suspicious characteristics such as unfamiliar names, file paths, digital signatures, or hash values.\n\n3. Analyze Process Execution Context: Investigate the context in which the binary executed and attempted to create the driver. Review process execution details, such as parent processes, command-line arguments, process creation time, and associated network connections.\n\n4. Assess System Impact: Evaluate whether any abnormal behavior occurred on the endpoint after this event took place. Look for signs of system instability, crashes, performance degradation, or other anomalous activities that may indicate malicious intent.\n\n5. Conduct File Analysis: Perform an in-depth analysis of the binary itself using appropriate tools like antivirus scanners and sandboxing environments to identify any malware indicators such as malicious code patterns or known signatures associated with malware families.\n\n6. Check Reputation: Research information about the binary's reputation online using threat intelligence platforms, virus total scanners, or security forums to determine if it has been previously identified as malicious.\n\n7. Perform Behavioral Analysis: If feasible, conduct dynamic analysis by executing the binary in an isolated environment while monitoring its behavior for any suspicious activities like network communication, file system changes, or attempts to escalate privileges.\n\n8. Review System Logs: Examine relevant logs such as event logs, process creation logs, driver loading logs, and network logs to identify any additional indicators of compromise or related activities.\n\nWhen assessing this alert, you should also ask yourself the following additional questions:\n\n1. Is the binary a legitimate tool that is commonly used in your organization? If not, why would it be present on the endpoint?\n\n2. Is there a business justification for creating a Process Explorer driver with this specific binary? Are there any documented cases or known legitimate reasons for doing so?\n\n3. Are there any other security events or alerts related to this binary or associated processes that can provide further context?\n\n4. Has the binary been whitelisted or approved by your organization's security policies? If not, why was it allowed to execute on the endpoint?\n\n5. Do you have sufficient visibility into other endpoints within your environment? Have similar events been observed elsewhere? This could indicate a larger-scale attack.\n\nRemember that each investigation may vary based on your organization's specific context and requirements.",
596 data_system_Channel: "Microsoft-Windows-Sysmon/Operational",
597 data_references:
598 "https://learn.microsoft.com/en-us/sysinternals/downloads/process-explorer, https://github.com/Yaxser/Backstab, https://www.elastic.co/security-labs/stopping-vulnerable-driver-attacks, https://news.sophos.com/en-us/2023/04/19/aukill-edr-killer-malware-abuses-process-explorer-driver/",
599 data_event_ProcessGuid: "6D0AAEFA-8781-6547-C4BB-000000004200",
600 gl2_processing_error:
601 'Replaced invalid timestamp value in message <366ba9a0-7bd5-11ee-93bc-86000046278a> with current time - Value <2023-11-05T12:16:56.030+0000> caused exception: Invalid format: "2023-11-05T12:16:56.030+0000" is malformed at "T12:16:56.030+0000".',
602 data_falsepositives:
603 "Some false positives may occur with legitimate renamed process explorer binaries",
604 data_event_Image: "C:\\Program Files\\socfortress\\sysinternals\\logonsessions64.exe",
605 data_system_Execution_attributes_ThreadID: "3804",
606 message:
607 '{"true":1699186616.142398,"timestamp":"2023-11-05T12:16:56.030+0000","rule":{"level":12,"description":"Process Explorer Driver Creation By Non-Sysinternals Binary","id":"200051","firedtimes":1,"mail":true,"groups":["windows","chainsaw","sigma"]},"agent":{"id":"097","name":"ANSYDWDC01","ip":"139.180.134.102","labels":{"customer":"00002"}},"manager":{"name":"ASHWZHMA"},"id":"1699186616.690805701","decoder":{"name":"json"},"data":{"id":"de46c52b-0bf8-4936-a327-aace94f94ac6","status":"experimental","group":"Sigma","kind":"individual","document":"{\\"kind\\":\\"evtx\\",\\"path\\":\\"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\winevt\\\\\\\\Logs\\\\\\\\Microsoft-Windows-Sysmon%4Operational.evtx\\",\\"data\\":{\\"Event\\":{\\"EventData\\":{\\"CreationUtcTime\\":\\"2023-11-01 06:52:11.733\\",\\"Image\\":\\"C:\\\\\\\\Program Files\\\\\\\\socfortress\\\\\\\\sysinternals\\\\\\\\logonsessions64.exe\\",\\"ProcessGuid\\":\\"6D0AAEFA-8781-6547-C4BB-000000004200\\",\\"ProcessId\\":4684,\\"RuleName\\":\\"-\\",\\"TargetFilename\\":\\"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\drivers\\\\\\\\PROCEXP152.SYS\\",\\"User\\":\\"NT AUTHORITY\\\\\\\\SYSTEM\\",\\"UtcTime\\":\\"2023-11-05 12:16:02.043\\"},\\"System\\":{\\"Channel\\":\\"Microsoft-Windows-Sysmon/Operational\\",\\"Computer\\":\\"ANSYDWDC01.ANMS.LOCAL\\",\\"Correlation\\":null,\\"EventID\\":11,\\"EventRecordID\\":18141034,\\"Execution_attributes\\":{\\"ProcessID\\":2564,\\"ThreadID\\":3804},\\"Keywords\\":\\"0x8000000000000000\\",\\"Level\\":4,\\"Opcode\\":0,\\"Provider_attributes\\":{\\"Guid\\":\\"5770385F-C22A-43E0-BF4C-06F5698FFBD9\\",\\"Name\\":\\"Microsoft-Windows-Sysmon\\"},\\"Security_attributes\\":{\\"UserID\\":\\"S-1-5-18\\"},\\"Task\\":11,\\"TimeCreated_attributes\\":{\\"SystemTime\\":\\"2023-11-05T12:16:02.045670Z\\"},\\"Version\\":2}},\\"Event_attributes\\":{\\"xmlns\\":\\"http://schemas.microsoft.com/win/2004/08/events/event\\"}}}","event":{"CreationUtcTime":"2023-11-01 06:52:11.733","Image":"C:\\\\Program Files\\\\socfortress\\\\sysinternals\\\\logonsessions64.exe","ProcessGuid":"6D0AAEFA-8781-6547-C4BB-000000004200","ProcessId":"4684","RuleName":"-","TargetFilename":"C:\\\\Windows\\\\System32\\\\drivers\\\\PROCEXP152.SYS","User":"NT AUTHORITY\\\\SYSTEM","UtcTime":"2023-11-05 12:16:02.043"},"path":"C:\\\\Windows\\\\System32\\\\winevt\\\\Logs\\\\Microsoft-Windows-Sysmon%4Operational.evtx","system":{"Channel":"Microsoft-Windows-Sysmon/Operational","Computer":"ANSYDWDC01.ANMS.LOCAL","Correlation":"null","EventID":"11","EventRecordID":"18141034","Execution_attributes":{"ProcessID":"2564","ThreadID":"3804"},"Keywords":"0x8000000000000000","Level":"4","Opcode":"0","Provider_attributes":{"Guid":"5770385F-C22A-43E0-BF4C-06F5698FFBD9","Name":"Microsoft-Windows-Sysmon"},"Security_attributes":{"UserID":"S-1-5-18"},"Task":"11","TimeCreated_attributes":{"SystemTime":"2023-11-05T12:16:02.045670Z"},"Version":"2"},"name":"Process Explorer Driver Creation By Non-Sysinternals Binary","timestamp":"2023-11-05T12:16:02.045670+00:00","authors":["Florian Roth (Nextron Systems)"],"level":"high","source":"sigma","falsepositives":["Some false positives may occur with legitimate renamed process explorer binaries"],"logsource":{"category":"file_event","product":"windows"},"references":["https://learn.microsoft.com/en-us/sysinternals/downloads/process-explorer","https://github.com/Yaxser/Backstab","https://www.elastic.co/security-labs/stopping-vulnerable-driver-attacks","https://news.sophos.com/en-us/2023/04/19/aukill-edr-killer-malware-abuses-process-explorer-driver/"],"tags":["attack.persistence","attack.privilege_escalation","attack.t1068"]},"location":"active-response\\\\active-responses.log"}',
608 data_system_EventID: "11",
609 data_system_Provider_attributes_Guid: "5770385F-C22A-43E0-BF4C-06F5698FFBD9",
610 rule_id: "200051",
611 manager_name: "ASHWZHMA",
612 data_event_TargetFilename: "C:\\Windows\\System32\\drivers\\PROCEXP152.SYS",
613 location: "active-response\\active-responses.log",
614 data_authors: "Florian Roth (Nextron Systems)",
615 rule_group3: AlertSourceDataLogsourceProduct.Sigma,
616 msg_timestamp: "2023-11-05T12:16:56.030Z",
617 rule_group2: "chainsaw",
618 rule_group1: "windows"
619 },
620 sort: [1699186562043]
621 },
622 {
623 _index: "wazuh_00002_201",
624 _id: "2e1383c2-7bd7-11ee-93bc-86000046278a",
625 _score: null,
626 _source: {
627 data_system_Task: "11",
628 source_reserved_ip: true,
629 agent_id: "097",
630 agent_name: "ANSYDWDC01",
631 data_system_Correlation: "null",
632 gl2_remote_ip: "10.255.255.13",
633 gl2_remote_port: 35304,
634 agent_labels_customer: "00002",
635 data_system_Version: "2",
636 agent_ip_city_name: "Singapore",
637 source: "10.255.255.13",
638 gl2_source_input: "6459151dea00fd5d3da2df91",
639 rule_level: 12,
640 data_level: AlertSourceDataLevelEnum.High,
641 timestamp_utc: "2023-11-05T12:16:02.043Z",
642 data_event_ProcessId: "4684",
643 syslog_type: AlertSourceSyslogType.Wazuh,
644 data_system_Opcode: "0",
645 rule_description: "Process Explorer Driver Creation By Non-Sysinternals Binary",
646 gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38",
647 id: "1699187457.705230523",
648 data_status: AlertSourceDataStatus.Experimental,
649 data_system_Computer: "ANSYDWDC01.ANMS.LOCAL",
650 gl2_accounted_message_size: 10712,
651 data_document:
652 '{"kind":"evtx","path":"C:\\\\Windows\\\\System32\\\\winevt\\\\Logs\\\\Microsoft-Windows-Sysmon%4Operational.evtx","data":{"Event":{"EventData":{"CreationUtcTime":"2023-11-01 06:52:11.733","Image":"C:\\\\Program Files\\\\socfortress\\\\sysinternals\\\\logonsessions64.exe","ProcessGuid":"6D0AAEFA-8781-6547-C4BB-000000004200","ProcessId":4684,"RuleName":"-","TargetFilename":"C:\\\\Windows\\\\System32\\\\drivers\\\\PROCEXP152.SYS","User":"NT AUTHORITY\\\\SYSTEM","UtcTime":"2023-11-05 12:16:02.043"},"System":{"Channel":"Microsoft-Windows-Sysmon/Operational","Computer":"ANSYDWDC01.ANMS.LOCAL","Correlation":null,"EventID":11,"EventRecordID":18141034,"Execution_attributes":{"ProcessID":2564,"ThreadID":3804},"Keywords":"0x8000000000000000","Level":4,"Opcode":0,"Provider_attributes":{"Guid":"5770385F-C22A-43E0-BF4C-06F5698FFBD9","Name":"Microsoft-Windows-Sysmon"},"Security_attributes":{"UserID":"S-1-5-18"},"Task":11,"TimeCreated_attributes":{"SystemTime":"2023-11-05T12:16:02.045670Z"},"Version":2}},"Event_attributes":{"xmlns":"http://schemas.microsoft.com/win/2004/08/events/event"}}}',
653 data_event_UtcTime: "2023-11-05 12:16:02.043",
654 streams: ["645a3a6123e5cc30bbc0e5dc"],
655 gl2_message_id: "01HEFQE3FX6ARYDEQYMHJPGTE9",
656 data_source: AlertSourceDataLogsourceProduct.Sigma,
657 agent_ip: "139.180.134.102",
658 data_system_Security_attributes_UserID: "S-1-5-18",
659 true: 1699187457.773739,
660 data_timestamp: "2023-11-05T12:16:02.045670+00:00",
661 data_system_Level: "4",
662 data_event_CreationUtcTime: "2023-11-01 06:52:11.733",
663 data_system_Execution_attributes_ProcessID: "2564",
664 rule_groups: "windows, chainsaw, sigma",
665 data_system_EventRecordID: "18141034",
666 process_id: "4684",
667 data_system_TimeCreated_attributes_SystemTime: "2023-11-05T12:16:02.045670Z",
668 data_event_RuleName: "-",
669 data_logsource_category: AlertSourceDataLogsourceCategory.FileEvent,
670 data_system_Keywords: "0x8000000000000000",
671 sigma_name_encoded: "Process%20Explorer%20Driver%20Creation%20By%20Non-Sysinternals%20Binary",
672 agent_ip_geolocation: "1.3078,103.6818",
673 data_group: AlertSourceDataGroup.Sigma,
674 rule_firedtimes: 2,
675 data_event_User: "NT AUTHORITY\\SYSTEM",
676 data_path: "C:\\Windows\\System32\\winevt\\Logs\\Microsoft-Windows-Sysmon%4Operational.evtx",
677 rule_mail: true,
678 data_system_Provider_attributes_Name: "Microsoft-Windows-Sysmon",
679 data_name: "Process Explorer Driver Creation By Non-Sysinternals Binary",
680 decoder_name: AlertSourceDecoderName.JSON,
681 data_id: "de46c52b-0bf8-4936-a327-aace94f94ac6",
682 agent_ip_country_code: "SG",
683 syslog_level: AlertSourceSyslogLevel.Alert,
684 data_tags: "attack.persistence, attack.privilege_escalation, attack.t1068",
685 data_kind: AlertSourceDataKind.Individual,
686 data_logsource_product: AlertSourceDataLogsourceProduct.Windows,
687 timestamp: "2023-11-05 12:31:01.629",
688 ask_socfortress_message:
689 "The SIGMA alert \"Process Explorer Driver Creation By Non-Sysinternals Binary\" suggests that a non-Sysinternals binary has attempted to create a Process Explorer driver on a Windows endpoint. Process Explorer is a widely used system monitoring tool developed by Sysinternals (now part of Microsoft). The creation of a Process Explorer driver by a non-Sysinternals binary could indicate suspicious or potentially malicious activity.\n\nTo investigate this alert and determine an appropriate response, you should focus on the following key aspects:\n\n1. Validate the Alert: Verify the accuracy of the alert by checking if it was triggered by legitimate activity or if it is a false positive. Ensure that your detection system is properly configured and up to date.\n\n2. Identify the Binary: Determine which specific binary attempted to create the Process Explorer driver. Look for any unusual or suspicious characteristics such as unfamiliar names, file paths, digital signatures, or hash values.\n\n3. Analyze Process Execution Context: Investigate the context in which the binary executed and attempted to create the driver. Review process execution details, such as parent processes, command-line arguments, process creation time, and associated network connections.\n\n4. Assess System Impact: Evaluate whether any abnormal behavior occurred on the endpoint after this event took place. Look for signs of system instability, crashes, performance degradation, or other anomalous activities that may indicate malicious intent.\n\n5. Conduct File Analysis: Perform an in-depth analysis of the binary itself using appropriate tools like antivirus scanners and sandboxing environments to identify any malware indicators such as malicious code patterns or known signatures associated with malware families.\n\n6. Check Reputation: Research information about the binary's reputation online using threat intelligence platforms, virus total scanners, or security forums to determine if it has been previously identified as malicious.\n\n7. Perform Behavioral Analysis: If feasible, conduct dynamic analysis by executing the binary in an isolated environment while monitoring its behavior for any suspicious activities like network communication, file system changes, or attempts to escalate privileges.\n\n8. Review System Logs: Examine relevant logs such as event logs, process creation logs, driver loading logs, and network logs to identify any additional indicators of compromise or related activities.\n\nWhen assessing this alert, you should also ask yourself the following additional questions:\n\n1. Is the binary a legitimate tool that is commonly used in your organization? If not, why would it be present on the endpoint?\n\n2. Is there a business justification for creating a Process Explorer driver with this specific binary? Are there any documented cases or known legitimate reasons for doing so?\n\n3. Are there any other security events or alerts related to this binary or associated processes that can provide further context?\n\n4. Has the binary been whitelisted or approved by your organization's security policies? If not, why was it allowed to execute on the endpoint?\n\n5. Do you have sufficient visibility into other endpoints within your environment? Have similar events been observed elsewhere? This could indicate a larger-scale attack.\n\nRemember that each investigation may vary based on your organization's specific context and requirements.",
690 data_system_Channel: "Microsoft-Windows-Sysmon/Operational",
691 data_references:
692 "https://learn.microsoft.com/en-us/sysinternals/downloads/process-explorer, https://github.com/Yaxser/Backstab, https://www.elastic.co/security-labs/stopping-vulnerable-driver-attacks, https://news.sophos.com/en-us/2023/04/19/aukill-edr-killer-malware-abuses-process-explorer-driver/",
693 data_event_ProcessGuid: "6D0AAEFA-8781-6547-C4BB-000000004200",
694 gl2_processing_error:
695 'Replaced invalid timestamp value in message <2e1383c2-7bd7-11ee-93bc-86000046278a> with current time - Value <2023-11-05T12:30:57.704+0000> caused exception: Invalid format: "2023-11-05T12:30:57.704+0000" is malformed at "T12:30:57.704+0000".',
696 data_falsepositives:
697 "Some false positives may occur with legitimate renamed process explorer binaries",
698 data_event_Image: "C:\\Program Files\\socfortress\\sysinternals\\logonsessions64.exe",
699 data_system_Execution_attributes_ThreadID: "3804",
700 message:
701 '{"true":1699187457.773739,"timestamp":"2023-11-05T12:30:57.704+0000","rule":{"level":12,"description":"Process Explorer Driver Creation By Non-Sysinternals Binary","id":"200051","firedtimes":2,"mail":true,"groups":["windows","chainsaw","sigma"]},"agent":{"id":"097","name":"ANSYDWDC01","ip":"139.180.134.102","labels":{"customer":"00002"}},"manager":{"name":"ASHWZHMA"},"id":"1699187457.705230523","decoder":{"name":"json"},"data":{"id":"de46c52b-0bf8-4936-a327-aace94f94ac6","status":"experimental","group":"Sigma","kind":"individual","document":"{\\"kind\\":\\"evtx\\",\\"path\\":\\"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\winevt\\\\\\\\Logs\\\\\\\\Microsoft-Windows-Sysmon%4Operational.evtx\\",\\"data\\":{\\"Event\\":{\\"EventData\\":{\\"CreationUtcTime\\":\\"2023-11-01 06:52:11.733\\",\\"Image\\":\\"C:\\\\\\\\Program Files\\\\\\\\socfortress\\\\\\\\sysinternals\\\\\\\\logonsessions64.exe\\",\\"ProcessGuid\\":\\"6D0AAEFA-8781-6547-C4BB-000000004200\\",\\"ProcessId\\":4684,\\"RuleName\\":\\"-\\",\\"TargetFilename\\":\\"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\drivers\\\\\\\\PROCEXP152.SYS\\",\\"User\\":\\"NT AUTHORITY\\\\\\\\SYSTEM\\",\\"UtcTime\\":\\"2023-11-05 12:16:02.043\\"},\\"System\\":{\\"Channel\\":\\"Microsoft-Windows-Sysmon/Operational\\",\\"Computer\\":\\"ANSYDWDC01.ANMS.LOCAL\\",\\"Correlation\\":null,\\"EventID\\":11,\\"EventRecordID\\":18141034,\\"Execution_attributes\\":{\\"ProcessID\\":2564,\\"ThreadID\\":3804},\\"Keywords\\":\\"0x8000000000000000\\",\\"Level\\":4,\\"Opcode\\":0,\\"Provider_attributes\\":{\\"Guid\\":\\"5770385F-C22A-43E0-BF4C-06F5698FFBD9\\",\\"Name\\":\\"Microsoft-Windows-Sysmon\\"},\\"Security_attributes\\":{\\"UserID\\":\\"S-1-5-18\\"},\\"Task\\":11,\\"TimeCreated_attributes\\":{\\"SystemTime\\":\\"2023-11-05T12:16:02.045670Z\\"},\\"Version\\":2}},\\"Event_attributes\\":{\\"xmlns\\":\\"http://schemas.microsoft.com/win/2004/08/events/event\\"}}}","event":{"CreationUtcTime":"2023-11-01 06:52:11.733","Image":"C:\\\\Program Files\\\\socfortress\\\\sysinternals\\\\logonsessions64.exe","ProcessGuid":"6D0AAEFA-8781-6547-C4BB-000000004200","ProcessId":"4684","RuleName":"-","TargetFilename":"C:\\\\Windows\\\\System32\\\\drivers\\\\PROCEXP152.SYS","User":"NT AUTHORITY\\\\SYSTEM","UtcTime":"2023-11-05 12:16:02.043"},"path":"C:\\\\Windows\\\\System32\\\\winevt\\\\Logs\\\\Microsoft-Windows-Sysmon%4Operational.evtx","system":{"Channel":"Microsoft-Windows-Sysmon/Operational","Computer":"ANSYDWDC01.ANMS.LOCAL","Correlation":"null","EventID":"11","EventRecordID":"18141034","Execution_attributes":{"ProcessID":"2564","ThreadID":"3804"},"Keywords":"0x8000000000000000","Level":"4","Opcode":"0","Provider_attributes":{"Guid":"5770385F-C22A-43E0-BF4C-06F5698FFBD9","Name":"Microsoft-Windows-Sysmon"},"Security_attributes":{"UserID":"S-1-5-18"},"Task":"11","TimeCreated_attributes":{"SystemTime":"2023-11-05T12:16:02.045670Z"},"Version":"2"},"name":"Process Explorer Driver Creation By Non-Sysinternals Binary","timestamp":"2023-11-05T12:16:02.045670+00:00","authors":["Florian Roth (Nextron Systems)"],"level":"high","source":"sigma","falsepositives":["Some false positives may occur with legitimate renamed process explorer binaries"],"logsource":{"category":"file_event","product":"windows"},"references":["https://learn.microsoft.com/en-us/sysinternals/downloads/process-explorer","https://github.com/Yaxser/Backstab","https://www.elastic.co/security-labs/stopping-vulnerable-driver-attacks","https://news.sophos.com/en-us/2023/04/19/aukill-edr-killer-malware-abuses-process-explorer-driver/"],"tags":["attack.persistence","attack.privilege_escalation","attack.t1068"]},"location":"active-response\\\\active-responses.log"}',
702 data_system_EventID: "11",
703 data_system_Provider_attributes_Guid: "5770385F-C22A-43E0-BF4C-06F5698FFBD9",
704 rule_id: "200051",
705 manager_name: "ASHWZHMA",
706 data_event_TargetFilename: "C:\\Windows\\System32\\drivers\\PROCEXP152.SYS",
707 location: "active-response\\active-responses.log",
708 data_authors: "Florian Roth (Nextron Systems)",
709 rule_group3: AlertSourceDataLogsourceProduct.Sigma,
710 msg_timestamp: "2023-11-05T12:30:57.704Z",
711 rule_group2: "chainsaw",
712 rule_group1: "windows"
713 },
714 sort: [1699186562043]
715 },
716 {
717 _index: "wazuh_00002_201",
718 _id: "d4a60924-7bcc-11ee-93bc-86000046278a",
719 _score: null,
720 _source: {
721 data_system_Task: "11",
722 source_reserved_ip: true,
723 agent_id: "097",
724 agent_name: "ANSYDWDC01",
725 data_system_Correlation: "null",
726 gl2_remote_ip: "10.255.255.13",
727 gl2_remote_port: 38584,
728 agent_labels_customer: "00002",
729 data_system_Version: "2",
730 agent_ip_city_name: "Singapore",
731 source: "10.255.255.13",
732 gl2_source_input: "6459151dea00fd5d3da2df91",
733 rule_level: 12,
734 data_level: AlertSourceDataLevelEnum.High,
735 timestamp_utc: "2023-11-05T11:16:02.307Z",
736 data_event_ProcessId: "6712",
737 syslog_type: AlertSourceSyslogType.Wazuh,
738 data_system_Opcode: "0",
739 rule_description: "Process Explorer Driver Creation By Non-Sysinternals Binary",
740 gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38",
741 id: "1699183014.641989382",
742 data_status: AlertSourceDataStatus.Experimental,
743 data_system_Computer: "ANSYDWDC01.ANMS.LOCAL",
744 gl2_accounted_message_size: 10712,
745 data_document:
746 '{"kind":"evtx","path":"C:\\\\Windows\\\\System32\\\\winevt\\\\Logs\\\\Microsoft-Windows-Sysmon%4Operational.evtx","data":{"Event":{"EventData":{"CreationUtcTime":"2023-11-01 06:52:11.733","Image":"C:\\\\Program Files\\\\socfortress\\\\sysinternals\\\\logonsessions64.exe","ProcessGuid":"6D0AAEFA-7972-6547-E6B9-000000004200","ProcessId":6712,"RuleName":"-","TargetFilename":"C:\\\\Windows\\\\System32\\\\drivers\\\\PROCEXP152.SYS","User":"NT AUTHORITY\\\\SYSTEM","UtcTime":"2023-11-05 11:16:02.307"},"System":{"Channel":"Microsoft-Windows-Sysmon/Operational","Computer":"ANSYDWDC01.ANMS.LOCAL","Correlation":null,"EventID":11,"EventRecordID":18140573,"Execution_attributes":{"ProcessID":2564,"ThreadID":3804},"Keywords":"0x8000000000000000","Level":4,"Opcode":0,"Provider_attributes":{"Guid":"5770385F-C22A-43E0-BF4C-06F5698FFBD9","Name":"Microsoft-Windows-Sysmon"},"Security_attributes":{"UserID":"S-1-5-18"},"Task":11,"TimeCreated_attributes":{"SystemTime":"2023-11-05T11:16:02.321071Z"},"Version":2}},"Event_attributes":{"xmlns":"http://schemas.microsoft.com/win/2004/08/events/event"}}}',
747 data_event_UtcTime: "2023-11-05 11:16:02.307",
748 streams: ["645a3a6123e5cc30bbc0e5dc"],
749 gl2_message_id: "01HEFK6ESE3ZHZY3GH5THZQ7VS",
750 data_source: AlertSourceDataLogsourceProduct.Sigma,
751 agent_ip: "139.180.134.102",
752 data_system_Security_attributes_UserID: "S-1-5-18",
753 true: 1699183014.546914,
754 data_timestamp: "2023-11-05T11:16:02.321071+00:00",
755 data_system_Level: "4",
756 data_event_CreationUtcTime: "2023-11-01 06:52:11.733",
757 data_system_Execution_attributes_ProcessID: "2564",
758 rule_groups: "windows, chainsaw, sigma",
759 data_system_EventRecordID: "18140573",
760 process_id: "6712",
761 data_system_TimeCreated_attributes_SystemTime: "2023-11-05T11:16:02.321071Z",
762 data_event_RuleName: "-",
763 data_logsource_category: AlertSourceDataLogsourceCategory.FileEvent,
764 data_system_Keywords: "0x8000000000000000",
765 sigma_name_encoded: "Process%20Explorer%20Driver%20Creation%20By%20Non-Sysinternals%20Binary",
766 agent_ip_geolocation: "1.3078,103.6818",
767 data_group: AlertSourceDataGroup.Sigma,
768 rule_firedtimes: 1,
769 data_event_User: "NT AUTHORITY\\SYSTEM",
770 data_path: "C:\\Windows\\System32\\winevt\\Logs\\Microsoft-Windows-Sysmon%4Operational.evtx",
771 rule_mail: true,
772 data_system_Provider_attributes_Name: "Microsoft-Windows-Sysmon",
773 data_name: "Process Explorer Driver Creation By Non-Sysinternals Binary",
774 decoder_name: AlertSourceDecoderName.JSON,
775 data_id: "de46c52b-0bf8-4936-a327-aace94f94ac6",
776 agent_ip_country_code: "SG",
777 syslog_level: AlertSourceSyslogLevel.Alert,
778 data_tags: "attack.persistence, attack.privilege_escalation, attack.t1068",
779 data_kind: AlertSourceDataKind.Individual,
780 data_logsource_product: AlertSourceDataLogsourceProduct.Windows,
781 timestamp: "2023-11-05 11:16:56.750",
782 ask_socfortress_message:
783 "The SIGMA alert \"Process Explorer Driver Creation By Non-Sysinternals Binary\" suggests that a non-Sysinternals binary has attempted to create a Process Explorer driver on a Windows endpoint. Process Explorer is a widely used system monitoring tool developed by Sysinternals (now part of Microsoft). The creation of a Process Explorer driver by a non-Sysinternals binary could indicate suspicious or potentially malicious activity.\n\nTo investigate this alert and determine an appropriate response, you should focus on the following key aspects:\n\n1. Validate the Alert: Verify the accuracy of the alert by checking if it was triggered by legitimate activity or if it is a false positive. Ensure that your detection system is properly configured and up to date.\n\n2. Identify the Binary: Determine which specific binary attempted to create the Process Explorer driver. Look for any unusual or suspicious characteristics such as unfamiliar names, file paths, digital signatures, or hash values.\n\n3. Analyze Process Execution Context: Investigate the context in which the binary executed and attempted to create the driver. Review process execution details, such as parent processes, command-line arguments, process creation time, and associated network connections.\n\n4. Assess System Impact: Evaluate whether any abnormal behavior occurred on the endpoint after this event took place. Look for signs of system instability, crashes, performance degradation, or other anomalous activities that may indicate malicious intent.\n\n5. Conduct File Analysis: Perform an in-depth analysis of the binary itself using appropriate tools like antivirus scanners and sandboxing environments to identify any malware indicators such as malicious code patterns or known signatures associated with malware families.\n\n6. Check Reputation: Research information about the binary's reputation online using threat intelligence platforms, virus total scanners, or security forums to determine if it has been previously identified as malicious.\n\n7. Perform Behavioral Analysis: If feasible, conduct dynamic analysis by executing the binary in an isolated environment while monitoring its behavior for any suspicious activities like network communication, file system changes, or attempts to escalate privileges.\n\n8. Review System Logs: Examine relevant logs such as event logs, process creation logs, driver loading logs, and network logs to identify any additional indicators of compromise or related activities.\n\nWhen assessing this alert, you should also ask yourself the following additional questions:\n\n1. Is the binary a legitimate tool that is commonly used in your organization? If not, why would it be present on the endpoint?\n\n2. Is there a business justification for creating a Process Explorer driver with this specific binary? Are there any documented cases or known legitimate reasons for doing so?\n\n3. Are there any other security events or alerts related to this binary or associated processes that can provide further context?\n\n4. Has the binary been whitelisted or approved by your organization's security policies? If not, why was it allowed to execute on the endpoint?\n\n5. Do you have sufficient visibility into other endpoints within your environment? Have similar events been observed elsewhere? This could indicate a larger-scale attack.\n\nRemember that each investigation may vary based on your organization's specific context and requirements.",
784 data_system_Channel: "Microsoft-Windows-Sysmon/Operational",
785 data_references:
786 "https://learn.microsoft.com/en-us/sysinternals/downloads/process-explorer, https://github.com/Yaxser/Backstab, https://www.elastic.co/security-labs/stopping-vulnerable-driver-attacks, https://news.sophos.com/en-us/2023/04/19/aukill-edr-killer-malware-abuses-process-explorer-driver/",
787 data_event_ProcessGuid: "6D0AAEFA-7972-6547-E6B9-000000004200",
788 gl2_processing_error:
789 'Replaced invalid timestamp value in message <d4a60924-7bcc-11ee-93bc-86000046278a> with current time - Value <2023-11-05T11:16:54.542+0000> caused exception: Invalid format: "2023-11-05T11:16:54.542+0000" is malformed at "T11:16:54.542+0000".',
790 data_falsepositives:
791 "Some false positives may occur with legitimate renamed process explorer binaries",
792 data_event_Image: "C:\\Program Files\\socfortress\\sysinternals\\logonsessions64.exe",
793 data_system_Execution_attributes_ThreadID: "3804",
794 message:
795 '{"true":1699183014.546914,"timestamp":"2023-11-05T11:16:54.542+0000","rule":{"level":12,"description":"Process Explorer Driver Creation By Non-Sysinternals Binary","id":"200051","firedtimes":1,"mail":true,"groups":["windows","chainsaw","sigma"]},"agent":{"id":"097","name":"ANSYDWDC01","ip":"139.180.134.102","labels":{"customer":"00002"}},"manager":{"name":"ASHWZHMA"},"id":"1699183014.641989382","decoder":{"name":"json"},"data":{"id":"de46c52b-0bf8-4936-a327-aace94f94ac6","status":"experimental","group":"Sigma","kind":"individual","document":"{\\"kind\\":\\"evtx\\",\\"path\\":\\"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\winevt\\\\\\\\Logs\\\\\\\\Microsoft-Windows-Sysmon%4Operational.evtx\\",\\"data\\":{\\"Event\\":{\\"EventData\\":{\\"CreationUtcTime\\":\\"2023-11-01 06:52:11.733\\",\\"Image\\":\\"C:\\\\\\\\Program Files\\\\\\\\socfortress\\\\\\\\sysinternals\\\\\\\\logonsessions64.exe\\",\\"ProcessGuid\\":\\"6D0AAEFA-7972-6547-E6B9-000000004200\\",\\"ProcessId\\":6712,\\"RuleName\\":\\"-\\",\\"TargetFilename\\":\\"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\drivers\\\\\\\\PROCEXP152.SYS\\",\\"User\\":\\"NT AUTHORITY\\\\\\\\SYSTEM\\",\\"UtcTime\\":\\"2023-11-05 11:16:02.307\\"},\\"System\\":{\\"Channel\\":\\"Microsoft-Windows-Sysmon/Operational\\",\\"Computer\\":\\"ANSYDWDC01.ANMS.LOCAL\\",\\"Correlation\\":null,\\"EventID\\":11,\\"EventRecordID\\":18140573,\\"Execution_attributes\\":{\\"ProcessID\\":2564,\\"ThreadID\\":3804},\\"Keywords\\":\\"0x8000000000000000\\",\\"Level\\":4,\\"Opcode\\":0,\\"Provider_attributes\\":{\\"Guid\\":\\"5770385F-C22A-43E0-BF4C-06F5698FFBD9\\",\\"Name\\":\\"Microsoft-Windows-Sysmon\\"},\\"Security_attributes\\":{\\"UserID\\":\\"S-1-5-18\\"},\\"Task\\":11,\\"TimeCreated_attributes\\":{\\"SystemTime\\":\\"2023-11-05T11:16:02.321071Z\\"},\\"Version\\":2}},\\"Event_attributes\\":{\\"xmlns\\":\\"http://schemas.microsoft.com/win/2004/08/events/event\\"}}}","event":{"CreationUtcTime":"2023-11-01 06:52:11.733","Image":"C:\\\\Program Files\\\\socfortress\\\\sysinternals\\\\logonsessions64.exe","ProcessGuid":"6D0AAEFA-7972-6547-E6B9-000000004200","ProcessId":"6712","RuleName":"-","TargetFilename":"C:\\\\Windows\\\\System32\\\\drivers\\\\PROCEXP152.SYS","User":"NT AUTHORITY\\\\SYSTEM","UtcTime":"2023-11-05 11:16:02.307"},"path":"C:\\\\Windows\\\\System32\\\\winevt\\\\Logs\\\\Microsoft-Windows-Sysmon%4Operational.evtx","system":{"Channel":"Microsoft-Windows-Sysmon/Operational","Computer":"ANSYDWDC01.ANMS.LOCAL","Correlation":"null","EventID":"11","EventRecordID":"18140573","Execution_attributes":{"ProcessID":"2564","ThreadID":"3804"},"Keywords":"0x8000000000000000","Level":"4","Opcode":"0","Provider_attributes":{"Guid":"5770385F-C22A-43E0-BF4C-06F5698FFBD9","Name":"Microsoft-Windows-Sysmon"},"Security_attributes":{"UserID":"S-1-5-18"},"Task":"11","TimeCreated_attributes":{"SystemTime":"2023-11-05T11:16:02.321071Z"},"Version":"2"},"name":"Process Explorer Driver Creation By Non-Sysinternals Binary","timestamp":"2023-11-05T11:16:02.321071+00:00","authors":["Florian Roth (Nextron Systems)"],"level":"high","source":"sigma","falsepositives":["Some false positives may occur with legitimate renamed process explorer binaries"],"logsource":{"category":"file_event","product":"windows"},"references":["https://learn.microsoft.com/en-us/sysinternals/downloads/process-explorer","https://github.com/Yaxser/Backstab","https://www.elastic.co/security-labs/stopping-vulnerable-driver-attacks","https://news.sophos.com/en-us/2023/04/19/aukill-edr-killer-malware-abuses-process-explorer-driver/"],"tags":["attack.persistence","attack.privilege_escalation","attack.t1068"]},"location":"active-response\\\\active-responses.log"}',
796 data_system_EventID: "11",
797 data_system_Provider_attributes_Guid: "5770385F-C22A-43E0-BF4C-06F5698FFBD9",
798 rule_id: "200051",
799 manager_name: "ASHWZHMA",
800 data_event_TargetFilename: "C:\\Windows\\System32\\drivers\\PROCEXP152.SYS",
801 location: "active-response\\active-responses.log",
802 data_authors: "Florian Roth (Nextron Systems)",
803 rule_group3: AlertSourceDataLogsourceProduct.Sigma,
804 msg_timestamp: "2023-11-05T11:16:54.542Z",
805 rule_group2: "chainsaw",
806 rule_group1: "windows"
807 },
808 sort: [1699182962307]
809 },
810 {
811 _index: "wazuh_00002_201",
812 _id: "cf49be20-7bce-11ee-93bc-86000046278a",
813 _score: null,
814 _source: {
815 data_system_Task: "11",
816 source_reserved_ip: true,
817 agent_id: "097",
818 agent_name: "ANSYDWDC01",
819 data_system_Correlation: "null",
820 gl2_remote_ip: "10.255.255.13",
821 gl2_remote_port: 49198,
822 agent_labels_customer: "00002",
823 data_system_Version: "2",
824 agent_ip_city_name: "Singapore",
825 source: "10.255.255.13",
826 gl2_source_input: "6459151dea00fd5d3da2df91",
827 rule_level: 12,
828 data_level: AlertSourceDataLevelEnum.High,
829 timestamp_utc: "2023-11-05T11:16:02.307Z",
830 data_event_ProcessId: "6712",
831 syslog_type: AlertSourceSyslogType.Wazuh,
832 data_system_Opcode: "0",
833 rule_description: "Process Explorer Driver Creation By Non-Sysinternals Binary",
834 gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38",
835 id: "1699183862.653635812",
836 data_status: AlertSourceDataStatus.Experimental,
837 data_system_Computer: "ANSYDWDC01.ANMS.LOCAL",
838 gl2_accounted_message_size: 10712,
839 data_document:
840 '{"kind":"evtx","path":"C:\\\\Windows\\\\System32\\\\winevt\\\\Logs\\\\Microsoft-Windows-Sysmon%4Operational.evtx","data":{"Event":{"EventData":{"CreationUtcTime":"2023-11-01 06:52:11.733","Image":"C:\\\\Program Files\\\\socfortress\\\\sysinternals\\\\logonsessions64.exe","ProcessGuid":"6D0AAEFA-7972-6547-E6B9-000000004200","ProcessId":6712,"RuleName":"-","TargetFilename":"C:\\\\Windows\\\\System32\\\\drivers\\\\PROCEXP152.SYS","User":"NT AUTHORITY\\\\SYSTEM","UtcTime":"2023-11-05 11:16:02.307"},"System":{"Channel":"Microsoft-Windows-Sysmon/Operational","Computer":"ANSYDWDC01.ANMS.LOCAL","Correlation":null,"EventID":11,"EventRecordID":18140573,"Execution_attributes":{"ProcessID":2564,"ThreadID":3804},"Keywords":"0x8000000000000000","Level":4,"Opcode":0,"Provider_attributes":{"Guid":"5770385F-C22A-43E0-BF4C-06F5698FFBD9","Name":"Microsoft-Windows-Sysmon"},"Security_attributes":{"UserID":"S-1-5-18"},"Task":11,"TimeCreated_attributes":{"SystemTime":"2023-11-05T11:16:02.321071Z"},"Version":2}},"Event_attributes":{"xmlns":"http://schemas.microsoft.com/win/2004/08/events/event"}}}',
841 data_event_UtcTime: "2023-11-05 11:16:02.307",
842 streams: ["645a3a6123e5cc30bbc0e5dc"],
843 gl2_message_id: "01HEFM0CR3M66JCE9GK8X0BSHV",
844 data_source: AlertSourceDataLogsourceProduct.Sigma,
845 agent_ip: "139.180.134.102",
846 data_system_Security_attributes_UserID: "S-1-5-18",
847 true: 1699183863.254522,
848 data_timestamp: "2023-11-05T11:16:02.321071+00:00",
849 data_system_Level: "4",
850 data_event_CreationUtcTime: "2023-11-01 06:52:11.733",
851 data_system_Execution_attributes_ProcessID: "2564",
852 rule_groups: "windows, chainsaw, sigma",
853 data_system_EventRecordID: "18140573",
854 process_id: "6712",
855 data_system_TimeCreated_attributes_SystemTime: "2023-11-05T11:16:02.321071Z",
856 data_event_RuleName: "-",
857 data_logsource_category: AlertSourceDataLogsourceCategory.FileEvent,
858 data_system_Keywords: "0x8000000000000000",
859 sigma_name_encoded: "Process%20Explorer%20Driver%20Creation%20By%20Non-Sysinternals%20Binary",
860 agent_ip_geolocation: "1.3078,103.6818",
861 data_group: AlertSourceDataGroup.Sigma,
862 rule_firedtimes: 2,
863 data_event_User: "NT AUTHORITY\\SYSTEM",
864 data_path: "C:\\Windows\\System32\\winevt\\Logs\\Microsoft-Windows-Sysmon%4Operational.evtx",
865 rule_mail: true,
866 data_system_Provider_attributes_Name: "Microsoft-Windows-Sysmon",
867 data_name: "Process Explorer Driver Creation By Non-Sysinternals Binary",
868 decoder_name: AlertSourceDecoderName.JSON,
869 data_id: "de46c52b-0bf8-4936-a327-aace94f94ac6",
870 agent_ip_country_code: "SG",
871 syslog_level: AlertSourceSyslogLevel.Alert,
872 data_tags: "attack.persistence, attack.privilege_escalation, attack.t1068",
873 data_kind: AlertSourceDataKind.Individual,
874 data_logsource_product: AlertSourceDataLogsourceProduct.Windows,
875 timestamp: "2023-11-05 11:31:06.627",
876 ask_socfortress_message:
877 "The SIGMA alert \"Process Explorer Driver Creation By Non-Sysinternals Binary\" suggests that a non-Sysinternals binary has attempted to create a Process Explorer driver on a Windows endpoint. Process Explorer is a widely used system monitoring tool developed by Sysinternals (now part of Microsoft). The creation of a Process Explorer driver by a non-Sysinternals binary could indicate suspicious or potentially malicious activity.\n\nTo investigate this alert and determine an appropriate response, you should focus on the following key aspects:\n\n1. Validate the Alert: Verify the accuracy of the alert by checking if it was triggered by legitimate activity or if it is a false positive. Ensure that your detection system is properly configured and up to date.\n\n2. Identify the Binary: Determine which specific binary attempted to create the Process Explorer driver. Look for any unusual or suspicious characteristics such as unfamiliar names, file paths, digital signatures, or hash values.\n\n3. Analyze Process Execution Context: Investigate the context in which the binary executed and attempted to create the driver. Review process execution details, such as parent processes, command-line arguments, process creation time, and associated network connections.\n\n4. Assess System Impact: Evaluate whether any abnormal behavior occurred on the endpoint after this event took place. Look for signs of system instability, crashes, performance degradation, or other anomalous activities that may indicate malicious intent.\n\n5. Conduct File Analysis: Perform an in-depth analysis of the binary itself using appropriate tools like antivirus scanners and sandboxing environments to identify any malware indicators such as malicious code patterns or known signatures associated with malware families.\n\n6. Check Reputation: Research information about the binary's reputation online using threat intelligence platforms, virus total scanners, or security forums to determine if it has been previously identified as malicious.\n\n7. Perform Behavioral Analysis: If feasible, conduct dynamic analysis by executing the binary in an isolated environment while monitoring its behavior for any suspicious activities like network communication, file system changes, or attempts to escalate privileges.\n\n8. Review System Logs: Examine relevant logs such as event logs, process creation logs, driver loading logs, and network logs to identify any additional indicators of compromise or related activities.\n\nWhen assessing this alert, you should also ask yourself the following additional questions:\n\n1. Is the binary a legitimate tool that is commonly used in your organization? If not, why would it be present on the endpoint?\n\n2. Is there a business justification for creating a Process Explorer driver with this specific binary? Are there any documented cases or known legitimate reasons for doing so?\n\n3. Are there any other security events or alerts related to this binary or associated processes that can provide further context?\n\n4. Has the binary been whitelisted or approved by your organization's security policies? If not, why was it allowed to execute on the endpoint?\n\n5. Do you have sufficient visibility into other endpoints within your environment? Have similar events been observed elsewhere? This could indicate a larger-scale attack.\n\nRemember that each investigation may vary based on your organization's specific context and requirements.",
878 data_system_Channel: "Microsoft-Windows-Sysmon/Operational",
879 data_references:
880 "https://learn.microsoft.com/en-us/sysinternals/downloads/process-explorer, https://github.com/Yaxser/Backstab, https://www.elastic.co/security-labs/stopping-vulnerable-driver-attacks, https://news.sophos.com/en-us/2023/04/19/aukill-edr-killer-malware-abuses-process-explorer-driver/",
881 data_event_ProcessGuid: "6D0AAEFA-7972-6547-E6B9-000000004200",
882 gl2_processing_error:
883 'Replaced invalid timestamp value in message <cf49be20-7bce-11ee-93bc-86000046278a> with current time - Value <2023-11-05T11:31:02.897+0000> caused exception: Invalid format: "2023-11-05T11:31:02.897+0000" is malformed at "T11:31:02.897+0000".',
884 data_falsepositives:
885 "Some false positives may occur with legitimate renamed process explorer binaries",
886 data_event_Image: "C:\\Program Files\\socfortress\\sysinternals\\logonsessions64.exe",
887 data_system_Execution_attributes_ThreadID: "3804",
888 message:
889 '{"true":1699183863.254522,"timestamp":"2023-11-05T11:31:02.897+0000","rule":{"level":12,"description":"Process Explorer Driver Creation By Non-Sysinternals Binary","id":"200051","firedtimes":2,"mail":true,"groups":["windows","chainsaw","sigma"]},"agent":{"id":"097","name":"ANSYDWDC01","ip":"139.180.134.102","labels":{"customer":"00002"}},"manager":{"name":"ASHWZHMA"},"id":"1699183862.653635812","decoder":{"name":"json"},"data":{"id":"de46c52b-0bf8-4936-a327-aace94f94ac6","status":"experimental","group":"Sigma","kind":"individual","document":"{\\"kind\\":\\"evtx\\",\\"path\\":\\"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\winevt\\\\\\\\Logs\\\\\\\\Microsoft-Windows-Sysmon%4Operational.evtx\\",\\"data\\":{\\"Event\\":{\\"EventData\\":{\\"CreationUtcTime\\":\\"2023-11-01 06:52:11.733\\",\\"Image\\":\\"C:\\\\\\\\Program Files\\\\\\\\socfortress\\\\\\\\sysinternals\\\\\\\\logonsessions64.exe\\",\\"ProcessGuid\\":\\"6D0AAEFA-7972-6547-E6B9-000000004200\\",\\"ProcessId\\":6712,\\"RuleName\\":\\"-\\",\\"TargetFilename\\":\\"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\drivers\\\\\\\\PROCEXP152.SYS\\",\\"User\\":\\"NT AUTHORITY\\\\\\\\SYSTEM\\",\\"UtcTime\\":\\"2023-11-05 11:16:02.307\\"},\\"System\\":{\\"Channel\\":\\"Microsoft-Windows-Sysmon/Operational\\",\\"Computer\\":\\"ANSYDWDC01.ANMS.LOCAL\\",\\"Correlation\\":null,\\"EventID\\":11,\\"EventRecordID\\":18140573,\\"Execution_attributes\\":{\\"ProcessID\\":2564,\\"ThreadID\\":3804},\\"Keywords\\":\\"0x8000000000000000\\",\\"Level\\":4,\\"Opcode\\":0,\\"Provider_attributes\\":{\\"Guid\\":\\"5770385F-C22A-43E0-BF4C-06F5698FFBD9\\",\\"Name\\":\\"Microsoft-Windows-Sysmon\\"},\\"Security_attributes\\":{\\"UserID\\":\\"S-1-5-18\\"},\\"Task\\":11,\\"TimeCreated_attributes\\":{\\"SystemTime\\":\\"2023-11-05T11:16:02.321071Z\\"},\\"Version\\":2}},\\"Event_attributes\\":{\\"xmlns\\":\\"http://schemas.microsoft.com/win/2004/08/events/event\\"}}}","event":{"CreationUtcTime":"2023-11-01 06:52:11.733","Image":"C:\\\\Program Files\\\\socfortress\\\\sysinternals\\\\logonsessions64.exe","ProcessGuid":"6D0AAEFA-7972-6547-E6B9-000000004200","ProcessId":"6712","RuleName":"-","TargetFilename":"C:\\\\Windows\\\\System32\\\\drivers\\\\PROCEXP152.SYS","User":"NT AUTHORITY\\\\SYSTEM","UtcTime":"2023-11-05 11:16:02.307"},"path":"C:\\\\Windows\\\\System32\\\\winevt\\\\Logs\\\\Microsoft-Windows-Sysmon%4Operational.evtx","system":{"Channel":"Microsoft-Windows-Sysmon/Operational","Computer":"ANSYDWDC01.ANMS.LOCAL","Correlation":"null","EventID":"11","EventRecordID":"18140573","Execution_attributes":{"ProcessID":"2564","ThreadID":"3804"},"Keywords":"0x8000000000000000","Level":"4","Opcode":"0","Provider_attributes":{"Guid":"5770385F-C22A-43E0-BF4C-06F5698FFBD9","Name":"Microsoft-Windows-Sysmon"},"Security_attributes":{"UserID":"S-1-5-18"},"Task":"11","TimeCreated_attributes":{"SystemTime":"2023-11-05T11:16:02.321071Z"},"Version":"2"},"name":"Process Explorer Driver Creation By Non-Sysinternals Binary","timestamp":"2023-11-05T11:16:02.321071+00:00","authors":["Florian Roth (Nextron Systems)"],"level":"high","source":"sigma","falsepositives":["Some false positives may occur with legitimate renamed process explorer binaries"],"logsource":{"category":"file_event","product":"windows"},"references":["https://learn.microsoft.com/en-us/sysinternals/downloads/process-explorer","https://github.com/Yaxser/Backstab","https://www.elastic.co/security-labs/stopping-vulnerable-driver-attacks","https://news.sophos.com/en-us/2023/04/19/aukill-edr-killer-malware-abuses-process-explorer-driver/"],"tags":["attack.persistence","attack.privilege_escalation","attack.t1068"]},"location":"active-response\\\\active-responses.log"}',
890 data_system_EventID: "11",
891 data_system_Provider_attributes_Guid: "5770385F-C22A-43E0-BF4C-06F5698FFBD9",
892 rule_id: "200051",
893 manager_name: "ASHWZHMA",
894 data_event_TargetFilename: "C:\\Windows\\System32\\drivers\\PROCEXP152.SYS",
895 location: "active-response\\active-responses.log",
896 data_authors: "Florian Roth (Nextron Systems)",
897 rule_group3: AlertSourceDataLogsourceProduct.Sigma,
898 msg_timestamp: "2023-11-05T11:31:02.897Z",
899 rule_group2: "chainsaw",
900 rule_group1: "windows"
901 },
902 sort: [1699182962307]
903 },
904 {
905 _index: "wazuh_00002_201",
906 _id: "75dcb8b2-7bc4-11ee-93bc-86000046278a",
907 _score: null,
908 _source: {
909 data_system_Task: "11",
910 source_reserved_ip: true,
911 agent_id: "097",
912 agent_name: "ANSYDWDC01",
913 data_system_Correlation: "null",
914 gl2_remote_ip: "10.255.255.13",
915 gl2_remote_port: 59674,
916 agent_labels_customer: "00002",
917 data_system_Version: "2",
918 agent_ip_city_name: "Singapore",
919 source: "10.255.255.13",
920 gl2_source_input: "6459151dea00fd5d3da2df91",
921 rule_level: 12,
922 data_level: AlertSourceDataLevelEnum.High,
923 timestamp_utc: "2023-11-05T10:16:05.625Z",
924 data_event_ProcessId: "5020",
925 syslog_type: AlertSourceSyslogType.Wazuh,
926 data_system_Opcode: "0",
927 rule_description: "Process Explorer Driver Creation By Non-Sysinternals Binary",
928 gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38",
929 id: "1699179418.594692359",
930 data_status: AlertSourceDataStatus.Experimental,
931 data_system_Computer: "ANSYDWDC01.ANMS.LOCAL",
932 gl2_accounted_message_size: 11648,
933 data_document:
934 '{"kind":"evtx","path":"C:\\\\Windows\\\\System32\\\\winevt\\\\Logs\\\\Microsoft-Windows-Sysmon%4Operational.evtx","data":{"Event":{"EventData":{"CreationUtcTime":"2023-11-01 06:52:11.733","Image":"C:\\\\Program Files\\\\socfortress\\\\sysinternals\\\\logonsessions64.exe","ProcessGuid":"6D0AAEFA-6B64-6547-61B8-000000004200","ProcessId":5020,"RuleName":"-","TargetFilename":"C:\\\\Windows\\\\System32\\\\drivers\\\\PROCEXP152.SYS","User":"NT AUTHORITY\\\\SYSTEM","UtcTime":"2023-11-05 10:16:05.625"},"System":{"Channel":"Microsoft-Windows-Sysmon/Operational","Computer":"ANSYDWDC01.ANMS.LOCAL","Correlation":null,"EventID":11,"EventRecordID":18140150,"Execution_attributes":{"ProcessID":2564,"ThreadID":3804},"Keywords":"0x8000000000000000","Level":4,"Opcode":0,"Provider_attributes":{"Guid":"5770385F-C22A-43E0-BF4C-06F5698FFBD9","Name":"Microsoft-Windows-Sysmon"},"Security_attributes":{"UserID":"S-1-5-18"},"Task":11,"TimeCreated_attributes":{"SystemTime":"2023-11-05T10:16:05.635338Z"},"Version":2}},"Event_attributes":{"xmlns":"http://schemas.microsoft.com/win/2004/08/events/event"}}}',
935 data_event_UtcTime: "2023-11-05 10:16:05.625",
936 streams: ["645a3a6123e5cc30bbc0e5dc"],
937 gl2_message_id: "01HEFFRR246C2SFHZZNDKNXRYP",
938 data_source: AlertSourceDataLogsourceProduct.Sigma,
939 agent_ip: "139.180.134.102",
940 data_system_Security_attributes_UserID: "S-1-5-18",
941 true: 1699179418.395436,
942 data_timestamp: "2023-11-05T10:16:05.635338+00:00",
943 data_system_Level: "4",
944 data_event_CreationUtcTime: "2023-11-01 06:52:11.733",
945 data_system_Execution_attributes_ProcessID: "2564",
946 rule_groups: "windows, chainsaw, sigma",
947 data_system_EventRecordID: "18140150",
948 process_id: "5020",
949 data_system_TimeCreated_attributes_SystemTime: "2023-11-05T10:16:05.635338Z",
950 data_event_RuleName: "-",
951 data_logsource_category: AlertSourceDataLogsourceCategory.FileEvent,
952 data_system_Keywords: "0x8000000000000000",
953 sigma_name_encoded: "Process%20Explorer%20Driver%20Creation%20By%20Non-Sysinternals%20Binary",
954 agent_ip_geolocation: "1.3078,103.6818",
955 data_group: AlertSourceDataGroup.Sigma,
956 rule_firedtimes: 1,
957 data_event_User: "NT AUTHORITY\\SYSTEM",
958 data_path: "C:\\Windows\\System32\\winevt\\Logs\\Microsoft-Windows-Sysmon%4Operational.evtx",
959 rule_mail: true,
960 data_system_Provider_attributes_Name: "Microsoft-Windows-Sysmon",
961 data_name: "Process Explorer Driver Creation By Non-Sysinternals Binary",
962 decoder_name: AlertSourceDecoderName.JSON,
963 data_id: "de46c52b-0bf8-4936-a327-aace94f94ac6",
964 agent_ip_country_code: "SG",
965 syslog_level: AlertSourceSyslogLevel.Alert,
966 data_tags: "attack.persistence, attack.privilege_escalation, attack.t1068",
967 data_kind: AlertSourceDataKind.Individual,
968 data_logsource_product: AlertSourceDataLogsourceProduct.Windows,
969 timestamp: "2023-11-05 10:17:01.764",
970 ask_socfortress_message:
971 "The SIGMA alert \"Process Explorer Driver Creation By Non-Sysinternals Binary\" indicates that a Windows endpoint has detected an instance where a process explorer driver was created by a binary that is not associated with Microsoft Sysinternals, a legitimate software tool widely used for system monitoring and troubleshooting.\n\nThis alert suggests the possibility of malicious activity on the endpoint. Attackers often leverage process explorer drivers or similar techniques to gain unauthorized access, elevate privileges, or hide their presence on a system. As such, it is important to thoroughly investigate this alert to determine the appropriate response.\n\nHere are key aspects you should investigate when responding to this alert:\n\n1. Endpoint Details: Gather information about the affected endpoint such as its hostname, IP address, operating system version, and any other relevant details. This information will help in understanding the context and potential impact of the alert.\n\n2. Timestamp and Correlation: Identify when the event occurred and check for any correlation with other security events or alerts on the same endpoint or across your environment. This can help determine if it's an isolated incident or part of a broader attack pattern.\n\n3. Process Explorer Driver: Determine which specific driver was created and by which binary it was created. Identify its location on disk and inspect its file properties (e.g., name, size, creation date). Compare these details against known legitimate drivers associated with Microsoft Sysinternals tools.\n\n4. Binary Analysis: Conduct further analysis of the non-Sysinternals binary responsible for creating the process explorer driver. Scan it using antivirus/anti-malware tools to identify any potential malicious behavior or indicators of compromise (IOCs). Consider submitting samples to threat intelligence platforms for additional analysis.\n\n5. Process Information: Examine details about the process associated with creating this driver (e.g., process ID (PID), parent PID) to understand how it was initiated and by what means.\n\n6. System Logs: Review relevant logs such as event logs, system logs, and security logs to identify any suspicious activities or additional indicators of compromise. Look for any abnormal system behavior or unauthorized modifications.\n\n7. User Context: Determine the user account associated with the process that initiated the driver creation. Check if it is a privileged account or a standard user account. If it is a privileged account, investigate whether this activity was expected and authorized.\n\n8. Network Activity: Analyze network traffic logs to identify any communication originating from the affected endpoint during or after the event. Look for connections to suspicious IP addresses, domains, or known command-and-control servers.\n\n9. Endpoint Security Posture: Evaluate the security controls deployed on the affected endpoint, such as antivirus/anti-malware software, intrusion prevention systems (IPS), host-based firewalls, and endpoint detection and response (EDR) solutions. Determine if these controls detected or blocked any malicious activity related to this alert.\n\n10. Incident Response Plan: Assess your organization's incident response plan and determine if there are predefined steps for responding to similar alerts like this one. Follow established procedures to contain the incident, mitigate risks, remediate affected systems, and prevent future occurrences.\n\nAdditional questions you should ask yourself when assessing this alert:\n\n1. Is there any legitimate reason for a non-Sysinternals binary to create a process explorer driver on this endpoint?\n2. Have there been any recent changes in software deployment or system configuration that could explain this alert?\n3. Are there other endpoints in your environment running similar binaries that could trigger similar alerts?\n4. Are there any recent reports of malware campaigns targeting process explorer drivers or abusing legitimate tools like Sysinternals?\n5. Are there any indicators suggesting compromise on this endpoint beyond just the creation of the driver?\n\nBy thoroughly investigating these aspects and considering additional relevant questions specific to your environment, you can make an informed decision about how best to respond to this SIGMA alert and mitigate potential risks.",
972 data_system_Channel: "Microsoft-Windows-Sysmon/Operational",
973 data_references:
974 "https://learn.microsoft.com/en-us/sysinternals/downloads/process-explorer, https://github.com/Yaxser/Backstab, https://www.elastic.co/security-labs/stopping-vulnerable-driver-attacks, https://news.sophos.com/en-us/2023/04/19/aukill-edr-killer-malware-abuses-process-explorer-driver/",
975 data_event_ProcessGuid: "6D0AAEFA-6B64-6547-61B8-000000004200",
976 gl2_processing_error:
977 'Replaced invalid timestamp value in message <75dcb8b2-7bc4-11ee-93bc-86000046278a> with current time - Value <2023-11-05T10:16:58.328+0000> caused exception: Invalid format: "2023-11-05T10:16:58.328+0000" is malformed at "T10:16:58.328+0000".',
978 data_falsepositives:
979 "Some false positives may occur with legitimate renamed process explorer binaries",
980 data_event_Image: "C:\\Program Files\\socfortress\\sysinternals\\logonsessions64.exe",
981 data_system_Execution_attributes_ThreadID: "3804",
982 message:
983 '{"true":1699179418.395436,"timestamp":"2023-11-05T10:16:58.328+0000","rule":{"level":12,"description":"Process Explorer Driver Creation By Non-Sysinternals Binary","id":"200051","firedtimes":1,"mail":true,"groups":["windows","chainsaw","sigma"]},"agent":{"id":"097","name":"ANSYDWDC01","ip":"139.180.134.102","labels":{"customer":"00002"}},"manager":{"name":"ASHWZHMA"},"id":"1699179418.594692359","decoder":{"name":"json"},"data":{"id":"de46c52b-0bf8-4936-a327-aace94f94ac6","status":"experimental","group":"Sigma","kind":"individual","document":"{\\"kind\\":\\"evtx\\",\\"path\\":\\"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\winevt\\\\\\\\Logs\\\\\\\\Microsoft-Windows-Sysmon%4Operational.evtx\\",\\"data\\":{\\"Event\\":{\\"EventData\\":{\\"CreationUtcTime\\":\\"2023-11-01 06:52:11.733\\",\\"Image\\":\\"C:\\\\\\\\Program Files\\\\\\\\socfortress\\\\\\\\sysinternals\\\\\\\\logonsessions64.exe\\",\\"ProcessGuid\\":\\"6D0AAEFA-6B64-6547-61B8-000000004200\\",\\"ProcessId\\":5020,\\"RuleName\\":\\"-\\",\\"TargetFilename\\":\\"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\drivers\\\\\\\\PROCEXP152.SYS\\",\\"User\\":\\"NT AUTHORITY\\\\\\\\SYSTEM\\",\\"UtcTime\\":\\"2023-11-05 10:16:05.625\\"},\\"System\\":{\\"Channel\\":\\"Microsoft-Windows-Sysmon/Operational\\",\\"Computer\\":\\"ANSYDWDC01.ANMS.LOCAL\\",\\"Correlation\\":null,\\"EventID\\":11,\\"EventRecordID\\":18140150,\\"Execution_attributes\\":{\\"ProcessID\\":2564,\\"ThreadID\\":3804},\\"Keywords\\":\\"0x8000000000000000\\",\\"Level\\":4,\\"Opcode\\":0,\\"Provider_attributes\\":{\\"Guid\\":\\"5770385F-C22A-43E0-BF4C-06F5698FFBD9\\",\\"Name\\":\\"Microsoft-Windows-Sysmon\\"},\\"Security_attributes\\":{\\"UserID\\":\\"S-1-5-18\\"},\\"Task\\":11,\\"TimeCreated_attributes\\":{\\"SystemTime\\":\\"2023-11-05T10:16:05.635338Z\\"},\\"Version\\":2}},\\"Event_attributes\\":{\\"xmlns\\":\\"http://schemas.microsoft.com/win/2004/08/events/event\\"}}}","event":{"CreationUtcTime":"2023-11-01 06:52:11.733","Image":"C:\\\\Program Files\\\\socfortress\\\\sysinternals\\\\logonsessions64.exe","ProcessGuid":"6D0AAEFA-6B64-6547-61B8-000000004200","ProcessId":"5020","RuleName":"-","TargetFilename":"C:\\\\Windows\\\\System32\\\\drivers\\\\PROCEXP152.SYS","User":"NT AUTHORITY\\\\SYSTEM","UtcTime":"2023-11-05 10:16:05.625"},"path":"C:\\\\Windows\\\\System32\\\\winevt\\\\Logs\\\\Microsoft-Windows-Sysmon%4Operational.evtx","system":{"Channel":"Microsoft-Windows-Sysmon/Operational","Computer":"ANSYDWDC01.ANMS.LOCAL","Correlation":"null","EventID":"11","EventRecordID":"18140150","Execution_attributes":{"ProcessID":"2564","ThreadID":"3804"},"Keywords":"0x8000000000000000","Level":"4","Opcode":"0","Provider_attributes":{"Guid":"5770385F-C22A-43E0-BF4C-06F5698FFBD9","Name":"Microsoft-Windows-Sysmon"},"Security_attributes":{"UserID":"S-1-5-18"},"Task":"11","TimeCreated_attributes":{"SystemTime":"2023-11-05T10:16:05.635338Z"},"Version":"2"},"name":"Process Explorer Driver Creation By Non-Sysinternals Binary","timestamp":"2023-11-05T10:16:05.635338+00:00","authors":["Florian Roth (Nextron Systems)"],"level":"high","source":"sigma","falsepositives":["Some false positives may occur with legitimate renamed process explorer binaries"],"logsource":{"category":"file_event","product":"windows"},"references":["https://learn.microsoft.com/en-us/sysinternals/downloads/process-explorer","https://github.com/Yaxser/Backstab","https://www.elastic.co/security-labs/stopping-vulnerable-driver-attacks","https://news.sophos.com/en-us/2023/04/19/aukill-edr-killer-malware-abuses-process-explorer-driver/"],"tags":["attack.persistence","attack.privilege_escalation","attack.t1068"]},"location":"active-response\\\\active-responses.log"}',
984 data_system_EventID: "11",
985 data_system_Provider_attributes_Guid: "5770385F-C22A-43E0-BF4C-06F5698FFBD9",
986 rule_id: "200051",
987 manager_name: "ASHWZHMA",
988 data_event_TargetFilename: "C:\\Windows\\System32\\drivers\\PROCEXP152.SYS",
989 location: "active-response\\active-responses.log",
990 data_authors: "Florian Roth (Nextron Systems)",
991 rule_group3: AlertSourceDataLogsourceProduct.Sigma,
992 msg_timestamp: "2023-11-05T10:16:58.328Z",
993 rule_group2: "chainsaw",
994 rule_group1: "windows"
995 },
996 sort: [1699179365625]
997 }
998 ]
999 },
1000 {
1001 index_name: "wazuh-bkomanh1_1",
1002 total_alerts: 5,
1003 alerts: [
1004 {
1005 _index: "wazuh-bkomanh1_1",
1006 _id: "ae3aac92-7bd7-11ee-93bc-86000046278a",
1007 _score: null,
1008 _source: {
1009 data_win_eventdata_description: "Application Compatibility Database Installer",
1010 source_reserved_ip: true,
1011 data_win_system_eventRecordID: "834890",
1012 data_win_eventdata_user: "NT AUTHORITY\\\\SYSTEM",
1013 agent_id: "068",
1014 agent_name: "WinDev2308Eval",
1015 sha256: "5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77",
1016 gl2_remote_ip: "10.255.255.13",
1017 data_win_system_eventID: "1",
1018 gl2_remote_port: 36714,
1019 agent_labels_customer: "bkomanh1",
1020 source: "10.255.255.13",
1021 gl2_source_input: "6459151dea00fd5d3da2df91",
1022 rule_level: 12,
1023 data_win_eventdata_originalFileName: "sdbinst.exe",
1024 data_win_eventdata_company: "Microsoft Corporation",
1025 data_win_system_task: "1",
1026 timestamp_utc: "2023-11-05T12:34:39.363Z",
1027 syslog_type: AlertSourceSyslogType.Wazuh,
1028 data_win_system_threadID: "4928",
1029 rule_description: "Application Compatibility Database launched",
1030 data_win_eventdata_parentUser: "NT AUTHORITY\\\\SYSTEM",
1031 gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38",
1032 id: "1699187674.709551442",
1033 rule_mitre_tactic: "Privilege Escalation, Persistence",
1034 gl2_accounted_message_size: 7629,
1035 data_win_eventdata_integrityLevel: AlertSourceDataWinEventdataIntegrityLevel.System,
1036 data_win_eventdata_utcTime: "2023-11-05 12:34:39.359",
1037 streams: ["650b315d5e9a2d550c6687ae"],
1038 rule_mitre_id: "T1546.011",
1039 gl2_message_id: "01HEFQMNETVW5WV1DMEJR3V2FD",
1040 data_win_system_computer: "WinDev2308Eval",
1041 data_win_eventdata_currentDirectory: "C:\\\\Windows\\\\system32\\\\",
1042 agent_ip_reserved_ip: true,
1043 data_win_eventdata_ruleName: "technique_id=T1546.011,technique_name=Application Shimming",
1044 data_win_eventdata_hashes:
1045 "SHA1=C0C9554DCEBF89ABC7DA5332037BC2C88A3B0F1E,MD5=72A442005F409F233C223E60A7A0D868,SHA256=5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77,IMPHASH=999B9DCD61DAB941B1E8D50FE6EF72CD",
1046 agent_ip: "172.26.161.217",
1047 data_win_eventdata_image: "C:\\\\Windows\\\\System32\\\\sdbinst.exe",
1048 data_win_eventdata_parentProcessGuid: "{10906cbf-9e07-6528-8600-000000000e00}",
1049 true: 1699187674.749328,
1050 data_win_eventdata_parentProcessId: "5952",
1051 rule_groups: "sysmon, sysmon_eid1_detections, windows",
1052 data_win_system_keywords: "0x8000000000000000",
1053 data_win_system_level: "4",
1054 data_win_eventdata_fileVersion: "10.0.22621.2361 (WinBuild.160101.0800)",
1055 data_win_eventdata_parentImage: "C:\\\\Windows\\\\System32\\\\svchost.exe",
1056 process_id: "7076",
1057 data_win_system_severityValue: AlertSourceDataWinSystemSeverityValue.Information,
1058 data_win_eventdata_processGuid: "{10906cbf-8bdf-6547-fe84-010000000e00}",
1059 rule_mitre_technique: "Application Shimming",
1060 rule_firedtimes: 1,
1061 data_win_system_systemTime: "2023-11-05T12:34:39.3631014Z",
1062 rule_mail: true,
1063 decoder_name: AlertSourceDecoderName.WindowsEventchannel,
1064 data_win_eventdata_commandLine: "C:\\\\Windows\\\\System32\\\\sdbinst.exe -m -bg",
1065 data_win_system_processID: "3808",
1066 data_win_system_channel: "Microsoft-Windows-Sysmon/Operational",
1067 syslog_level: AlertSourceSyslogLevel.Alert,
1068 data_win_system_providerName: "Microsoft-Windows-Sysmon",
1069 data_win_eventdata_processId: "7076",
1070 data_win_system_version: "5",
1071 data_win_system_providerGuid: "{5770385f-c22a-43e0-bf4c-06f5698ffbd9}",
1072 timestamp: "2023-11-05 12:34:36.634",
1073 data_win_eventdata_parentCommandLine:
1074 "C:\\\\Windows\\\\system32\\\\svchost.exe -k LocalSystemNetworkRestricted -p -s PcaSvc",
1075 data_win_system_opcode: "0",
1076 gl2_processing_error:
1077 'Replaced invalid timestamp value in message <ae3aac92-7bd7-11ee-93bc-86000046278a> with current time - Value <2023-11-05T12:34:34.734+0000> caused exception: Invalid format: "2023-11-05T12:34:34.734+0000" is malformed at "T12:34:34.734+0000".',
1078 data_win_eventdata_terminalSessionId: "0",
1079 message:
1080 '{"true":1699187674.749328,"timestamp":"2023-11-05T12:34:34.734+0000","rule":{"level":12,"description":"Application Compatibility Database launched","id":"92058","mitre":{"id":["T1546.011"],"tactic":["Privilege Escalation","Persistence"],"technique":["Application Shimming"]},"firedtimes":1,"mail":true,"groups":["sysmon","sysmon_eid1_detections","windows"]},"agent":{"id":"068","name":"WinDev2308Eval","ip":"172.26.161.217","labels":{"customer":"bkomanh1"}},"manager":{"name":"ASHWZHMA"},"id":"1699187674.709551442","decoder":{"name":"windows_eventchannel"},"data":{"win":{"system":{"providerName":"Microsoft-Windows-Sysmon","providerGuid":"{5770385f-c22a-43e0-bf4c-06f5698ffbd9}","eventID":"1","version":"5","level":"4","task":"1","opcode":"0","keywords":"0x8000000000000000","systemTime":"2023-11-05T12:34:39.3631014Z","eventRecordID":"834890","processID":"3808","threadID":"4928","channel":"Microsoft-Windows-Sysmon/Operational","computer":"WinDev2308Eval","severityValue":"INFORMATION","message":"\\"Process Create:\\r\\nRuleName: technique_id=T1546.011,technique_name=Application Shimming\\r\\nUtcTime: 2023-11-05 12:34:39.359\\r\\nProcessGuid: {10906cbf-8bdf-6547-fe84-010000000e00}\\r\\nProcessId: 7076\\r\\nImage: C:\\\\Windows\\\\System32\\\\sdbinst.exe\\r\\nFileVersion: 10.0.22621.2361 (WinBuild.160101.0800)\\r\\nDescription: Application Compatibility Database Installer\\r\\nProduct: Microsoft® Windows® Operating System\\r\\nCompany: Microsoft Corporation\\r\\nOriginalFileName: sdbinst.exe\\r\\nCommandLine: C:\\\\Windows\\\\System32\\\\sdbinst.exe -m -bg\\r\\nCurrentDirectory: C:\\\\Windows\\\\system32\\\\\\r\\nUser: NT AUTHORITY\\\\SYSTEM\\r\\nLogonGuid: {10906cbf-9df1-6528-e703-000000000000}\\r\\nLogonId: 0x3E7\\r\\nTerminalSessionId: 0\\r\\nIntegrityLevel: System\\r\\nHashes: SHA1=C0C9554DCEBF89ABC7DA5332037BC2C88A3B0F1E,MD5=72A442005F409F233C223E60A7A0D868,SHA256=5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77,IMPHASH=999B9DCD61DAB941B1E8D50FE6EF72CD\\r\\nParentProcessGuid: {10906cbf-9e07-6528-8600-000000000e00}\\r\\nParentProcessId: 5952\\r\\nParentImage: C:\\\\Windows\\\\System32\\\\svchost.exe\\r\\nParentCommandLine: C:\\\\Windows\\\\system32\\\\svchost.exe -k LocalSystemNetworkRestricted -p -s PcaSvc\\r\\nParentUser: NT AUTHORITY\\\\SYSTEM\\""},"eventdata":{"ruleName":"technique_id=T1546.011,technique_name=Application Shimming","utcTime":"2023-11-05 12:34:39.359","processGuid":"{10906cbf-8bdf-6547-fe84-010000000e00}","processId":"7076","image":"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\sdbinst.exe","fileVersion":"10.0.22621.2361 (WinBuild.160101.0800)","description":"Application Compatibility Database Installer","product":"Microsoft® Windows® Operating System","company":"Microsoft Corporation","originalFileName":"sdbinst.exe","commandLine":"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\sdbinst.exe -m -bg","currentDirectory":"C:\\\\\\\\Windows\\\\\\\\system32\\\\\\\\","user":"NT AUTHORITY\\\\\\\\SYSTEM","logonGuid":"{10906cbf-9df1-6528-e703-000000000000}","logonId":"0x3e7","terminalSessionId":"0","integrityLevel":"System","hashes":"SHA1=C0C9554DCEBF89ABC7DA5332037BC2C88A3B0F1E,MD5=72A442005F409F233C223E60A7A0D868,SHA256=5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77,IMPHASH=999B9DCD61DAB941B1E8D50FE6EF72CD","parentProcessGuid":"{10906cbf-9e07-6528-8600-000000000e00}","parentProcessId":"5952","parentImage":"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\svchost.exe","parentCommandLine":"C:\\\\\\\\Windows\\\\\\\\system32\\\\\\\\svchost.exe -k LocalSystemNetworkRestricted -p -s PcaSvc","parentUser":"NT AUTHORITY\\\\\\\\SYSTEM"}}},"location":"EventChannel"}',
1081 rule_id: "92058",
1082 hash_sha256: "SHA256=5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77",
1083 manager_name: "ASHWZHMA",
1084 data_win_eventdata_logonGuid: "{10906cbf-9df1-6528-e703-000000000000}",
1085 data_win_eventdata_logonId: "0x3e7",
1086 location: "EventChannel",
1087 rule_group3: AlertSourceDataLogsourceProduct.Windows,
1088 data_win_system_message:
1089 '"Process Create:\r\nRuleName: technique_id=T1546.011,technique_name=Application Shimming\r\nUtcTime: 2023-11-05 12:34:39.359\r\nProcessGuid: {10906cbf-8bdf-6547-fe84-010000000e00}\r\nProcessId: 7076\r\nImage: C:\\Windows\\System32\\sdbinst.exe\r\nFileVersion: 10.0.22621.2361 (WinBuild.160101.0800)\r\nDescription: Application Compatibility Database Installer\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: sdbinst.exe\r\nCommandLine: C:\\Windows\\System32\\sdbinst.exe -m -bg\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {10906cbf-9df1-6528-e703-000000000000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: SHA1=C0C9554DCEBF89ABC7DA5332037BC2C88A3B0F1E,MD5=72A442005F409F233C223E60A7A0D868,SHA256=5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77,IMPHASH=999B9DCD61DAB941B1E8D50FE6EF72CD\r\nParentProcessGuid: {10906cbf-9e07-6528-8600-000000000e00}\r\nParentProcessId: 5952\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k LocalSystemNetworkRestricted -p -s PcaSvc\r\nParentUser: NT AUTHORITY\\SYSTEM"',
1090 msg_timestamp: "2023-11-05T12:34:34.734Z",
1091 rule_group2: "sysmon_eid1_detections",
1092 data_win_eventdata_product: "Microsoft® Windows® Operating System",
1093 rule_group1: "sysmon"
1094 },
1095 sort: [1699187679363]
1096 },
1097 {
1098 _index: "wazuh-bkomanh1_1",
1099 _id: "6d89de79-7bd0-11ee-93bc-86000046278a",
1100 _score: null,
1101 _source: {
1102 source_reserved_ip: true,
1103 data_win_system_eventRecordID: "10017",
1104 agent_id: "068",
1105 agent_name: "WinDev2308Eval",
1106 gl2_remote_ip: "10.255.255.13",
1107 data_win_system_eventID: "1116",
1108 data_win_eventdata_fWLink:
1109 "https://go.microsoft.com/fwlink/?linkid=37020&amp;name=Trojan:Win32/Wacatac.H!ml&amp;threatid=2147814523&amp;enterprise=0",
1110 gl2_remote_port: 37408,
1111 rule_tsc: "A1.2, CC7.2, CC7.3, CC6.1, CC6.8",
1112 agent_labels_customer: "bkomanh1",
1113 source: "10.255.255.13",
1114 gl2_source_input: "6459151dea00fd5d3da2df91",
1115 rule_level: 12,
1116 data_win_system_task: "0",
1117 timestamp_utc: "2023-11-05T11:42:41.269Z",
1118 syslog_type: AlertSourceSyslogType.Wazuh,
1119 data_win_system_threadID: "1424",
1120 rule_description:
1121 "Windows Defender: Antimalware platform detected potentially unwanted software ()",
1122 gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38",
1123 id: "1699184556.662819009",
1124 gl2_accounted_message_size: 6560,
1125 streams: ["650b315d5e9a2d550c6687ae"],
1126 gl2_message_id: "01HEFMNKESZFXFE4JGPJ43SFF6",
1127 data_win_system_computer: "WinDev2308Eval",
1128 agent_ip_reserved_ip: true,
1129 agent_ip: "172.26.161.217",
1130 true: 1699184556.769473,
1131 rule_hipaa: "164.312.b",
1132 rule_groups: "windows, windows_defender",
1133 data_win_system_keywords: "0x8000000000000000",
1134 data_win_system_level: "3",
1135 process_id: "3772",
1136 data_win_system_severityValue: AlertSourceDataWinSystemSeverityValue.Warning,
1137 rule_gdpr: "IV_35.7.d",
1138 rule_firedtimes: 1,
1139 data_win_system_systemTime: "2023-11-05T11:42:41.2693093Z",
1140 rule_mail: true,
1141 rule_pci_dss: "5.1, 5.2, 10.6.1, 11.4",
1142 rule_nist_800_53: "SI.3, AU.6, SI.4",
1143 decoder_name: AlertSourceDecoderName.WindowsEventchannel,
1144 data_win_system_processID: "3772",
1145 data_win_system_channel: "Microsoft-Windows-Windows Defender/Operational",
1146 syslog_level: AlertSourceSyslogLevel.Alert,
1147 data_win_system_providerName: "Microsoft-Windows-Windows Defender",
1148 data_win_system_version: "0",
1149 data_win_system_providerGuid: "{11cd958a-c507-4ef3-b3f2-5fd9dfbd2c78}",
1150 timestamp: "2023-11-05 11:42:41.625",
1151 data_win_eventdata_path:
1152 "containerfile:_C:\\\\Users\\\\User\\\\Desktop\\\\Email Extractor Professional Edition v7.3.3.6 Full Activated - WwW.Dr-FarFar.CoM.zip; file:_C:\\\\Users\\\\User\\\\Desktop\\\\Email Extractor Professional Edition v7.3.3.6 Full Activated - WwW.Dr-FarFar.CoM.zip-&gt;Setup/Email Extractor Professional Edition Full Activated.exe-&gt;(inno#000059)",
1153 data_win_system_opcode: "0",
1154 gl2_processing_error:
1155 'Replaced invalid timestamp value in message <6d89de79-7bd0-11ee-93bc-86000046278a> with current time - Value <2023-11-05T11:42:36.668+0000> caused exception: Invalid format: "2023-11-05T11:42:36.668+0000" is malformed at "T11:42:36.668+0000".',
1156 message:
1157 '{"true":1699184556.769473,"timestamp":"2023-11-05T11:42:36.668+0000","rule":{"level":12,"description":"Windows Defender: Antimalware platform detected potentially unwanted software ()","id":"62123","firedtimes":1,"mail":true,"groups":["windows","windows_defender"],"pci_dss":["5.1","5.2","10.6.1","11.4"],"gpg13":["4.2"],"gdpr":["IV_35.7.d"],"hipaa":["164.312.b"],"nist_800_53":["SI.3","AU.6","SI.4"],"tsc":["A1.2","CC7.2","CC7.3","CC6.1","CC6.8"]},"agent":{"id":"068","name":"WinDev2308Eval","ip":"172.26.161.217","labels":{"customer":"bkomanh1"}},"manager":{"name":"ASHWZHMA"},"id":"1699184556.662819009","decoder":{"name":"windows_eventchannel"},"data":{"win":{"system":{"providerName":"Microsoft-Windows-Windows Defender","providerGuid":"{11cd958a-c507-4ef3-b3f2-5fd9dfbd2c78}","eventID":"1116","version":"0","level":"3","task":"0","opcode":"0","keywords":"0x8000000000000000","systemTime":"2023-11-05T11:42:41.2693093Z","eventRecordID":"10017","processID":"3772","threadID":"1424","channel":"Microsoft-Windows-Windows Defender/Operational","computer":"WinDev2308Eval","severityValue":"WARNING","message":"\\"Microsoft Defender Antivirus has detected malware or other potentially unwanted software.\\r\\n For more information please see the following:\\r\\nhttps://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Wacatac.H!ml&threatid=2147814523&enterprise=0\\r\\n \\tName: Trojan:Win32/Wacatac.H!ml\\r\\n \\tID: 2147814523\\r\\n \\tSeverity: Severe\\r\\n \\tCategory: Trojan\\r\\n \\tPath: containerfile:_C:\\\\Users\\\\User\\\\Desktop\\\\Email Extractor Professional Edition v7.3.3.6 Full Activated - WwW.Dr-FarFar.CoM.zip; file:_C:\\\\Users\\\\User\\\\Desktop\\\\Email Extractor Professional Edition v7.3.3.6 Full Activated - WwW.Dr-FarFar.CoM.zip->Setup/Email Extractor Professional Edition Full Activated.exe->(inno#000059)\\r\\n \\tDetection Origin: Local machine\\r\\n \\tDetection Type: FastPath\\r\\n \\tDetection Source: System\\r\\n \\tUser: NT AUTHORITY\\\\SYSTEM\\r\\n \\tProcess Name: Unknown\\r\\n \\tSecurity intelligence Version: AV: 1.399.1651.0, AS: 1.399.1651.0, NIS: 1.399.1651.0\\r\\n \\tEngine Version: AM: 1.1.23090.2007, NIS: 1.1.23090.2007\\""},"eventdata":{"product Name":"Microsoft Defender Antivirus","product Version":"4.18.23090.2008","detection ID":"{8ECA5A94-47DE-4F30-B462-E46EE7427324}","detection Time":"2023-11-05T11:42:39.792Z","threat ID":"2147814523","threat Name":"Trojan:Win32/Wacatac.H!ml","severity ID":"5","severity Name":"Severe","category ID":"8","category Name":"Trojan","fWLink":"https://go.microsoft.com/fwlink/?linkid=37020&amp;name=Trojan:Win32/Wacatac.H!ml&amp;threatid=2147814523&amp;enterprise=0","status Code":"1","state":"1","source ID":"2","source Name":"System","process Name":"Unknown","detection User":"NT AUTHORITY\\\\\\\\SYSTEM","path":"containerfile:_C:\\\\\\\\Users\\\\\\\\User\\\\\\\\Desktop\\\\\\\\Email Extractor Professional Edition v7.3.3.6 Full Activated - WwW.Dr-FarFar.CoM.zip; file:_C:\\\\\\\\Users\\\\\\\\User\\\\\\\\Desktop\\\\\\\\Email Extractor Professional Edition v7.3.3.6 Full Activated - WwW.Dr-FarFar.CoM.zip-&gt;Setup/Email Extractor Professional Edition Full Activated.exe-&gt;(inno#000059)","origin ID":"1","origin Name":"Local machine","execution ID":"0","execution Name":"Unknown","type ID":"8","type Name":"FastPath","pre Execution Status":"0","action ID":"9","action Name":"Not Applicable","error Code":"0x00000000","error Description":"The operation completed successfully.","post Clean Status":"0","additional Actions ID":"0","additional Actions String":"No additional actions required","security intelligence Version":"AV: 1.399.1651.0, AS: 1.399.1651.0, NIS: 1.399.1651.0","engine Version":"AM: 1.1.23090.2007, NIS: 1.1.23090.2007"}}},"location":"EventChannel"}',
1158 rule_id: "62123",
1159 manager_name: "ASHWZHMA",
1160 rule_gpg13: "4.2",
1161 data_win_eventdata_state: "1",
1162 location: "EventChannel",
1163 data_win_system_message:
1164 '"Microsoft Defender Antivirus has detected malware or other potentially unwanted software.\r\n For more information please see the following:\r\nhttps://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Wacatac.H!ml&threatid=2147814523&enterprise=0\r\n \tName: Trojan:Win32/Wacatac.H!ml\r\n \tID: 2147814523\r\n \tSeverity: Severe\r\n \tCategory: Trojan\r\n \tPath: containerfile:_C:\\Users\\User\\Desktop\\Email Extractor Professional Edition v7.3.3.6 Full Activated - WwW.Dr-FarFar.CoM.zip; file:_C:\\Users\\User\\Desktop\\Email Extractor Professional Edition v7.3.3.6 Full Activated - WwW.Dr-FarFar.CoM.zip->Setup/Email Extractor Professional Edition Full Activated.exe->(inno#000059)\r\n \tDetection Origin: Local machine\r\n \tDetection Type: FastPath\r\n \tDetection Source: System\r\n \tUser: NT AUTHORITY\\SYSTEM\r\n \tProcess Name: Unknown\r\n \tSecurity intelligence Version: AV: 1.399.1651.0, AS: 1.399.1651.0, NIS: 1.399.1651.0\r\n \tEngine Version: AM: 1.1.23090.2007, NIS: 1.1.23090.2007"',
1165 msg_timestamp: "2023-11-05T11:42:36.668Z",
1166 rule_group2: "windows_defender",
1167 rule_group1: "windows"
1168 },
1169 sort: [1699184561269]
1170 },
1171 {
1172 _index: "wazuh-bkomanh1_1",
1173 _id: "4c764493-7bcf-11ee-93bc-86000046278a",
1174 _score: null,
1175 _source: {
1176 data_win_eventdata_description: "Application Compatibility Database Installer",
1177 source_reserved_ip: true,
1178 data_win_system_eventRecordID: "833927",
1179 data_win_eventdata_user: "NT AUTHORITY\\\\SYSTEM",
1180 agent_id: "068",
1181 agent_name: "WinDev2308Eval",
1182 sha256: "5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77",
1183 gl2_remote_ip: "10.255.255.13",
1184 data_win_system_eventID: "1",
1185 gl2_remote_port: 53864,
1186 agent_labels_customer: "bkomanh1",
1187 source: "10.255.255.13",
1188 gl2_source_input: "6459151dea00fd5d3da2df91",
1189 rule_level: 12,
1190 data_win_eventdata_originalFileName: "sdbinst.exe",
1191 data_win_eventdata_company: "Microsoft Corporation",
1192 data_win_system_task: "1",
1193 timestamp_utc: "2023-11-05T11:34:39.282Z",
1194 syslog_type: AlertSourceSyslogType.Wazuh,
1195 data_win_system_threadID: "4928",
1196 rule_description: "Application Compatibility Database launched",
1197 data_win_eventdata_parentUser: "NT AUTHORITY\\\\SYSTEM",
1198 gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38",
1199 id: "1699184073.657048982",
1200 rule_mitre_tactic: "Privilege Escalation, Persistence",
1201 gl2_accounted_message_size: 7629,
1202 data_win_eventdata_integrityLevel: AlertSourceDataWinEventdataIntegrityLevel.System,
1203 data_win_eventdata_utcTime: "2023-11-05 11:34:39.276",
1204 streams: ["650b315d5e9a2d550c6687ae"],
1205 rule_mitre_id: "T1546.011",
1206 gl2_message_id: "01HEFM6STTQE4PJPF9Q1AC96JZ",
1207 data_win_system_computer: "WinDev2308Eval",
1208 data_win_eventdata_currentDirectory: "C:\\\\Windows\\\\system32\\\\",
1209 agent_ip_reserved_ip: true,
1210 data_win_eventdata_ruleName: "technique_id=T1546.011,technique_name=Application Shimming",
1211 data_win_eventdata_hashes:
1212 "SHA1=C0C9554DCEBF89ABC7DA5332037BC2C88A3B0F1E,MD5=72A442005F409F233C223E60A7A0D868,SHA256=5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77,IMPHASH=999B9DCD61DAB941B1E8D50FE6EF72CD",
1213 agent_ip: "172.26.161.217",
1214 data_win_eventdata_image: "C:\\\\Windows\\\\System32\\\\sdbinst.exe",
1215 data_win_eventdata_parentProcessGuid: "{10906cbf-9e07-6528-8600-000000000e00}",
1216 true: 1699184073.810394,
1217 data_win_eventdata_parentProcessId: "5952",
1218 rule_groups: "sysmon, sysmon_eid1_detections, windows",
1219 data_win_system_keywords: "0x8000000000000000",
1220 data_win_system_level: "4",
1221 data_win_eventdata_fileVersion: "10.0.22621.2361 (WinBuild.160101.0800)",
1222 data_win_eventdata_parentImage: "C:\\\\Windows\\\\System32\\\\svchost.exe",
1223 process_id: "1800",
1224 data_win_system_severityValue: AlertSourceDataWinSystemSeverityValue.Information,
1225 data_win_eventdata_processGuid: "{10906cbf-7dcf-6547-6284-010000000e00}",
1226 rule_mitre_technique: "Application Shimming",
1227 rule_firedtimes: 1,
1228 data_win_system_systemTime: "2023-11-05T11:34:39.2824291Z",
1229 rule_mail: true,
1230 decoder_name: AlertSourceDecoderName.WindowsEventchannel,
1231 data_win_eventdata_commandLine: "C:\\\\Windows\\\\System32\\\\sdbinst.exe -m -bg",
1232 data_win_system_processID: "3808",
1233 data_win_system_channel: "Microsoft-Windows-Sysmon/Operational",
1234 syslog_level: AlertSourceSyslogLevel.Alert,
1235 data_win_system_providerName: "Microsoft-Windows-Sysmon",
1236 data_win_eventdata_processId: "1800",
1237 data_win_system_version: "5",
1238 data_win_system_providerGuid: "{5770385f-c22a-43e0-bf4c-06f5698ffbd9}",
1239 timestamp: "2023-11-05 11:34:36.634",
1240 data_win_eventdata_parentCommandLine:
1241 "C:\\\\Windows\\\\system32\\\\svchost.exe -k LocalSystemNetworkRestricted -p -s PcaSvc",
1242 data_win_system_opcode: "0",
1243 gl2_processing_error:
1244 'Replaced invalid timestamp value in message <4c764493-7bcf-11ee-93bc-86000046278a> with current time - Value <2023-11-05T11:34:33.778+0000> caused exception: Invalid format: "2023-11-05T11:34:33.778+0000" is malformed at "T11:34:33.778+0000".',
1245 data_win_eventdata_terminalSessionId: "0",
1246 message:
1247 '{"true":1699184073.810394,"timestamp":"2023-11-05T11:34:33.778+0000","rule":{"level":12,"description":"Application Compatibility Database launched","id":"92058","mitre":{"id":["T1546.011"],"tactic":["Privilege Escalation","Persistence"],"technique":["Application Shimming"]},"firedtimes":1,"mail":true,"groups":["sysmon","sysmon_eid1_detections","windows"]},"agent":{"id":"068","name":"WinDev2308Eval","ip":"172.26.161.217","labels":{"customer":"bkomanh1"}},"manager":{"name":"ASHWZHMA"},"id":"1699184073.657048982","decoder":{"name":"windows_eventchannel"},"data":{"win":{"system":{"providerName":"Microsoft-Windows-Sysmon","providerGuid":"{5770385f-c22a-43e0-bf4c-06f5698ffbd9}","eventID":"1","version":"5","level":"4","task":"1","opcode":"0","keywords":"0x8000000000000000","systemTime":"2023-11-05T11:34:39.2824291Z","eventRecordID":"833927","processID":"3808","threadID":"4928","channel":"Microsoft-Windows-Sysmon/Operational","computer":"WinDev2308Eval","severityValue":"INFORMATION","message":"\\"Process Create:\\r\\nRuleName: technique_id=T1546.011,technique_name=Application Shimming\\r\\nUtcTime: 2023-11-05 11:34:39.276\\r\\nProcessGuid: {10906cbf-7dcf-6547-6284-010000000e00}\\r\\nProcessId: 1800\\r\\nImage: C:\\\\Windows\\\\System32\\\\sdbinst.exe\\r\\nFileVersion: 10.0.22621.2361 (WinBuild.160101.0800)\\r\\nDescription: Application Compatibility Database Installer\\r\\nProduct: Microsoft® Windows® Operating System\\r\\nCompany: Microsoft Corporation\\r\\nOriginalFileName: sdbinst.exe\\r\\nCommandLine: C:\\\\Windows\\\\System32\\\\sdbinst.exe -m -bg\\r\\nCurrentDirectory: C:\\\\Windows\\\\system32\\\\\\r\\nUser: NT AUTHORITY\\\\SYSTEM\\r\\nLogonGuid: {10906cbf-9df1-6528-e703-000000000000}\\r\\nLogonId: 0x3E7\\r\\nTerminalSessionId: 0\\r\\nIntegrityLevel: System\\r\\nHashes: SHA1=C0C9554DCEBF89ABC7DA5332037BC2C88A3B0F1E,MD5=72A442005F409F233C223E60A7A0D868,SHA256=5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77,IMPHASH=999B9DCD61DAB941B1E8D50FE6EF72CD\\r\\nParentProcessGuid: {10906cbf-9e07-6528-8600-000000000e00}\\r\\nParentProcessId: 5952\\r\\nParentImage: C:\\\\Windows\\\\System32\\\\svchost.exe\\r\\nParentCommandLine: C:\\\\Windows\\\\system32\\\\svchost.exe -k LocalSystemNetworkRestricted -p -s PcaSvc\\r\\nParentUser: NT AUTHORITY\\\\SYSTEM\\""},"eventdata":{"ruleName":"technique_id=T1546.011,technique_name=Application Shimming","utcTime":"2023-11-05 11:34:39.276","processGuid":"{10906cbf-7dcf-6547-6284-010000000e00}","processId":"1800","image":"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\sdbinst.exe","fileVersion":"10.0.22621.2361 (WinBuild.160101.0800)","description":"Application Compatibility Database Installer","product":"Microsoft® Windows® Operating System","company":"Microsoft Corporation","originalFileName":"sdbinst.exe","commandLine":"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\sdbinst.exe -m -bg","currentDirectory":"C:\\\\\\\\Windows\\\\\\\\system32\\\\\\\\","user":"NT AUTHORITY\\\\\\\\SYSTEM","logonGuid":"{10906cbf-9df1-6528-e703-000000000000}","logonId":"0x3e7","terminalSessionId":"0","integrityLevel":"System","hashes":"SHA1=C0C9554DCEBF89ABC7DA5332037BC2C88A3B0F1E,MD5=72A442005F409F233C223E60A7A0D868,SHA256=5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77,IMPHASH=999B9DCD61DAB941B1E8D50FE6EF72CD","parentProcessGuid":"{10906cbf-9e07-6528-8600-000000000e00}","parentProcessId":"5952","parentImage":"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\svchost.exe","parentCommandLine":"C:\\\\\\\\Windows\\\\\\\\system32\\\\\\\\svchost.exe -k LocalSystemNetworkRestricted -p -s PcaSvc","parentUser":"NT AUTHORITY\\\\\\\\SYSTEM"}}},"location":"EventChannel"}',
1248 rule_id: "92058",
1249 hash_sha256: "SHA256=5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77",
1250 manager_name: "ASHWZHMA",
1251 data_win_eventdata_logonGuid: "{10906cbf-9df1-6528-e703-000000000000}",
1252 data_win_eventdata_logonId: "0x3e7",
1253 location: "EventChannel",
1254 rule_group3: AlertSourceDataLogsourceProduct.Windows,
1255 data_win_system_message:
1256 '"Process Create:\r\nRuleName: technique_id=T1546.011,technique_name=Application Shimming\r\nUtcTime: 2023-11-05 11:34:39.276\r\nProcessGuid: {10906cbf-7dcf-6547-6284-010000000e00}\r\nProcessId: 1800\r\nImage: C:\\Windows\\System32\\sdbinst.exe\r\nFileVersion: 10.0.22621.2361 (WinBuild.160101.0800)\r\nDescription: Application Compatibility Database Installer\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: sdbinst.exe\r\nCommandLine: C:\\Windows\\System32\\sdbinst.exe -m -bg\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {10906cbf-9df1-6528-e703-000000000000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: SHA1=C0C9554DCEBF89ABC7DA5332037BC2C88A3B0F1E,MD5=72A442005F409F233C223E60A7A0D868,SHA256=5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77,IMPHASH=999B9DCD61DAB941B1E8D50FE6EF72CD\r\nParentProcessGuid: {10906cbf-9e07-6528-8600-000000000e00}\r\nParentProcessId: 5952\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k LocalSystemNetworkRestricted -p -s PcaSvc\r\nParentUser: NT AUTHORITY\\SYSTEM"',
1257 msg_timestamp: "2023-11-05T11:34:33.778Z",
1258 rule_group2: "sysmon_eid1_detections",
1259 data_win_eventdata_product: "Microsoft® Windows® Operating System",
1260 rule_group1: "sysmon"
1261 },
1262 sort: [1699184079282]
1263 },
1264 {
1265 _index: "wazuh-bkomanh1_1",
1266 _id: "eab278d1-7bc6-11ee-93bc-86000046278a",
1267 _score: null,
1268 _source: {
1269 data_win_eventdata_description: "Application Compatibility Database Installer",
1270 source_reserved_ip: true,
1271 data_win_system_eventRecordID: "832940",
1272 data_win_eventdata_user: "NT AUTHORITY\\\\SYSTEM",
1273 agent_id: "068",
1274 agent_name: "WinDev2308Eval",
1275 sha256: "5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77",
1276 gl2_remote_ip: "10.255.255.13",
1277 data_win_system_eventID: "1",
1278 gl2_remote_port: 55734,
1279 agent_labels_customer: "bkomanh1",
1280 source: "10.255.255.13",
1281 gl2_source_input: "6459151dea00fd5d3da2df91",
1282 rule_level: 12,
1283 data_win_eventdata_originalFileName: "sdbinst.exe",
1284 data_win_eventdata_company: "Microsoft Corporation",
1285 data_win_system_task: "1",
1286 timestamp_utc: "2023-11-05T10:34:39.227Z",
1287 syslog_type: AlertSourceSyslogType.Wazuh,
1288 data_win_system_threadID: "4928",
1289 rule_description: "Application Compatibility Database launched",
1290 data_win_eventdata_parentUser: "NT AUTHORITY\\\\SYSTEM",
1291 gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38",
1292 id: "1699180474.607950326",
1293 rule_mitre_tactic: "Privilege Escalation, Persistence",
1294 gl2_accounted_message_size: 7634,
1295 data_win_eventdata_integrityLevel: AlertSourceDataWinEventdataIntegrityLevel.System,
1296 data_win_eventdata_utcTime: "2023-11-05 10:34:39.223",
1297 streams: ["650b315d5e9a2d550c6687ae"],
1298 rule_mitre_id: "T1546.011",
1299 gl2_message_id: "01HEFGRY6YC425JFCGQFVGDCSB",
1300 data_win_system_computer: "WinDev2308Eval",
1301 data_win_eventdata_currentDirectory: "C:\\\\Windows\\\\system32\\\\",
1302 agent_ip_reserved_ip: true,
1303 data_win_eventdata_ruleName: "technique_id=T1546.011,technique_name=Application Shimming",
1304 data_win_eventdata_hashes:
1305 "SHA1=C0C9554DCEBF89ABC7DA5332037BC2C88A3B0F1E,MD5=72A442005F409F233C223E60A7A0D868,SHA256=5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77,IMPHASH=999B9DCD61DAB941B1E8D50FE6EF72CD",
1306 agent_ip: "172.26.161.217",
1307 data_win_eventdata_image: "C:\\\\Windows\\\\System32\\\\sdbinst.exe",
1308 data_win_eventdata_parentProcessGuid: "{10906cbf-9e07-6528-8600-000000000e00}",
1309 true: 1699180474.684764,
1310 data_win_eventdata_parentProcessId: "5952",
1311 rule_groups: "sysmon, sysmon_eid1_detections, windows",
1312 data_win_system_keywords: "0x8000000000000000",
1313 data_win_system_level: "4",
1314 data_win_eventdata_fileVersion: "10.0.22621.2361 (WinBuild.160101.0800)",
1315 data_win_eventdata_parentImage: "C:\\\\Windows\\\\System32\\\\svchost.exe",
1316 process_id: "10456",
1317 data_win_system_severityValue: AlertSourceDataWinSystemSeverityValue.Information,
1318 data_win_eventdata_processGuid: "{10906cbf-6fbf-6547-bc83-010000000e00}",
1319 rule_mitre_technique: "Application Shimming",
1320 rule_firedtimes: 1,
1321 data_win_system_systemTime: "2023-11-05T10:34:39.2278008Z",
1322 rule_mail: true,
1323 decoder_name: AlertSourceDecoderName.WindowsEventchannel,
1324 data_win_eventdata_commandLine: "C:\\\\Windows\\\\System32\\\\sdbinst.exe -m -bg",
1325 data_win_system_processID: "3808",
1326 data_win_system_channel: "Microsoft-Windows-Sysmon/Operational",
1327 syslog_level: AlertSourceSyslogLevel.Alert,
1328 data_win_system_providerName: "Microsoft-Windows-Sysmon",
1329 data_win_eventdata_processId: "10456",
1330 data_win_system_version: "5",
1331 data_win_system_providerGuid: "{5770385f-c22a-43e0-bf4c-06f5698ffbd9}",
1332 timestamp: "2023-11-05 10:34:36.638",
1333 data_win_eventdata_parentCommandLine:
1334 "C:\\\\Windows\\\\system32\\\\svchost.exe -k LocalSystemNetworkRestricted -p -s PcaSvc",
1335 data_win_system_opcode: "0",
1336 gl2_processing_error:
1337 'Replaced invalid timestamp value in message <eab278d1-7bc6-11ee-93bc-86000046278a> with current time - Value <2023-11-05T10:34:34.669+0000> caused exception: Invalid format: "2023-11-05T10:34:34.669+0000" is malformed at "T10:34:34.669+0000".',
1338 data_win_eventdata_terminalSessionId: "0",
1339 message:
1340 '{"true":1699180474.684764,"timestamp":"2023-11-05T10:34:34.669+0000","rule":{"level":12,"description":"Application Compatibility Database launched","id":"92058","mitre":{"id":["T1546.011"],"tactic":["Privilege Escalation","Persistence"],"technique":["Application Shimming"]},"firedtimes":1,"mail":true,"groups":["sysmon","sysmon_eid1_detections","windows"]},"agent":{"id":"068","name":"WinDev2308Eval","ip":"172.26.161.217","labels":{"customer":"bkomanh1"}},"manager":{"name":"ASHWZHMA"},"id":"1699180474.607950326","decoder":{"name":"windows_eventchannel"},"data":{"win":{"system":{"providerName":"Microsoft-Windows-Sysmon","providerGuid":"{5770385f-c22a-43e0-bf4c-06f5698ffbd9}","eventID":"1","version":"5","level":"4","task":"1","opcode":"0","keywords":"0x8000000000000000","systemTime":"2023-11-05T10:34:39.2278008Z","eventRecordID":"832940","processID":"3808","threadID":"4928","channel":"Microsoft-Windows-Sysmon/Operational","computer":"WinDev2308Eval","severityValue":"INFORMATION","message":"\\"Process Create:\\r\\nRuleName: technique_id=T1546.011,technique_name=Application Shimming\\r\\nUtcTime: 2023-11-05 10:34:39.223\\r\\nProcessGuid: {10906cbf-6fbf-6547-bc83-010000000e00}\\r\\nProcessId: 10456\\r\\nImage: C:\\\\Windows\\\\System32\\\\sdbinst.exe\\r\\nFileVersion: 10.0.22621.2361 (WinBuild.160101.0800)\\r\\nDescription: Application Compatibility Database Installer\\r\\nProduct: Microsoft® Windows® Operating System\\r\\nCompany: Microsoft Corporation\\r\\nOriginalFileName: sdbinst.exe\\r\\nCommandLine: C:\\\\Windows\\\\System32\\\\sdbinst.exe -m -bg\\r\\nCurrentDirectory: C:\\\\Windows\\\\system32\\\\\\r\\nUser: NT AUTHORITY\\\\SYSTEM\\r\\nLogonGuid: {10906cbf-9df1-6528-e703-000000000000}\\r\\nLogonId: 0x3E7\\r\\nTerminalSessionId: 0\\r\\nIntegrityLevel: System\\r\\nHashes: SHA1=C0C9554DCEBF89ABC7DA5332037BC2C88A3B0F1E,MD5=72A442005F409F233C223E60A7A0D868,SHA256=5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77,IMPHASH=999B9DCD61DAB941B1E8D50FE6EF72CD\\r\\nParentProcessGuid: {10906cbf-9e07-6528-8600-000000000e00}\\r\\nParentProcessId: 5952\\r\\nParentImage: C:\\\\Windows\\\\System32\\\\svchost.exe\\r\\nParentCommandLine: C:\\\\Windows\\\\system32\\\\svchost.exe -k LocalSystemNetworkRestricted -p -s PcaSvc\\r\\nParentUser: NT AUTHORITY\\\\SYSTEM\\""},"eventdata":{"ruleName":"technique_id=T1546.011,technique_name=Application Shimming","utcTime":"2023-11-05 10:34:39.223","processGuid":"{10906cbf-6fbf-6547-bc83-010000000e00}","processId":"10456","image":"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\sdbinst.exe","fileVersion":"10.0.22621.2361 (WinBuild.160101.0800)","description":"Application Compatibility Database Installer","product":"Microsoft® Windows® Operating System","company":"Microsoft Corporation","originalFileName":"sdbinst.exe","commandLine":"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\sdbinst.exe -m -bg","currentDirectory":"C:\\\\\\\\Windows\\\\\\\\system32\\\\\\\\","user":"NT AUTHORITY\\\\\\\\SYSTEM","logonGuid":"{10906cbf-9df1-6528-e703-000000000000}","logonId":"0x3e7","terminalSessionId":"0","integrityLevel":"System","hashes":"SHA1=C0C9554DCEBF89ABC7DA5332037BC2C88A3B0F1E,MD5=72A442005F409F233C223E60A7A0D868,SHA256=5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77,IMPHASH=999B9DCD61DAB941B1E8D50FE6EF72CD","parentProcessGuid":"{10906cbf-9e07-6528-8600-000000000e00}","parentProcessId":"5952","parentImage":"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\svchost.exe","parentCommandLine":"C:\\\\\\\\Windows\\\\\\\\system32\\\\\\\\svchost.exe -k LocalSystemNetworkRestricted -p -s PcaSvc","parentUser":"NT AUTHORITY\\\\\\\\SYSTEM"}}},"location":"EventChannel"}',
1341 rule_id: "92058",
1342 hash_sha256: "SHA256=5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77",
1343 manager_name: "ASHWZHMA",
1344 data_win_eventdata_logonGuid: "{10906cbf-9df1-6528-e703-000000000000}",
1345 data_win_eventdata_logonId: "0x3e7",
1346 location: "EventChannel",
1347 rule_group3: AlertSourceDataLogsourceProduct.Windows,
1348 data_win_system_message:
1349 '"Process Create:\r\nRuleName: technique_id=T1546.011,technique_name=Application Shimming\r\nUtcTime: 2023-11-05 10:34:39.223\r\nProcessGuid: {10906cbf-6fbf-6547-bc83-010000000e00}\r\nProcessId: 10456\r\nImage: C:\\Windows\\System32\\sdbinst.exe\r\nFileVersion: 10.0.22621.2361 (WinBuild.160101.0800)\r\nDescription: Application Compatibility Database Installer\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: sdbinst.exe\r\nCommandLine: C:\\Windows\\System32\\sdbinst.exe -m -bg\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {10906cbf-9df1-6528-e703-000000000000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: SHA1=C0C9554DCEBF89ABC7DA5332037BC2C88A3B0F1E,MD5=72A442005F409F233C223E60A7A0D868,SHA256=5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77,IMPHASH=999B9DCD61DAB941B1E8D50FE6EF72CD\r\nParentProcessGuid: {10906cbf-9e07-6528-8600-000000000e00}\r\nParentProcessId: 5952\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k LocalSystemNetworkRestricted -p -s PcaSvc\r\nParentUser: NT AUTHORITY\\SYSTEM"',
1350 msg_timestamp: "2023-11-05T10:34:34.669Z",
1351 rule_group2: "sysmon_eid1_detections",
1352 data_win_eventdata_product: "Microsoft® Windows® Operating System",
1353 rule_group1: "sysmon"
1354 },
1355 sort: [1699180479227]
1356 },
1357 {
1358 _index: "wazuh-bkomanh1_1",
1359 _id: "88ee10d0-7bbe-11ee-93bc-86000046278a",
1360 _score: null,
1361 _source: {
1362 data_win_eventdata_description: "Application Compatibility Database Installer",
1363 source_reserved_ip: true,
1364 data_win_system_eventRecordID: "832368",
1365 data_win_eventdata_user: "NT AUTHORITY\\\\SYSTEM",
1366 agent_id: "068",
1367 agent_name: "WinDev2308Eval",
1368 sha256: "5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77",
1369 gl2_remote_ip: "10.255.255.13",
1370 data_win_system_eventID: "1",
1371 gl2_remote_port: 41488,
1372 agent_labels_customer: "bkomanh1",
1373 source: "10.255.255.13",
1374 gl2_source_input: "6459151dea00fd5d3da2df91",
1375 rule_level: 12,
1376 data_win_eventdata_originalFileName: "sdbinst.exe",
1377 data_win_eventdata_company: "Microsoft Corporation",
1378 data_win_system_task: "1",
1379 timestamp_utc: "2023-11-05T09:34:39.164Z",
1380 syslog_type: AlertSourceSyslogType.Wazuh,
1381 data_win_system_threadID: "4928",
1382 rule_description: "Application Compatibility Database launched",
1383 data_win_eventdata_parentUser: "NT AUTHORITY\\\\SYSTEM",
1384 gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38",
1385 id: "1699176874.562050141",
1386 rule_mitre_tactic: "Privilege Escalation, Persistence",
1387 gl2_accounted_message_size: 7629,
1388 data_win_eventdata_integrityLevel: AlertSourceDataWinEventdataIntegrityLevel.System,
1389 data_win_eventdata_utcTime: "2023-11-05 09:34:39.158",
1390 streams: ["650b315d5e9a2d550c6687ae"],
1391 rule_mitre_id: "T1546.011",
1392 gl2_message_id: "01HEFDB2JYZDYQZM86QYF1YYTJ",
1393 data_win_system_computer: "WinDev2308Eval",
1394 data_win_eventdata_currentDirectory: "C:\\\\Windows\\\\system32\\\\",
1395 agent_ip_reserved_ip: true,
1396 data_win_eventdata_ruleName: "technique_id=T1546.011,technique_name=Application Shimming",
1397 data_win_eventdata_hashes:
1398 "SHA1=C0C9554DCEBF89ABC7DA5332037BC2C88A3B0F1E,MD5=72A442005F409F233C223E60A7A0D868,SHA256=5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77,IMPHASH=999B9DCD61DAB941B1E8D50FE6EF72CD",
1399 agent_ip: "172.26.161.217",
1400 data_win_eventdata_image: "C:\\\\Windows\\\\System32\\\\sdbinst.exe",
1401 data_win_eventdata_parentProcessGuid: "{10906cbf-9e07-6528-8600-000000000e00}",
1402 true: 1699176874.657827,
1403 data_win_eventdata_parentProcessId: "5952",
1404 rule_groups: "sysmon, sysmon_eid1_detections, windows",
1405 data_win_system_keywords: "0x8000000000000000",
1406 data_win_system_level: "4",
1407 data_win_eventdata_fileVersion: "10.0.22621.2361 (WinBuild.160101.0800)",
1408 data_win_eventdata_parentImage: "C:\\\\Windows\\\\System32\\\\svchost.exe",
1409 process_id: "1368",
1410 data_win_system_severityValue: AlertSourceDataWinSystemSeverityValue.Information,
1411 data_win_eventdata_processGuid: "{10906cbf-61af-6547-4683-010000000e00}",
1412 rule_mitre_technique: "Application Shimming",
1413 rule_firedtimes: 1,
1414 data_win_system_systemTime: "2023-11-05T09:34:39.1640751Z",
1415 rule_mail: true,
1416 decoder_name: AlertSourceDecoderName.WindowsEventchannel,
1417 data_win_eventdata_commandLine: "C:\\\\Windows\\\\System32\\\\sdbinst.exe -m -bg",
1418 data_win_system_processID: "3808",
1419 data_win_system_channel: "Microsoft-Windows-Sysmon/Operational",
1420 syslog_level: AlertSourceSyslogLevel.Alert,
1421 data_win_system_providerName: "Microsoft-Windows-Sysmon",
1422 data_win_eventdata_processId: "1368",
1423 data_win_system_version: "5",
1424 data_win_system_providerGuid: "{5770385f-c22a-43e0-bf4c-06f5698ffbd9}",
1425 timestamp: "2023-11-05 09:34:36.638",
1426 data_win_eventdata_parentCommandLine:
1427 "C:\\\\Windows\\\\system32\\\\svchost.exe -k LocalSystemNetworkRestricted -p -s PcaSvc",
1428 data_win_system_opcode: "0",
1429 gl2_processing_error:
1430 'Replaced invalid timestamp value in message <88ee10d0-7bbe-11ee-93bc-86000046278a> with current time - Value <2023-11-05T09:34:34.642+0000> caused exception: Invalid format: "2023-11-05T09:34:34.642+0000" is malformed at "T09:34:34.642+0000".',
1431 data_win_eventdata_terminalSessionId: "0",
1432 message:
1433 '{"true":1699176874.657827,"timestamp":"2023-11-05T09:34:34.642+0000","rule":{"level":12,"description":"Application Compatibility Database launched","id":"92058","mitre":{"id":["T1546.011"],"tactic":["Privilege Escalation","Persistence"],"technique":["Application Shimming"]},"firedtimes":1,"mail":true,"groups":["sysmon","sysmon_eid1_detections","windows"]},"agent":{"id":"068","name":"WinDev2308Eval","ip":"172.26.161.217","labels":{"customer":"bkomanh1"}},"manager":{"name":"ASHWZHMA"},"id":"1699176874.562050141","decoder":{"name":"windows_eventchannel"},"data":{"win":{"system":{"providerName":"Microsoft-Windows-Sysmon","providerGuid":"{5770385f-c22a-43e0-bf4c-06f5698ffbd9}","eventID":"1","version":"5","level":"4","task":"1","opcode":"0","keywords":"0x8000000000000000","systemTime":"2023-11-05T09:34:39.1640751Z","eventRecordID":"832368","processID":"3808","threadID":"4928","channel":"Microsoft-Windows-Sysmon/Operational","computer":"WinDev2308Eval","severityValue":"INFORMATION","message":"\\"Process Create:\\r\\nRuleName: technique_id=T1546.011,technique_name=Application Shimming\\r\\nUtcTime: 2023-11-05 09:34:39.158\\r\\nProcessGuid: {10906cbf-61af-6547-4683-010000000e00}\\r\\nProcessId: 1368\\r\\nImage: C:\\\\Windows\\\\System32\\\\sdbinst.exe\\r\\nFileVersion: 10.0.22621.2361 (WinBuild.160101.0800)\\r\\nDescription: Application Compatibility Database Installer\\r\\nProduct: Microsoft® Windows® Operating System\\r\\nCompany: Microsoft Corporation\\r\\nOriginalFileName: sdbinst.exe\\r\\nCommandLine: C:\\\\Windows\\\\System32\\\\sdbinst.exe -m -bg\\r\\nCurrentDirectory: C:\\\\Windows\\\\system32\\\\\\r\\nUser: NT AUTHORITY\\\\SYSTEM\\r\\nLogonGuid: {10906cbf-9df1-6528-e703-000000000000}\\r\\nLogonId: 0x3E7\\r\\nTerminalSessionId: 0\\r\\nIntegrityLevel: System\\r\\nHashes: SHA1=C0C9554DCEBF89ABC7DA5332037BC2C88A3B0F1E,MD5=72A442005F409F233C223E60A7A0D868,SHA256=5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77,IMPHASH=999B9DCD61DAB941B1E8D50FE6EF72CD\\r\\nParentProcessGuid: {10906cbf-9e07-6528-8600-000000000e00}\\r\\nParentProcessId: 5952\\r\\nParentImage: C:\\\\Windows\\\\System32\\\\svchost.exe\\r\\nParentCommandLine: C:\\\\Windows\\\\system32\\\\svchost.exe -k LocalSystemNetworkRestricted -p -s PcaSvc\\r\\nParentUser: NT AUTHORITY\\\\SYSTEM\\""},"eventdata":{"ruleName":"technique_id=T1546.011,technique_name=Application Shimming","utcTime":"2023-11-05 09:34:39.158","processGuid":"{10906cbf-61af-6547-4683-010000000e00}","processId":"1368","image":"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\sdbinst.exe","fileVersion":"10.0.22621.2361 (WinBuild.160101.0800)","description":"Application Compatibility Database Installer","product":"Microsoft® Windows® Operating System","company":"Microsoft Corporation","originalFileName":"sdbinst.exe","commandLine":"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\sdbinst.exe -m -bg","currentDirectory":"C:\\\\\\\\Windows\\\\\\\\system32\\\\\\\\","user":"NT AUTHORITY\\\\\\\\SYSTEM","logonGuid":"{10906cbf-9df1-6528-e703-000000000000}","logonId":"0x3e7","terminalSessionId":"0","integrityLevel":"System","hashes":"SHA1=C0C9554DCEBF89ABC7DA5332037BC2C88A3B0F1E,MD5=72A442005F409F233C223E60A7A0D868,SHA256=5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77,IMPHASH=999B9DCD61DAB941B1E8D50FE6EF72CD","parentProcessGuid":"{10906cbf-9e07-6528-8600-000000000e00}","parentProcessId":"5952","parentImage":"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\svchost.exe","parentCommandLine":"C:\\\\\\\\Windows\\\\\\\\system32\\\\\\\\svchost.exe -k LocalSystemNetworkRestricted -p -s PcaSvc","parentUser":"NT AUTHORITY\\\\\\\\SYSTEM"}}},"location":"EventChannel"}',
1434 rule_id: "92058",
1435 hash_sha256: "SHA256=5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77",
1436 manager_name: "ASHWZHMA",
1437 data_win_eventdata_logonGuid: "{10906cbf-9df1-6528-e703-000000000000}",
1438 data_win_eventdata_logonId: "0x3e7",
1439 location: "EventChannel",
1440 rule_group3: AlertSourceDataLogsourceProduct.Windows,
1441 data_win_system_message:
1442 '"Process Create:\r\nRuleName: technique_id=T1546.011,technique_name=Application Shimming\r\nUtcTime: 2023-11-05 09:34:39.158\r\nProcessGuid: {10906cbf-61af-6547-4683-010000000e00}\r\nProcessId: 1368\r\nImage: C:\\Windows\\System32\\sdbinst.exe\r\nFileVersion: 10.0.22621.2361 (WinBuild.160101.0800)\r\nDescription: Application Compatibility Database Installer\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: sdbinst.exe\r\nCommandLine: C:\\Windows\\System32\\sdbinst.exe -m -bg\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {10906cbf-9df1-6528-e703-000000000000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: SHA1=C0C9554DCEBF89ABC7DA5332037BC2C88A3B0F1E,MD5=72A442005F409F233C223E60A7A0D868,SHA256=5913E1A6AC0D582A8710FFD723E16486A0E7C56C6122820175C4745C30816B77,IMPHASH=999B9DCD61DAB941B1E8D50FE6EF72CD\r\nParentProcessGuid: {10906cbf-9e07-6528-8600-000000000e00}\r\nParentProcessId: 5952\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k LocalSystemNetworkRestricted -p -s PcaSvc\r\nParentUser: NT AUTHORITY\\SYSTEM"',
1443 msg_timestamp: "2023-11-05T09:34:34.642Z",
1444 rule_group2: "sysmon_eid1_detections",
1445 data_win_eventdata_product: "Microsoft® Windows® Operating System",
1446 rule_group1: "sysmon"
1447 },
1448 sort: [1699176879164]
1449 }
1450 ]
1451 },
1452 {
1453 index_name: "wazuh-toafb68l_2",
1454 total_alerts: 2,
1455 alerts: [
1456 {
1457 _index: "wazuh-toafb68l_2",
1458 _id: "15d6dd81-7ba4-11ee-93bc-86000046278a",
1459 _score: null,
1460 _source: {
1461 parent_process_id: "214455",
1462 source_reserved_ip: true,
1463 agent_id: "077",
1464 agent_name: "ssdnodes-zabbix",
1465 gl2_remote_ip: "10.255.255.13",
1466 gl2_remote_port: 53816,
1467 data_columns_cwd: "/",
1468 agent_labels_customer: "toafb68l",
1469 agent_ip_city_name: "Sydney",
1470 source: "10.255.255.13",
1471 gl2_source_input: "6459151dea00fd5d3da2df91",
1472 rule_level: 12,
1473 data_calendarTime: "Sun Nov 5 06:25:09 2023 UTC",
1474 data_counter: "19295",
1475 data_columns_duration: "2809889",
1476 timestamp_utc: "2023-11-05T06:25:09.000Z",
1477 syslog_type: AlertSourceSyslogType.Wazuh,
1478 process_name: "/bin/dd",
1479 process_cmd_line: "dd if=/dev/urandom bs=2 count=1",
1480 data_hostIdentifier: "ssdnodes-zabbix",
1481 data_columns_probe_error: "0",
1482 rule_description:
1483 "Adversaries may use binary padding to add junk data and change the on-disk representation of malware. This rule detect using dd and truncate to add a junk data to file.",
1484 gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38",
1485 id: "1699165511.370373429",
1486 rule_mitre_tactic: "Defense Evasion",
1487 process_image: "/bin/dd",
1488 gl2_accounted_message_size: 2736,
1489 data_columns_uid: "0",
1490 streams: ["6518f9c15e9a2d550c8a49f1"],
1491 rule_mitre_id: "T1027",
1492 gl2_message_id: "01HEF2GCTSQMHY4KKXANGM0WNP",
1493 agent_ip: "208.87.135.165",
1494 data_columns_gid: "0",
1495 data_columns_syscall: "exec",
1496 true: 1699165511.829736,
1497 data_columns_cid: "42132",
1498 rule_groups: "osquery, bpf_process_events",
1499 data_columns_exit_code: "0",
1500 process_id: "214456",
1501 agent_ip_geolocation: "-33.8715,151.2006",
1502 rule_mitre_technique: "Obfuscated Files or Information",
1503 rule_firedtimes: 1,
1504 rule_mail: true,
1505 data_name: "bpf_process_events",
1506 decoder_name: AlertSourceDecoderName.JSON,
1507 agent_ip_country_code: "AU",
1508 data_columns_ntime: "3024028081495260",
1509 syslog_level: AlertSourceSyslogLevel.Alert,
1510 timestamp: "2023-11-05 06:25:16.633",
1511 data_columns_cmdline: "dd if=/dev/urandom bs=2 count=1",
1512 data_columns_tid: "214456",
1513 gl2_processing_error:
1514 'Replaced invalid timestamp value in message <15d6dd81-7ba4-11ee-93bc-86000046278a> with current time - Value <2023-11-05T06:25:11.808+0000> caused exception: Invalid format: "2023-11-05T06:25:11.808+0000" is malformed at "T06:25:11.808+0000".',
1515 data_columns_pid: "214456",
1516 message:
1517 '{"true":1699165511.829736,"timestamp":"2023-11-05T06:25:11.808+0000","rule":{"level":12,"description":"Adversaries may use binary padding to add junk data and change the on-disk representation of malware. This rule detect using dd and truncate to add a junk data to file.","id":"200243","mitre":{"id":["T1027"],"tactic":["Defense Evasion"],"technique":["Obfuscated Files or Information"]},"firedtimes":1,"mail":true,"groups":["osquery","bpf_process_events"]},"agent":{"id":"077","name":"ssdnodes-zabbix","ip":"208.87.135.165","labels":{"customer":"toafb68l"}},"manager":{"name":"ASHWZHMA"},"id":"1699165511.370373429","decoder":{"name":"json"},"data":{"action":"added","name":"bpf_process_events","hostIdentifier":"ssdnodes-zabbix","calendarTime":"Sun Nov 5 06:25:09 2023 UTC","unixTime":"1699165509","epoch":"0","counter":"19295","numerics":"false","columns":{"cid":"42132","cmdline":"dd if=/dev/urandom bs=2 count=1","cwd":"/","duration":"2809889","exit_code":"0","gid":"0","ntime":"3024028081495260","parent":"214455","path":"/bin/dd","pid":"214456","probe_error":"0","syscall":"exec","tid":"214456","uid":"0"}},"location":"/var/log/osquery/osqueryd.results.log"}',
1518 data_numerics: "false",
1519 rule_id: "200243",
1520 manager_name: "ASHWZHMA",
1521 data_columns_path: "/bin/dd",
1522 data_unixTime: "1699165509",
1523 data_action: "added",
1524 data_epoch: "0",
1525 location: "/var/log/osquery/osqueryd.results.log",
1526 data_columns_parent: "214455",
1527 msg_timestamp: "2023-11-05T06:25:11.808Z",
1528 rule_group2: "bpf_process_events",
1529 rule_group1: "osquery"
1530 },
1531 sort: [1699165509000]
1532 },
1533 {
1534 _index: "wazuh-toafb68l_2",
1535 _id: "fd5fcbb2-7b83-11ee-93bc-86000046278a",
1536 _score: null,
1537 _source: {
1538 parent_process_id: "98528",
1539 source_reserved_ip: true,
1540 agent_id: "077",
1541 agent_name: "ssdnodes-zabbix",
1542 gl2_remote_ip: "10.255.255.13",
1543 gl2_remote_port: 54994,
1544 data_columns_cwd: "/tmp",
1545 agent_labels_customer: "toafb68l",
1546 agent_ip_city_name: "Sydney",
1547 source: "10.255.255.13",
1548 gl2_source_input: "6459151dea00fd5d3da2df91",
1549 rule_level: 12,
1550 data_calendarTime: "Sun Nov 5 02:35:28 2023 UTC",
1551 data_counter: "18098",
1552 data_columns_duration: "134246",
1553 timestamp_utc: "2023-11-05T02:35:28.000Z",
1554 syslog_type: AlertSourceSyslogType.Wazuh,
1555 process_name: "/usr/bin/chmod",
1556 process_cmd_line: "chmod +r /var/lib/update-notifier/updates-available",
1557 data_hostIdentifier: "ssdnodes-zabbix",
1558 data_columns_probe_error: "0",
1559 rule_description: "Detects file and folder permission changes.",
1560 gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38",
1561 id: "1699151730.117474775",
1562 rule_mitre_tactic: "Defense Evasion",
1563 process_image: "/usr/bin/chmod",
1564 gl2_accounted_message_size: 2594,
1565 data_columns_uid: "0",
1566 streams: ["6518f9c15e9a2d550c8a49f1"],
1567 rule_mitre_id: "T1222",
1568 gl2_message_id: "01HEENBPZC4ZK59R2RWMZ3AK9K",
1569 agent_ip: "208.87.135.165",
1570 data_columns_gid: "0",
1571 data_columns_syscall: "exec",
1572 true: 1699151730.737527,
1573 data_columns_cid: "66927",
1574 rule_groups: "osquery, bpf_process_events",
1575 data_columns_exit_code: "0",
1576 process_id: "98594",
1577 agent_ip_geolocation: "-33.8715,151.2006",
1578 rule_mitre_technique: "File and Directory Permissions Modification",
1579 rule_firedtimes: 1,
1580 rule_mail: true,
1581 data_name: "bpf_process_events",
1582 decoder_name: AlertSourceDecoderName.JSON,
1583 agent_ip_country_code: "AU",
1584 data_columns_ntime: "3010249590404014",
1585 syslog_level: AlertSourceSyslogLevel.Alert,
1586 timestamp: "2023-11-05 02:35:31.692",
1587 data_columns_cmdline: "chmod +r /var/lib/update-notifier/updates-available",
1588 data_columns_tid: "98594",
1589 gl2_processing_error:
1590 'Replaced invalid timestamp value in message <fd5fcbb2-7b83-11ee-93bc-86000046278a> with current time - Value <2023-11-05T02:35:30.736+0000> caused exception: Invalid format: "2023-11-05T02:35:30.736+0000" is malformed at "T02:35:30.736+0000".',
1591 data_columns_pid: "98594",
1592 message:
1593 '{"true":1699151730.737527,"timestamp":"2023-11-05T02:35:30.736+0000","rule":{"level":12,"description":"Detects file and folder permission changes.","id":"200259","mitre":{"id":["T1222"],"tactic":["Defense Evasion"],"technique":["File and Directory Permissions Modification"]},"firedtimes":1,"mail":true,"groups":["osquery","bpf_process_events"]},"agent":{"id":"077","name":"ssdnodes-zabbix","ip":"208.87.135.165","labels":{"customer":"toafb68l"}},"manager":{"name":"ASHWZHMA"},"id":"1699151730.117474775","decoder":{"name":"json"},"data":{"action":"added","name":"bpf_process_events","hostIdentifier":"ssdnodes-zabbix","calendarTime":"Sun Nov 5 02:35:28 2023 UTC","unixTime":"1699151728","epoch":"0","counter":"18098","numerics":"false","columns":{"cid":"66927","cmdline":"chmod +r /var/lib/update-notifier/updates-available","cwd":"/tmp","duration":"134246","exit_code":"0","gid":"0","ntime":"3010249590404014","parent":"98528","path":"/usr/bin/chmod","pid":"98594","probe_error":"0","syscall":"exec","tid":"98594","uid":"0"}},"location":"/var/log/osquery/osqueryd.results.log"}',
1594 data_numerics: "false",
1595 rule_id: "200259",
1596 manager_name: "ASHWZHMA",
1597 data_columns_path: "/usr/bin/chmod",
1598 data_unixTime: "1699151728",
1599 data_action: "added",
1600 data_epoch: "0",
1601 location: "/var/log/osquery/osqueryd.results.log",
1602 data_columns_parent: "98528",
1603 msg_timestamp: "2023-11-05T02:35:30.736Z",
1604 rule_group2: "bpf_process_events",
1605 rule_group1: "osquery"
1606 },
1607 sort: [1699151728000]
1608 }
1609 ]
1610 },
1611 {
1612 index_name: "wazuh-wso4vxhq_8",
1613 total_alerts: 5,
1614 alerts: [
1615 {
1616 _index: "wazuh-wso4vxhq_8",
1617 _id: "e1c93161-7bda-11ee-93bc-86000046278a",
1618 _score: null,
1619 _source: {
1620 source_reserved_ip: true,
1621 data_win_system_eventRecordID: "4882778",
1622 agent_id: "070",
1623 agent_name: "web1",
1624 data_win_eventdata_sourceProcessGUID: "{d9ab9ebb-7e1a-6544-44e0-010000003000}",
1625 gl2_remote_ip: "10.255.255.13",
1626 data_win_system_eventID: "10",
1627 gl2_remote_port: 57078,
1628 agent_labels_customer: "wso4vxhq",
1629 agent_ip_city_name: "N/A",
1630 source: "10.255.255.13",
1631 data_win_eventdata_targetImage: "C:\\\\Windows\\\\explorer.exe",
1632 gl2_source_input: "6459151dea00fd5d3da2df91",
1633 rule_level: 12,
1634 data_win_eventdata_sourceUser: "WEB1\\\\Administrator",
1635 data_win_system_task: "10",
1636 timestamp_utc: "2023-11-05T12:57:26.938Z",
1637 syslog_type: AlertSourceSyslogType.Wazuh,
1638 data_win_system_threadID: "5576",
1639 rule_description:
1640 "Explorer process was accessed by C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe, possible process injection",
1641 gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38",
1642 id: "1699189047.740504296",
1643 data_win_eventdata_grantedAccess: "0x40",
1644 data_win_eventdata_sourceImage:
1645 "C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe",
1646 rule_mitre_tactic: "Defense Evasion, Privilege Escalation",
1647 gl2_accounted_message_size: 11454,
1648 data_win_eventdata_utcTime: "2023-11-05 12:57:26.937",
1649 streams: ["650d3da25e9a2d550c6d6491"],
1650 rule_mitre_id: "T1055",
1651 gl2_message_id: "01HEFRYM77XPQT25DBE9HD17DT",
1652 data_win_system_computer: "web1",
1653 data_win_eventdata_ruleName: "technique_id=T1036,technique_name=Masquerading",
1654 agent_ip: "202.43.110.138",
1655 true: 1699189047.88765,
1656 rule_groups: "sysmon, sysmon_eid10_detections, windows",
1657 data_win_system_keywords: "0x8000000000000000",
1658 data_win_system_level: "4",
1659 data_win_eventdata_targetProcessGUID: "{d9ab9ebb-62bb-6547-601c-020000003000}",
1660 data_win_system_severityValue: AlertSourceDataWinSystemSeverityValue.Information,
1661 data_win_eventdata_targetUser: "WEB1\\\\Administrator",
1662 agent_ip_geolocation: "16.1667,107.8333",
1663 rule_mitre_technique: "Process Injection",
1664 rule_firedtimes: 86,
1665 data_win_system_systemTime: "2023-11-05T12:57:26.938209400Z",
1666 rule_mail: true,
1667 decoder_name: AlertSourceDecoderName.WindowsEventchannel,
1668 agent_ip_country_code: "VN",
1669 data_win_system_processID: "3468",
1670 data_win_system_channel: "Microsoft-Windows-Sysmon/Operational",
1671 syslog_level: AlertSourceSyslogLevel.Alert,
1672 data_win_system_providerName: "Microsoft-Windows-Sysmon",
1673 data_win_system_version: "3",
1674 data_win_system_providerGuid: "{5770385f-c22a-43e0-bf4c-06f5698ffbd9}",
1675 timestamp: "2023-11-05 12:57:31.623",
1676 data_win_eventdata_callTrace:
1677 "C:\\\\Windows\\\\SYSTEM32\\\\ntdll.dll+9ff24|C:\\\\Windows\\\\System32\\\\KERNELBASE.dll+1668e|C:\\\\Windows\\\\System32\\\\shcore.dll+cca8|C:\\\\Windows\\\\System32\\\\shcore.dll+ba62|C:\\\\Windows\\\\System32\\\\shcore.dll+b585|C:\\\\Windows\\\\System32\\\\shcore.dll+b275|C:\\\\Windows\\\\System32\\\\shcore.dll+b209|C:\\\\Windows\\\\System32\\\\shcore.dll+b104|C:\\\\Windows\\\\system32\\\\explorerframe.dll+12b986|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+157bd8c|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+18051ce|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2e1a17|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2dfdfe|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+130216a|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a566ec|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a5695f|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3e93b|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c40433|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb8e|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3d62541|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb68|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c942dd|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3db94|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a52491",
1678 data_win_system_opcode: "0",
1679 gl2_processing_error:
1680 'Replaced invalid timestamp value in message <e1c93161-7bda-11ee-93bc-86000046278a> with current time - Value <2023-11-05T12:57:27.609+0000> caused exception: Invalid format: "2023-11-05T12:57:27.609+0000" is malformed at "T12:57:27.609+0000".',
1681 data_win_eventdata_sourceProcessId: "1652",
1682 message:
1683 '{"true":1699189047.88765,"timestamp":"2023-11-05T12:57:27.609+0000","rule":{"level":12,"description":"Explorer process was accessed by C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe, possible process injection","id":"92910","mitre":{"id":["T1055"],"tactic":["Defense Evasion","Privilege Escalation"],"technique":["Process Injection"]},"firedtimes":86,"mail":true,"groups":["sysmon","sysmon_eid10_detections","windows"]},"agent":{"id":"070","name":"web1","ip":"202.43.110.138","labels":{"customer":"wso4vxhq"}},"manager":{"name":"ASHWZHMA"},"id":"1699189047.740504296","decoder":{"name":"windows_eventchannel"},"data":{"win":{"system":{"providerName":"Microsoft-Windows-Sysmon","providerGuid":"{5770385f-c22a-43e0-bf4c-06f5698ffbd9}","eventID":"10","version":"3","level":"4","task":"10","opcode":"0","keywords":"0x8000000000000000","systemTime":"2023-11-05T12:57:26.938209400Z","eventRecordID":"4882778","processID":"3468","threadID":"5576","channel":"Microsoft-Windows-Sysmon/Operational","computer":"web1","severityValue":"INFORMATION","message":"\\"Process accessed:\\r\\nRuleName: technique_id=T1036,technique_name=Masquerading\\r\\nUtcTime: 2023-11-05 12:57:26.937\\r\\nSourceProcessGUID: {d9ab9ebb-7e1a-6544-44e0-010000003000}\\r\\nSourceProcessId: 1652\\r\\nSourceThreadId: 1284\\r\\nSourceImage: C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe\\r\\nTargetProcessGUID: {d9ab9ebb-62bb-6547-601c-020000003000}\\r\\nTargetProcessId: 4384\\r\\nTargetImage: C:\\\\Windows\\\\explorer.exe\\r\\nGrantedAccess: 0x40\\r\\nCallTrace: C:\\\\Windows\\\\SYSTEM32\\\\ntdll.dll+9ff24|C:\\\\Windows\\\\System32\\\\KERNELBASE.dll+1668e|C:\\\\Windows\\\\System32\\\\shcore.dll+cca8|C:\\\\Windows\\\\System32\\\\shcore.dll+ba62|C:\\\\Windows\\\\System32\\\\shcore.dll+b585|C:\\\\Windows\\\\System32\\\\shcore.dll+b275|C:\\\\Windows\\\\System32\\\\shcore.dll+b209|C:\\\\Windows\\\\System32\\\\shcore.dll+b104|C:\\\\Windows\\\\system32\\\\explorerframe.dll+12b986|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+157bd8c|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+18051ce|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2e1a17|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2dfdfe|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+130216a|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a566ec|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a5695f|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3e93b|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c40433|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb8e|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3d62541|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb68|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c942dd|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3db94|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a52491\\r\\nSourceUser: WEB1\\\\Administrator\\r\\nTargetUser: WEB1\\\\Administrator\\""},"eventdata":{"ruleName":"technique_id=T1036,technique_name=Masquerading","utcTime":"2023-11-05 12:57:26.937","sourceProcessGUID":"{d9ab9ebb-7e1a-6544-44e0-010000003000}","sourceProcessId":"1652","sourceThreadId":"1284","sourceImage":"C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe","targetProcessGUID":"{d9ab9ebb-62bb-6547-601c-020000003000}","targetProcessId":"4384","targetImage":"C:\\\\\\\\Windows\\\\\\\\explorer.exe","grantedAccess":"0x40","callTrace":"C:\\\\\\\\Windows\\\\\\\\SYSTEM32\\\\\\\\ntdll.dll+9ff24|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\KERNELBASE.dll+1668e|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+cca8|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+ba62|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+b585|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+b275|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+b209|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+b104|C:\\\\\\\\Windows\\\\\\\\system32\\\\\\\\explorerframe.dll+12b986|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+157bd8c|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+18051ce|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+2e1a17|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+2dfdfe|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+130216a|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+a566ec|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+a5695f|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c3e93b|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c40433|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3fbdb8e|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3d62541|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3fbdb68|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c942dd|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c3db94|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+a52491","sourceUser":"WEB1\\\\\\\\Administrator","targetUser":"WEB1\\\\\\\\Administrator"}}},"location":"EventChannel"}',
1684 rule_id: "92910",
1685 manager_name: "ASHWZHMA",
1686 location: "EventChannel",
1687 data_win_eventdata_targetProcessId: "4384",
1688 rule_group3: AlertSourceDataLogsourceProduct.Windows,
1689 data_win_system_message:
1690 '"Process accessed:\r\nRuleName: technique_id=T1036,technique_name=Masquerading\r\nUtcTime: 2023-11-05 12:57:26.937\r\nSourceProcessGUID: {d9ab9ebb-7e1a-6544-44e0-010000003000}\r\nSourceProcessId: 1652\r\nSourceThreadId: 1284\r\nSourceImage: C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe\r\nTargetProcessGUID: {d9ab9ebb-62bb-6547-601c-020000003000}\r\nTargetProcessId: 4384\r\nTargetImage: C:\\Windows\\explorer.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+9ff24|C:\\Windows\\System32\\KERNELBASE.dll+1668e|C:\\Windows\\System32\\shcore.dll+cca8|C:\\Windows\\System32\\shcore.dll+ba62|C:\\Windows\\System32\\shcore.dll+b585|C:\\Windows\\System32\\shcore.dll+b275|C:\\Windows\\System32\\shcore.dll+b209|C:\\Windows\\System32\\shcore.dll+b104|C:\\Windows\\system32\\explorerframe.dll+12b986|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+157bd8c|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+18051ce|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+2e1a17|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+2dfdfe|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+130216a|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+a566ec|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+a5695f|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c3e93b|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c40433|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3fbdb8e|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3d62541|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3fbdb68|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c942dd|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c3db94|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+a52491\r\nSourceUser: WEB1\\Administrator\r\nTargetUser: WEB1\\Administrator"',
1691 data_win_eventdata_sourceThreadId: "1284",
1692 msg_timestamp: "2023-11-05T12:57:27.609Z",
1693 rule_group2: "sysmon_eid10_detections",
1694 rule_group1: "sysmon"
1695 },
1696 sort: [1699189046938]
1697 },
1698 {
1699 _index: "wazuh-wso4vxhq_8",
1700 _id: "e1c97f73-7bda-11ee-93bc-86000046278a",
1701 _score: null,
1702 _source: {
1703 source_reserved_ip: true,
1704 data_win_system_eventRecordID: "4882779",
1705 agent_id: "070",
1706 agent_name: "web1",
1707 data_win_eventdata_sourceProcessGUID: "{d9ab9ebb-7e1a-6544-44e0-010000003000}",
1708 gl2_remote_ip: "10.255.255.13",
1709 data_win_system_eventID: "10",
1710 gl2_remote_port: 57078,
1711 agent_labels_customer: "wso4vxhq",
1712 agent_ip_city_name: "N/A",
1713 source: "10.255.255.13",
1714 data_win_eventdata_targetImage: "C:\\\\Windows\\\\explorer.exe",
1715 gl2_source_input: "6459151dea00fd5d3da2df91",
1716 rule_level: 12,
1717 data_win_eventdata_sourceUser: "WEB1\\\\Administrator",
1718 data_win_system_task: "10",
1719 timestamp_utc: "2023-11-05T12:57:26.938Z",
1720 syslog_type: AlertSourceSyslogType.Wazuh,
1721 data_win_system_threadID: "5576",
1722 rule_description:
1723 "Explorer process was accessed by C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe, possible process injection",
1724 gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38",
1725 id: "1699189047.740509955",
1726 data_win_eventdata_grantedAccess: "0x40",
1727 data_win_eventdata_sourceImage:
1728 "C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe",
1729 rule_mitre_tactic: "Defense Evasion, Privilege Escalation",
1730 gl2_accounted_message_size: 11630,
1731 data_win_eventdata_utcTime: "2023-11-05 12:57:26.937",
1732 streams: ["650d3da25e9a2d550c6d6491"],
1733 rule_mitre_id: "T1055",
1734 gl2_message_id: "01HEFRYM78C4GA33W2VN2H1WWS",
1735 data_win_system_computer: "web1",
1736 data_win_eventdata_ruleName: "technique_id=T1036,technique_name=Masquerading",
1737 agent_ip: "202.43.110.138",
1738 true: 1699189048.147682,
1739 rule_groups: "sysmon, sysmon_eid10_detections, windows",
1740 data_win_system_keywords: "0x8000000000000000",
1741 data_win_system_level: "4",
1742 data_win_eventdata_targetProcessGUID: "{d9ab9ebb-62bb-6547-601c-020000003000}",
1743 data_win_system_severityValue: AlertSourceDataWinSystemSeverityValue.Information,
1744 data_win_eventdata_targetUser: "WEB1\\\\Administrator",
1745 agent_ip_geolocation: "16.1667,107.8333",
1746 rule_mitre_technique: "Process Injection",
1747 rule_firedtimes: 87,
1748 data_win_system_systemTime: "2023-11-05T12:57:26.938692200Z",
1749 rule_mail: true,
1750 decoder_name: AlertSourceDecoderName.WindowsEventchannel,
1751 agent_ip_country_code: "VN",
1752 data_win_system_processID: "3468",
1753 data_win_system_channel: "Microsoft-Windows-Sysmon/Operational",
1754 syslog_level: AlertSourceSyslogLevel.Alert,
1755 data_win_system_providerName: "Microsoft-Windows-Sysmon",
1756 data_win_system_version: "3",
1757 data_win_system_providerGuid: "{5770385f-c22a-43e0-bf4c-06f5698ffbd9}",
1758 timestamp: "2023-11-05 12:57:31.624",
1759 data_win_eventdata_callTrace:
1760 "C:\\\\Windows\\\\SYSTEM32\\\\ntdll.dll+9ff24|C:\\\\Windows\\\\System32\\\\KERNELBASE.dll+1668e|C:\\\\Windows\\\\System32\\\\shcore.dll+cca8|C:\\\\Windows\\\\System32\\\\shcore.dll+ba77|C:\\\\Windows\\\\System32\\\\shcore.dll+b967|C:\\\\Windows\\\\System32\\\\shcore.dll+b8f1|C:\\\\Windows\\\\System32\\\\shcore.dll+b61a|C:\\\\Windows\\\\system32\\\\explorerframe.dll+12b9d0|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+157bd8c|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+18051ce|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2e1a17|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2dfdfe|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+130216a|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a566ec|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a5695f|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3e93b|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c40433|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb8e|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3d62541|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb68|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c942dd|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3db94|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a52491|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a3e4a9",
1761 data_win_system_opcode: "0",
1762 gl2_processing_error:
1763 'Replaced invalid timestamp value in message <e1c97f73-7bda-11ee-93bc-86000046278a> with current time - Value <2023-11-05T12:57:27.886+0000> caused exception: Invalid format: "2023-11-05T12:57:27.886+0000" is malformed at "T12:57:27.886+0000".',
1764 data_win_eventdata_sourceProcessId: "1652",
1765 message:
1766 '{"true":1699189048.147682,"timestamp":"2023-11-05T12:57:27.886+0000","rule":{"level":12,"description":"Explorer process was accessed by C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe, possible process injection","id":"92910","mitre":{"id":["T1055"],"tactic":["Defense Evasion","Privilege Escalation"],"technique":["Process Injection"]},"firedtimes":87,"mail":true,"groups":["sysmon","sysmon_eid10_detections","windows"]},"agent":{"id":"070","name":"web1","ip":"202.43.110.138","labels":{"customer":"wso4vxhq"}},"manager":{"name":"ASHWZHMA"},"id":"1699189047.740509955","decoder":{"name":"windows_eventchannel"},"data":{"win":{"system":{"providerName":"Microsoft-Windows-Sysmon","providerGuid":"{5770385f-c22a-43e0-bf4c-06f5698ffbd9}","eventID":"10","version":"3","level":"4","task":"10","opcode":"0","keywords":"0x8000000000000000","systemTime":"2023-11-05T12:57:26.938692200Z","eventRecordID":"4882779","processID":"3468","threadID":"5576","channel":"Microsoft-Windows-Sysmon/Operational","computer":"web1","severityValue":"INFORMATION","message":"\\"Process accessed:\\r\\nRuleName: technique_id=T1036,technique_name=Masquerading\\r\\nUtcTime: 2023-11-05 12:57:26.937\\r\\nSourceProcessGUID: {d9ab9ebb-7e1a-6544-44e0-010000003000}\\r\\nSourceProcessId: 1652\\r\\nSourceThreadId: 1284\\r\\nSourceImage: C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe\\r\\nTargetProcessGUID: {d9ab9ebb-62bb-6547-601c-020000003000}\\r\\nTargetProcessId: 4384\\r\\nTargetImage: C:\\\\Windows\\\\explorer.exe\\r\\nGrantedAccess: 0x40\\r\\nCallTrace: C:\\\\Windows\\\\SYSTEM32\\\\ntdll.dll+9ff24|C:\\\\Windows\\\\System32\\\\KERNELBASE.dll+1668e|C:\\\\Windows\\\\System32\\\\shcore.dll+cca8|C:\\\\Windows\\\\System32\\\\shcore.dll+ba77|C:\\\\Windows\\\\System32\\\\shcore.dll+b967|C:\\\\Windows\\\\System32\\\\shcore.dll+b8f1|C:\\\\Windows\\\\System32\\\\shcore.dll+b61a|C:\\\\Windows\\\\system32\\\\explorerframe.dll+12b9d0|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+157bd8c|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+18051ce|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2e1a17|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2dfdfe|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+130216a|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a566ec|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a5695f|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3e93b|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c40433|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb8e|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3d62541|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb68|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c942dd|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3db94|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a52491|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a3e4a9\\r\\nSourceUser: WEB1\\\\Administrator\\r\\nTargetUser: WEB1\\\\Administrator\\""},"eventdata":{"ruleName":"technique_id=T1036,technique_name=Masquerading","utcTime":"2023-11-05 12:57:26.937","sourceProcessGUID":"{d9ab9ebb-7e1a-6544-44e0-010000003000}","sourceProcessId":"1652","sourceThreadId":"1284","sourceImage":"C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe","targetProcessGUID":"{d9ab9ebb-62bb-6547-601c-020000003000}","targetProcessId":"4384","targetImage":"C:\\\\\\\\Windows\\\\\\\\explorer.exe","grantedAccess":"0x40","callTrace":"C:\\\\\\\\Windows\\\\\\\\SYSTEM32\\\\\\\\ntdll.dll+9ff24|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\KERNELBASE.dll+1668e|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+cca8|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+ba77|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+b967|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+b8f1|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+b61a|C:\\\\\\\\Windows\\\\\\\\system32\\\\\\\\explorerframe.dll+12b9d0|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+157bd8c|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+18051ce|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+2e1a17|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+2dfdfe|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+130216a|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+a566ec|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+a5695f|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c3e93b|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c40433|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3fbdb8e|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3d62541|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3fbdb68|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c942dd|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c3db94|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+a52491|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+a3e4a9","sourceUser":"WEB1\\\\\\\\Administrator","targetUser":"WEB1\\\\\\\\Administrator"}}},"location":"EventChannel"}',
1767 rule_id: "92910",
1768 manager_name: "ASHWZHMA",
1769 location: "EventChannel",
1770 data_win_eventdata_targetProcessId: "4384",
1771 rule_group3: AlertSourceDataLogsourceProduct.Windows,
1772 data_win_system_message:
1773 '"Process accessed:\r\nRuleName: technique_id=T1036,technique_name=Masquerading\r\nUtcTime: 2023-11-05 12:57:26.937\r\nSourceProcessGUID: {d9ab9ebb-7e1a-6544-44e0-010000003000}\r\nSourceProcessId: 1652\r\nSourceThreadId: 1284\r\nSourceImage: C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe\r\nTargetProcessGUID: {d9ab9ebb-62bb-6547-601c-020000003000}\r\nTargetProcessId: 4384\r\nTargetImage: C:\\Windows\\explorer.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+9ff24|C:\\Windows\\System32\\KERNELBASE.dll+1668e|C:\\Windows\\System32\\shcore.dll+cca8|C:\\Windows\\System32\\shcore.dll+ba77|C:\\Windows\\System32\\shcore.dll+b967|C:\\Windows\\System32\\shcore.dll+b8f1|C:\\Windows\\System32\\shcore.dll+b61a|C:\\Windows\\system32\\explorerframe.dll+12b9d0|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+157bd8c|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+18051ce|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+2e1a17|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+2dfdfe|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+130216a|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+a566ec|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+a5695f|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c3e93b|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c40433|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3fbdb8e|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3d62541|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3fbdb68|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c942dd|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c3db94|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+a52491|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+a3e4a9\r\nSourceUser: WEB1\\Administrator\r\nTargetUser: WEB1\\Administrator"',
1774 data_win_eventdata_sourceThreadId: "1284",
1775 msg_timestamp: "2023-11-05T12:57:27.886Z",
1776 rule_group2: "sysmon_eid10_detections",
1777 rule_group1: "sysmon"
1778 },
1779 sort: [1699189046938]
1780 },
1781 {
1782 _index: "wazuh-wso4vxhq_8",
1783 _id: "e1c93160-7bda-11ee-93bc-86000046278a",
1784 _score: null,
1785 _source: {
1786 source_reserved_ip: true,
1787 data_win_system_eventRecordID: "4882777",
1788 agent_id: "070",
1789 agent_name: "web1",
1790 data_win_eventdata_sourceProcessGUID: "{d9ab9ebb-7e1a-6544-44e0-010000003000}",
1791 gl2_remote_ip: "10.255.255.13",
1792 data_win_system_eventID: "10",
1793 gl2_remote_port: 57078,
1794 agent_labels_customer: "wso4vxhq",
1795 agent_ip_city_name: "N/A",
1796 source: "10.255.255.13",
1797 data_win_eventdata_targetImage: "C:\\\\Windows\\\\explorer.exe",
1798 gl2_source_input: "6459151dea00fd5d3da2df91",
1799 rule_level: 12,
1800 data_win_eventdata_sourceUser: "WEB1\\\\Administrator",
1801 data_win_system_task: "10",
1802 timestamp_utc: "2023-11-05T12:57:26.937Z",
1803 syslog_type: AlertSourceSyslogType.Wazuh,
1804 data_win_system_threadID: "5576",
1805 rule_description:
1806 "Explorer process was accessed by C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe, possible process injection",
1807 gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38",
1808 id: "1699189047.740498545",
1809 data_win_eventdata_grantedAccess: "0x40",
1810 data_win_eventdata_sourceImage:
1811 "C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe",
1812 rule_mitre_tactic: "Defense Evasion, Privilege Escalation",
1813 gl2_accounted_message_size: 11630,
1814 data_win_eventdata_utcTime: "2023-11-05 12:57:26.937",
1815 streams: ["650d3da25e9a2d550c6d6491"],
1816 rule_mitre_id: "T1055",
1817 gl2_message_id: "01HEFRYM7700MP8Y22100S2SEW",
1818 data_win_system_computer: "web1",
1819 data_win_eventdata_ruleName: "technique_id=T1036,technique_name=Masquerading",
1820 agent_ip: "202.43.110.138",
1821 true: 1699189047.610539,
1822 rule_groups: "sysmon, sysmon_eid10_detections, windows",
1823 data_win_system_keywords: "0x8000000000000000",
1824 data_win_system_level: "4",
1825 data_win_eventdata_targetProcessGUID: "{d9ab9ebb-62bb-6547-601c-020000003000}",
1826 data_win_system_severityValue: AlertSourceDataWinSystemSeverityValue.Information,
1827 data_win_eventdata_targetUser: "WEB1\\\\Administrator",
1828 agent_ip_geolocation: "16.1667,107.8333",
1829 rule_mitre_technique: "Process Injection",
1830 rule_firedtimes: 85,
1831 data_win_system_systemTime: "2023-11-05T12:57:26.937850100Z",
1832 rule_mail: true,
1833 decoder_name: AlertSourceDecoderName.WindowsEventchannel,
1834 agent_ip_country_code: "VN",
1835 data_win_system_processID: "3468",
1836 data_win_system_channel: "Microsoft-Windows-Sysmon/Operational",
1837 syslog_level: AlertSourceSyslogLevel.Alert,
1838 data_win_system_providerName: "Microsoft-Windows-Sysmon",
1839 data_win_system_version: "3",
1840 data_win_system_providerGuid: "{5770385f-c22a-43e0-bf4c-06f5698ffbd9}",
1841 timestamp: "2023-11-05 12:57:31.623",
1842 data_win_eventdata_callTrace:
1843 "C:\\\\Windows\\\\SYSTEM32\\\\ntdll.dll+9ff24|C:\\\\Windows\\\\System32\\\\KERNELBASE.dll+1668e|C:\\\\Windows\\\\System32\\\\shcore.dll+cca8|C:\\\\Windows\\\\System32\\\\shcore.dll+b55c|C:\\\\Windows\\\\System32\\\\shcore.dll+b275|C:\\\\Windows\\\\System32\\\\shcore.dll+b209|C:\\\\Windows\\\\System32\\\\shcore.dll+b104|C:\\\\Windows\\\\system32\\\\explorerframe.dll+12b986|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+157bd8c|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+18051ce|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2e1a17|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2dfdfe|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+130216a|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a566ec|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a5695f|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3e93b|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c40433|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb8e|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3d62541|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb68|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c942dd|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3db94|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a52491|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a3e4a9",
1844 data_win_system_opcode: "0",
1845 gl2_processing_error:
1846 'Replaced invalid timestamp value in message <e1c93160-7bda-11ee-93bc-86000046278a> with current time - Value <2023-11-05T12:57:27.609+0000> caused exception: Invalid format: "2023-11-05T12:57:27.609+0000" is malformed at "T12:57:27.609+0000".',
1847 data_win_eventdata_sourceProcessId: "1652",
1848 message:
1849 '{"true":1699189047.610539,"timestamp":"2023-11-05T12:57:27.609+0000","rule":{"level":12,"description":"Explorer process was accessed by C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe, possible process injection","id":"92910","mitre":{"id":["T1055"],"tactic":["Defense Evasion","Privilege Escalation"],"technique":["Process Injection"]},"firedtimes":85,"mail":true,"groups":["sysmon","sysmon_eid10_detections","windows"]},"agent":{"id":"070","name":"web1","ip":"202.43.110.138","labels":{"customer":"wso4vxhq"}},"manager":{"name":"ASHWZHMA"},"id":"1699189047.740498545","decoder":{"name":"windows_eventchannel"},"data":{"win":{"system":{"providerName":"Microsoft-Windows-Sysmon","providerGuid":"{5770385f-c22a-43e0-bf4c-06f5698ffbd9}","eventID":"10","version":"3","level":"4","task":"10","opcode":"0","keywords":"0x8000000000000000","systemTime":"2023-11-05T12:57:26.937850100Z","eventRecordID":"4882777","processID":"3468","threadID":"5576","channel":"Microsoft-Windows-Sysmon/Operational","computer":"web1","severityValue":"INFORMATION","message":"\\"Process accessed:\\r\\nRuleName: technique_id=T1036,technique_name=Masquerading\\r\\nUtcTime: 2023-11-05 12:57:26.937\\r\\nSourceProcessGUID: {d9ab9ebb-7e1a-6544-44e0-010000003000}\\r\\nSourceProcessId: 1652\\r\\nSourceThreadId: 1284\\r\\nSourceImage: C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe\\r\\nTargetProcessGUID: {d9ab9ebb-62bb-6547-601c-020000003000}\\r\\nTargetProcessId: 4384\\r\\nTargetImage: C:\\\\Windows\\\\explorer.exe\\r\\nGrantedAccess: 0x40\\r\\nCallTrace: C:\\\\Windows\\\\SYSTEM32\\\\ntdll.dll+9ff24|C:\\\\Windows\\\\System32\\\\KERNELBASE.dll+1668e|C:\\\\Windows\\\\System32\\\\shcore.dll+cca8|C:\\\\Windows\\\\System32\\\\shcore.dll+b55c|C:\\\\Windows\\\\System32\\\\shcore.dll+b275|C:\\\\Windows\\\\System32\\\\shcore.dll+b209|C:\\\\Windows\\\\System32\\\\shcore.dll+b104|C:\\\\Windows\\\\system32\\\\explorerframe.dll+12b986|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+157bd8c|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+18051ce|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2e1a17|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+2dfdfe|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+130216a|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a566ec|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a5695f|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3e93b|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c40433|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb8e|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3d62541|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3fbdb68|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c942dd|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+3c3db94|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a52491|C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe+a3e4a9\\r\\nSourceUser: WEB1\\\\Administrator\\r\\nTargetUser: WEB1\\\\Administrator\\""},"eventdata":{"ruleName":"technique_id=T1036,technique_name=Masquerading","utcTime":"2023-11-05 12:57:26.937","sourceProcessGUID":"{d9ab9ebb-7e1a-6544-44e0-010000003000}","sourceProcessId":"1652","sourceThreadId":"1284","sourceImage":"C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe","targetProcessGUID":"{d9ab9ebb-62bb-6547-601c-020000003000}","targetProcessId":"4384","targetImage":"C:\\\\\\\\Windows\\\\\\\\explorer.exe","grantedAccess":"0x40","callTrace":"C:\\\\\\\\Windows\\\\\\\\SYSTEM32\\\\\\\\ntdll.dll+9ff24|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\KERNELBASE.dll+1668e|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+cca8|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+b55c|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+b275|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+b209|C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\shcore.dll+b104|C:\\\\\\\\Windows\\\\\\\\system32\\\\\\\\explorerframe.dll+12b986|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+157bd8c|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+18051ce|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+2e1a17|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+2dfdfe|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+130216a|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+a566ec|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+a5695f|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c3e93b|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c40433|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3fbdb8e|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3d62541|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3fbdb68|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c942dd|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+3c3db94|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+a52491|C:\\\\\\\\Users\\\\\\\\Administrator\\\\\\\\AppData\\\\\\\\Roaming\\\\\\\\Telegram Desktop\\\\\\\\Telegram.exe+a3e4a9","sourceUser":"WEB1\\\\\\\\Administrator","targetUser":"WEB1\\\\\\\\Administrator"}}},"location":"EventChannel"}',
1850 rule_id: "92910",
1851 manager_name: "ASHWZHMA",
1852 location: "EventChannel",
1853 data_win_eventdata_targetProcessId: "4384",
1854 rule_group3: AlertSourceDataLogsourceProduct.Windows,
1855 data_win_system_message:
1856 '"Process accessed:\r\nRuleName: technique_id=T1036,technique_name=Masquerading\r\nUtcTime: 2023-11-05 12:57:26.937\r\nSourceProcessGUID: {d9ab9ebb-7e1a-6544-44e0-010000003000}\r\nSourceProcessId: 1652\r\nSourceThreadId: 1284\r\nSourceImage: C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe\r\nTargetProcessGUID: {d9ab9ebb-62bb-6547-601c-020000003000}\r\nTargetProcessId: 4384\r\nTargetImage: C:\\Windows\\explorer.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+9ff24|C:\\Windows\\System32\\KERNELBASE.dll+1668e|C:\\Windows\\System32\\shcore.dll+cca8|C:\\Windows\\System32\\shcore.dll+b55c|C:\\Windows\\System32\\shcore.dll+b275|C:\\Windows\\System32\\shcore.dll+b209|C:\\Windows\\System32\\shcore.dll+b104|C:\\Windows\\system32\\explorerframe.dll+12b986|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+157bd8c|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+18051ce|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+2e1a17|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+2dfdfe|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+130216a|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+a566ec|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+a5695f|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c3e93b|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c40433|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3fbdb8e|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3d62541|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3fbdb68|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c942dd|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+3c3db94|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+a52491|C:\\Users\\Administrator\\AppData\\Roaming\\Telegram Desktop\\Telegram.exe+a3e4a9\r\nSourceUser: WEB1\\Administrator\r\nTargetUser: WEB1\\Administrator"',
1857 data_win_eventdata_sourceThreadId: "1284",
1858 msg_timestamp: "2023-11-05T12:57:27.609Z",
1859 rule_group2: "sysmon_eid10_detections",
1860 rule_group1: "sysmon"
1861 },
1862 sort: [1699189046937]
1863 },
1864 {
1865 _index: "wazuh-wso4vxhq_8",
1866 _id: "85668701-7bda-11ee-93bc-86000046278a",
1867 _score: null,
1868 _source: {
1869 data_win_eventdata_newThreadId: "10040",
1870 source_reserved_ip: true,
1871 data_win_system_eventRecordID: "4882503",
1872 agent_id: "070",
1873 agent_name: "web1",
1874 gl2_remote_ip: "10.255.255.13",
1875 data_win_system_eventID: "8",
1876 gl2_remote_port: 48272,
1877 agent_labels_customer: "wso4vxhq",
1878 agent_ip_city_name: "N/A",
1879 source: "10.255.255.13",
1880 data_win_eventdata_targetImage: "C:\\\\Windows\\\\explorer.exe",
1881 gl2_source_input: "6459151dea00fd5d3da2df91",
1882 rule_level: 12,
1883 data_win_eventdata_sourceUser: "NT AUTHORITY\\\\SYSTEM",
1884 data_win_system_task: "8",
1885 timestamp_utc: "2023-11-05T12:54:51.363Z",
1886 syslog_type: AlertSourceSyslogType.Wazuh,
1887 data_win_system_threadID: "5576",
1888 rule_description:
1889 "Possible code injection on explorer.exe by C:\\\\Program Files\\\\VMware\\\\VMware Tools\\\\vmtoolsd.exe",
1890 gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38",
1891 id: "1699188892.737055402",
1892 data_win_eventdata_sourceImage: "C:\\\\Program Files\\\\VMware\\\\VMware Tools\\\\vmtoolsd.exe",
1893 rule_mitre_tactic: "Defense Evasion, Privilege Escalation",
1894 data_win_eventdata_targetProcessGuid: "{d9ab9ebb-62bb-6547-601c-020000003000}",
1895 gl2_accounted_message_size: 5134,
1896 data_win_eventdata_utcTime: "2023-11-05 12:54:51.363",
1897 streams: ["650d3da25e9a2d550c6d6491"],
1898 rule_mitre_id: "T1055",
1899 gl2_message_id: "01HEFRSWVHDK18DFBYAWFFH0Q5",
1900 data_win_system_computer: "web1",
1901 data_win_eventdata_ruleName: "technique_id=T1055,technique_name=Process Injection",
1902 agent_ip: "202.43.110.138",
1903 data_win_eventdata_startAddress: "0x00007FFDE5CCE720",
1904 true: 1699188892.065792,
1905 rule_groups: "sysmon, sysmon_eid8_detections, windows",
1906 data_win_system_keywords: "0x8000000000000000",
1907 data_win_system_level: "4",
1908 data_win_system_severityValue: AlertSourceDataWinSystemSeverityValue.Information,
1909 data_win_eventdata_targetUser: "WEB1\\\\Administrator",
1910 agent_ip_geolocation: "16.1667,107.8333",
1911 rule_mitre_technique: "Process Injection",
1912 rule_firedtimes: 2,
1913 data_win_system_systemTime: "2023-11-05T12:54:51.363981300Z",
1914 rule_mail: true,
1915 decoder_name: AlertSourceDecoderName.WindowsEventchannel,
1916 agent_ip_country_code: "VN",
1917 data_win_system_processID: "3468",
1918 data_win_system_channel: "Microsoft-Windows-Sysmon/Operational",
1919 syslog_level: AlertSourceSyslogLevel.Alert,
1920 data_win_system_providerName: "Microsoft-Windows-Sysmon",
1921 data_win_system_version: "2",
1922 data_win_system_providerGuid: "{5770385f-c22a-43e0-bf4c-06f5698ffbd9}",
1923 timestamp: "2023-11-05 12:54:56.625",
1924 data_win_system_opcode: "0",
1925 gl2_processing_error:
1926 'Replaced invalid timestamp value in message <85668701-7bda-11ee-93bc-86000046278a> with current time - Value <2023-11-05T12:54:52.014+0000> caused exception: Invalid format: "2023-11-05T12:54:52.014+0000" is malformed at "T12:54:52.014+0000".',
1927 data_win_eventdata_sourceProcessId: "3368",
1928 data_win_eventdata_startModule: "C:\\\\Windows\\\\System32\\\\KERNEL32.DLL",
1929 message:
1930 '{"true":1699188892.065792,"timestamp":"2023-11-05T12:54:52.014+0000","rule":{"level":12,"description":"Possible code injection on explorer.exe by C:\\\\\\\\Program Files\\\\\\\\VMware\\\\\\\\VMware Tools\\\\\\\\vmtoolsd.exe","id":"92400","mitre":{"id":["T1055"],"tactic":["Defense Evasion","Privilege Escalation"],"technique":["Process Injection"]},"firedtimes":2,"mail":true,"groups":["sysmon","sysmon_eid8_detections","windows"]},"agent":{"id":"070","name":"web1","ip":"202.43.110.138","labels":{"customer":"wso4vxhq"}},"manager":{"name":"ASHWZHMA"},"id":"1699188892.737055402","decoder":{"name":"windows_eventchannel"},"data":{"win":{"system":{"providerName":"Microsoft-Windows-Sysmon","providerGuid":"{5770385f-c22a-43e0-bf4c-06f5698ffbd9}","eventID":"8","version":"2","level":"4","task":"8","opcode":"0","keywords":"0x8000000000000000","systemTime":"2023-11-05T12:54:51.363981300Z","eventRecordID":"4882503","processID":"3468","threadID":"5576","channel":"Microsoft-Windows-Sysmon/Operational","computer":"web1","severityValue":"INFORMATION","message":"\\"CreateRemoteThread detected:\\r\\nRuleName: technique_id=T1055,technique_name=Process Injection\\r\\nUtcTime: 2023-11-05 12:54:51.363\\r\\nSourceProcessGuid: {d9ab9ebb-48da-652f-4900-000000003000}\\r\\nSourceProcessId: 3368\\r\\nSourceImage: C:\\\\Program Files\\\\VMware\\\\VMware Tools\\\\vmtoolsd.exe\\r\\nTargetProcessGuid: {d9ab9ebb-62bb-6547-601c-020000003000}\\r\\nTargetProcessId: 4384\\r\\nTargetImage: C:\\\\Windows\\\\explorer.exe\\r\\nNewThreadId: 10040\\r\\nStartAddress: 0x00007FFDE5CCE720\\r\\nStartModule: C:\\\\Windows\\\\System32\\\\KERNEL32.DLL\\r\\nStartFunction: GetCommandLineW\\r\\nSourceUser: NT AUTHORITY\\\\SYSTEM\\r\\nTargetUser: WEB1\\\\Administrator\\""},"eventdata":{"ruleName":"technique_id=T1055,technique_name=Process Injection","utcTime":"2023-11-05 12:54:51.363","sourceProcessGuid":"{d9ab9ebb-48da-652f-4900-000000003000}","sourceProcessId":"3368","sourceImage":"C:\\\\\\\\Program Files\\\\\\\\VMware\\\\\\\\VMware Tools\\\\\\\\vmtoolsd.exe","targetProcessGuid":"{d9ab9ebb-62bb-6547-601c-020000003000}","targetProcessId":"4384","targetImage":"C:\\\\\\\\Windows\\\\\\\\explorer.exe","newThreadId":"10040","startAddress":"0x00007FFDE5CCE720","startModule":"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\KERNEL32.DLL","startFunction":"GetCommandLineW","sourceUser":"NT AUTHORITY\\\\\\\\SYSTEM","targetUser":"WEB1\\\\\\\\Administrator"}}},"location":"EventChannel"}',
1931 rule_id: "92400",
1932 manager_name: "ASHWZHMA",
1933 data_win_eventdata_sourceProcessGuid: "{d9ab9ebb-48da-652f-4900-000000003000}",
1934 location: "EventChannel",
1935 data_win_eventdata_targetProcessId: "4384",
1936 data_win_eventdata_startFunction: "GetCommandLineW",
1937 rule_group3: AlertSourceDataLogsourceProduct.Windows,
1938 data_win_system_message:
1939 '"CreateRemoteThread detected:\r\nRuleName: technique_id=T1055,technique_name=Process Injection\r\nUtcTime: 2023-11-05 12:54:51.363\r\nSourceProcessGuid: {d9ab9ebb-48da-652f-4900-000000003000}\r\nSourceProcessId: 3368\r\nSourceImage: C:\\Program Files\\VMware\\VMware Tools\\vmtoolsd.exe\r\nTargetProcessGuid: {d9ab9ebb-62bb-6547-601c-020000003000}\r\nTargetProcessId: 4384\r\nTargetImage: C:\\Windows\\explorer.exe\r\nNewThreadId: 10040\r\nStartAddress: 0x00007FFDE5CCE720\r\nStartModule: C:\\Windows\\System32\\KERNEL32.DLL\r\nStartFunction: GetCommandLineW\r\nSourceUser: NT AUTHORITY\\SYSTEM\r\nTargetUser: WEB1\\Administrator"',
1940 msg_timestamp: "2023-11-05T12:54:52.014Z",
1941 rule_group2: "sysmon_eid8_detections",
1942 rule_group1: "sysmon"
1943 },
1944 sort: [1699188891363]
1945 },
1946 {
1947 _index: "wazuh-wso4vxhq_8",
1948 _id: "797bfd81-7bda-11ee-93bc-86000046278a",
1949 _score: null,
1950 _source: {
1951 data_win_eventdata_newThreadId: "13164",
1952 source_reserved_ip: true,
1953 data_win_system_eventRecordID: "4882339",
1954 agent_id: "070",
1955 agent_name: "web1",
1956 gl2_remote_ip: "10.255.255.13",
1957 data_win_system_eventID: "8",
1958 gl2_remote_port: 44978,
1959 agent_labels_customer: "wso4vxhq",
1960 agent_ip_city_name: "N/A",
1961 source: "10.255.255.13",
1962 data_win_eventdata_targetImage: "C:\\\\Windows\\\\System32\\\\lsass.exe",
1963 gl2_source_input: "6459151dea00fd5d3da2df91",
1964 rule_level: 12,
1965 data_win_eventdata_sourceUser: "NT AUTHORITY\\\\SYSTEM",
1966 data_win_system_task: "8",
1967 timestamp_utc: "2023-11-05T12:54:32.314Z",
1968 syslog_type: AlertSourceSyslogType.Wazuh,
1969 data_win_system_threadID: "5576",
1970 rule_description:
1971 "Local Security Authority Subsystem Service (LSASS) process was accessed by C:\\\\Program Files\\\\VMware\\\\VMware Tools\\\\vmtoolsd.exe, possible code injection for credential dumping",
1972 gl2_source_node: "809d9894-1865-4ac7-8204-3226c347cb38",
1973 id: "1699188873.736407303",
1974 data_win_eventdata_sourceImage: "C:\\\\Program Files\\\\VMware\\\\VMware Tools\\\\vmtoolsd.exe",
1975 rule_mitre_tactic: "Defense Evasion, Privilege Escalation",
1976 data_win_eventdata_targetProcessGuid: "{d9ab9ebb-48d7-652f-0c00-000000003000}",
1977 gl2_accounted_message_size: 5323,
1978 data_win_eventdata_utcTime: "2023-11-05 12:54:32.313",
1979 streams: ["650d3da25e9a2d550c6d6491"],
1980 rule_mitre_id: "T1055",
1981 gl2_message_id: "01HEFRS9ASFK4K72X8JPRDYJS6",
1982 data_win_system_computer: "web1",
1983 data_win_eventdata_ruleName: "technique_id=T1055,technique_name=Process Injection",
1984 agent_ip: "202.43.110.138",
1985 data_win_eventdata_startAddress: "0x00007FFDE5CCE720",
1986 true: 1699188873.447718,
1987 rule_groups: "sysmon, sysmon_eid8_detections, windows",
1988 data_win_system_keywords: "0x8000000000000000",
1989 data_win_system_level: "4",
1990 data_win_system_severityValue: AlertSourceDataWinSystemSeverityValue.Information,
1991 data_win_eventdata_targetUser: "NT AUTHORITY\\\\SYSTEM",
1992 agent_ip_geolocation: "16.1667,107.8333",
1993 rule_mitre_technique: "Process Injection",
1994 rule_firedtimes: 2,
1995 data_win_system_systemTime: "2023-11-05T12:54:32.314179900Z",
1996 rule_mail: true,
1997 decoder_name: AlertSourceDecoderName.WindowsEventchannel,
1998 agent_ip_country_code: "VN",
1999 data_win_system_processID: "3468",
2000 data_win_system_channel: "Microsoft-Windows-Sysmon/Operational",
2001 syslog_level: AlertSourceSyslogLevel.Alert,
2002 data_win_system_providerName: "Microsoft-Windows-Sysmon",
2003 data_win_system_version: "2",
2004 data_win_system_providerGuid: "{5770385f-c22a-43e0-bf4c-06f5698ffbd9}",
2005 timestamp: "2023-11-05 12:54:36.633",
2006 data_win_system_opcode: "0",
2007 gl2_processing_error:
2008 'Replaced invalid timestamp value in message <797bfd81-7bda-11ee-93bc-86000046278a> with current time - Value <2023-11-05T12:54:33.443+0000> caused exception: Invalid format: "2023-11-05T12:54:33.443+0000" is malformed at "T12:54:33.443+0000".',
2009 data_win_eventdata_sourceProcessId: "3368",
2010 data_win_eventdata_startModule: "C:\\\\Windows\\\\System32\\\\KERNEL32.DLL",
2011 message:
2012 '{"true":1699188873.447718,"timestamp":"2023-11-05T12:54:33.443+0000","rule":{"level":12,"description":"Local Security Authority Subsystem Service (LSASS) process was accessed by C:\\\\\\\\Program Files\\\\\\\\VMware\\\\\\\\VMware Tools\\\\\\\\vmtoolsd.exe, possible code injection for credential dumping","id":"92403","mitre":{"id":["T1055"],"tactic":["Defense Evasion","Privilege Escalation"],"technique":["Process Injection"]},"firedtimes":2,"mail":true,"groups":["sysmon","sysmon_eid8_detections","windows"]},"agent":{"id":"070","name":"web1","ip":"202.43.110.138","labels":{"customer":"wso4vxhq"}},"manager":{"name":"ASHWZHMA"},"id":"1699188873.736407303","decoder":{"name":"windows_eventchannel"},"data":{"win":{"system":{"providerName":"Microsoft-Windows-Sysmon","providerGuid":"{5770385f-c22a-43e0-bf4c-06f5698ffbd9}","eventID":"8","version":"2","level":"4","task":"8","opcode":"0","keywords":"0x8000000000000000","systemTime":"2023-11-05T12:54:32.314179900Z","eventRecordID":"4882339","processID":"3468","threadID":"5576","channel":"Microsoft-Windows-Sysmon/Operational","computer":"web1","severityValue":"INFORMATION","message":"\\"CreateRemoteThread detected:\\r\\nRuleName: technique_id=T1055,technique_name=Process Injection\\r\\nUtcTime: 2023-11-05 12:54:32.313\\r\\nSourceProcessGuid: {d9ab9ebb-48da-652f-4900-000000003000}\\r\\nSourceProcessId: 3368\\r\\nSourceImage: C:\\\\Program Files\\\\VMware\\\\VMware Tools\\\\vmtoolsd.exe\\r\\nTargetProcessGuid: {d9ab9ebb-48d7-652f-0c00-000000003000}\\r\\nTargetProcessId: 740\\r\\nTargetImage: C:\\\\Windows\\\\System32\\\\lsass.exe\\r\\nNewThreadId: 13164\\r\\nStartAddress: 0x00007FFDE5CCE720\\r\\nStartModule: C:\\\\Windows\\\\System32\\\\KERNEL32.DLL\\r\\nStartFunction: GetCommandLineW\\r\\nSourceUser: NT AUTHORITY\\\\SYSTEM\\r\\nTargetUser: NT AUTHORITY\\\\SYSTEM\\""},"eventdata":{"ruleName":"technique_id=T1055,technique_name=Process Injection","utcTime":"2023-11-05 12:54:32.313","sourceProcessGuid":"{d9ab9ebb-48da-652f-4900-000000003000}","sourceProcessId":"3368","sourceImage":"C:\\\\\\\\Program Files\\\\\\\\VMware\\\\\\\\VMware Tools\\\\\\\\vmtoolsd.exe","targetProcessGuid":"{d9ab9ebb-48d7-652f-0c00-000000003000}","targetProcessId":"740","targetImage":"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\lsass.exe","newThreadId":"13164","startAddress":"0x00007FFDE5CCE720","startModule":"C:\\\\\\\\Windows\\\\\\\\System32\\\\\\\\KERNEL32.DLL","startFunction":"GetCommandLineW","sourceUser":"NT AUTHORITY\\\\\\\\SYSTEM","targetUser":"NT AUTHORITY\\\\\\\\SYSTEM"}}},"location":"EventChannel"}',
2013 rule_id: "92403",
2014 manager_name: "ASHWZHMA",
2015 data_win_eventdata_sourceProcessGuid: "{d9ab9ebb-48da-652f-4900-000000003000}",
2016 location: "EventChannel",
2017 data_win_eventdata_targetProcessId: "740",
2018 data_win_eventdata_startFunction: "GetCommandLineW",
2019 rule_group3: AlertSourceDataLogsourceProduct.Windows,
2020 data_win_system_message:
2021 '"CreateRemoteThread detected:\r\nRuleName: technique_id=T1055,technique_name=Process Injection\r\nUtcTime: 2023-11-05 12:54:32.313\r\nSourceProcessGuid: {d9ab9ebb-48da-652f-4900-000000003000}\r\nSourceProcessId: 3368\r\nSourceImage: C:\\Program Files\\VMware\\VMware Tools\\vmtoolsd.exe\r\nTargetProcessGuid: {d9ab9ebb-48d7-652f-0c00-000000003000}\r\nTargetProcessId: 740\r\nTargetImage: C:\\Windows\\System32\\lsass.exe\r\nNewThreadId: 13164\r\nStartAddress: 0x00007FFDE5CCE720\r\nStartModule: C:\\Windows\\System32\\KERNEL32.DLL\r\nStartFunction: GetCommandLineW\r\nSourceUser: NT AUTHORITY\\SYSTEM\r\nTargetUser: NT AUTHORITY\\SYSTEM"',
2022 msg_timestamp: "2023-11-05T12:54:33.443Z",
2023 rule_group2: "sysmon_eid8_detections",
2024 rule_group1: "sysmon"
2025 },
2026 sort: [1699188872314]
2027 }
2028 ]
2029 }
2030 ]
2031
2032 export const alerts_by_host = [
2033 {
2034 agent_name: "ip-178-216-201-141",
2035 number_of_alerts: 4
2036 },
2037 {
2038 agent_name: "WinDev2308Eval",
2039 number_of_alerts: 10
2040 },
2041 {
2042 agent_name: "ANSYDWDC01",
2043 number_of_alerts: 20
2044 },
2045 {
2046 agent_name: "web1",
2047 number_of_alerts: 10
2048 },
2049 {
2050 agent_name: "ssdnodes-zabbix",
2051 number_of_alerts: 4
2052 }
2053 ]
2054
2055 export const alerts_by_rule = [
2056 {
2057 rule: "Explorer process was accessed by C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe, possible process injection",
2058 number_of_alerts: 6
2059 },
2060 {
2061 rule: "Explorer process was accessed by C:\\\\Users\\\\Administrator\\\\AppData\\\\Local\\\\Programs\\\\Messenger\\\\Messenger.exe, possible process injection",
2062 number_of_alerts: 4
2063 },
2064 {
2065 rule: "Adversaries may use binary padding to add junk data and change the on-disk representation of malware. This rule detect using dd and truncate to add a junk data to file.",
2066 number_of_alerts: 1
2067 },
2068 {
2069 rule: "Detects file and folder permission changes.",
2070 number_of_alerts: 7
2071 },
2072 {
2073 rule: "Process Explorer Driver Creation By Non-Sysinternals Binary",
2074 number_of_alerts: 20
2075 },
2076 {
2077 rule: "Application Compatibility Database launched",
2078 number_of_alerts: 10
2079 }
2080 ]
2081
2082 export const alerts_by_rule_per_host = [
2083 {
2084 agent_name: "ANSYDWDC01",
2085 number_of_alerts: 20,
2086 rule: "Process Explorer Driver Creation By Non-Sysinternals Binary"
2087 },
2088 {
2089 agent_name: "WinDev2308Eval",
2090 number_of_alerts: 10,
2091 rule: "Application Compatibility Database launched"
2092 },
2093 {
2094 agent_name: "ip-178-216-201-141",
2095 number_of_alerts: 4,
2096 rule: "Detects file and folder permission changes."
2097 },
2098 {
2099 agent_name: "web1",
2100 number_of_alerts: 9,
2101 rule: "Explorer process was accessed by C:\\\\Users\\\\Administrator\\\\AppData\\\\Roaming\\\\Telegram Desktop\\\\Telegram.exe, possible process injection"
2102 },
2103 {
2104 agent_name: "web1",
2105 number_of_alerts: 1,
2106 rule: "Explorer process was accessed by C:\\\\Users\\\\Administrator\\\\AppData\\\\Local\\\\Programs\\\\Messenger\\\\Messenger.exe, possible process injection"
2107 },
2108 {
2109 agent_name: "ssdnodes-zabbix",
2110 number_of_alerts: 1,
2111 rule: "Adversaries may use binary padding to add junk data and change the on-disk representation of malware. This rule detect using dd and truncate to add a junk data to file."
2112 },
2113 {
2114 agent_name: "ssdnodes-zabbix",
2115 number_of_alerts: 3,
2116 rule: "Detects file and folder permission changes."
2117 }
2118 ]