29.04.2014 Views

Spotting the Adversary with Windows Event Log Monitoring

Spotting the Adversary with Windows Event Log Monitoring

Spotting the Adversary with Windows Event Log Monitoring

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

MSI Packages Installed (MsiPackages.xml)<br />

<br />

MsiPackages<br />

SourceInitiated<br />

MSI Packages Installed. Targets: <strong>Windows</strong> XP+<br />

true<br />

http://schemas.microsoft.com/wbem/wsman/1/windows/<strong>Event</strong><strong>Log</strong><br />

Custom<br />

<br />

11000<br />

<br />

<br />

<br />

<br />

*[System[Provider[@Name='MsiInstaller'] and (Level=4 or Level=0) and (<strong>Event</strong>ID=1022 or <strong>Event</strong>ID=1033 or<br />

<strong>Event</strong>ID=11707 or <strong>Event</strong>ID=11728)]]<br />

<br />

<br />

*[System[Provider[@Name='NtServicePack'] and (<strong>Event</strong>ID=4377)]]<br />

*[System[Provider[@Name='FilterManager'] and (<strong>Event</strong>ID=6)]]<br />

*[System[Provider[@Name='<strong>Windows</strong> Update Agent'] and (<strong>Event</strong>ID=19)]]<br />

<br />

<br />

]]><br />

true<br />

httpRenderedText<br />

Forwarded<strong>Event</strong>s<br />

<br />

<br />

<br />

<strong>Windows</strong> Service Manager Errors (Service.xml)<br />

<br />

NTService<br />

SourceInitiated<br />

<strong>Windows</strong> Service Manager Errors<br />

true<br />

http://schemas.microsoft.com/wbem/wsman/1/windows/<strong>Event</strong><strong>Log</strong><br />

Custom<br />

<br />

11000<br />

<br />

<br />

<br />

<br />

*[System[(Level=1 or Level=2 or Level=3 or Level=4 or Level=0) and (<strong>Event</strong>ID=7022 or <strong>Event</strong>ID=7023 or <strong>Event</strong>ID=7024<br />

or <strong>Event</strong>ID=7026 or <strong>Event</strong>ID=7031 or <strong>Event</strong>ID=7034 or <strong>Event</strong>ID=7032 or <strong>Event</strong>ID=7045)]]<br />

<br />

<br />

]]><br />

true<br />

http<strong>Event</strong>s<br />

Forwarded<strong>Event</strong>s<br />

<br />

<br />

<br />

System <strong>Log</strong> Errors (Sys<strong>Log</strong>s.xml)<br />

<br />

Sys<strong>Log</strong>s<br />

SourceInitiated<br />

<strong>Windows</strong> System <strong>Log</strong>s<br />

true<br />

http://schemas.microsoft.com/wbem/wsman/1/windows/<strong>Event</strong><strong>Log</strong><br />

Custom<br />

<br />

11000<br />

<br />

<br />

<br />

<br />

<br />

*[System[(Level=2 or Level=3 or Level=4 or Level=0) and (<strong>Event</strong>ID=10016 or <strong>Event</strong>ID=11 or <strong>Event</strong>ID=104 or <strong>Event</strong>ID=6 or<br />

<strong>Event</strong>ID=1127 or <strong>Event</strong>ID=1125 or <strong>Event</strong>ID=40964 or <strong>Event</strong>ID=40968)]]<br />

<br />

]]><br />

true<br />

http<strong>Event</strong>s<br />

Forwarded<strong>Event</strong>s<br />

<br />

<br />

<br />

43

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!