Spotting the Adversary with Windows Event Log Monitoring
Spotting the Adversary with Windows Event Log Monitoring
Spotting the Adversary with Windows Event Log Monitoring
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
MSI Packages Installed (MsiPackages.xml)<br />
<br />
MsiPackages<br />
SourceInitiated<br />
MSI Packages Installed. Targets: <strong>Windows</strong> XP+<br />
true<br />
http://schemas.microsoft.com/wbem/wsman/1/windows/<strong>Event</strong><strong>Log</strong><br />
Custom<br />
<br />
11000<br />
<br />
<br />
<br />
<br />
*[System[Provider[@Name='MsiInstaller'] and (Level=4 or Level=0) and (<strong>Event</strong>ID=1022 or <strong>Event</strong>ID=1033 or<br />
<strong>Event</strong>ID=11707 or <strong>Event</strong>ID=11728)]]<br />
<br />
<br />
*[System[Provider[@Name='NtServicePack'] and (<strong>Event</strong>ID=4377)]]<br />
*[System[Provider[@Name='FilterManager'] and (<strong>Event</strong>ID=6)]]<br />
*[System[Provider[@Name='<strong>Windows</strong> Update Agent'] and (<strong>Event</strong>ID=19)]]<br />
<br />
<br />
]]><br />
true<br />
httpRenderedText<br />
Forwarded<strong>Event</strong>s<br />
<br />
<br />
<br />
<strong>Windows</strong> Service Manager Errors (Service.xml)<br />
<br />
NTService<br />
SourceInitiated<br />
<strong>Windows</strong> Service Manager Errors<br />
true<br />
http://schemas.microsoft.com/wbem/wsman/1/windows/<strong>Event</strong><strong>Log</strong><br />
Custom<br />
<br />
11000<br />
<br />
<br />
<br />
<br />
*[System[(Level=1 or Level=2 or Level=3 or Level=4 or Level=0) and (<strong>Event</strong>ID=7022 or <strong>Event</strong>ID=7023 or <strong>Event</strong>ID=7024<br />
or <strong>Event</strong>ID=7026 or <strong>Event</strong>ID=7031 or <strong>Event</strong>ID=7034 or <strong>Event</strong>ID=7032 or <strong>Event</strong>ID=7045)]]<br />
<br />
<br />
]]><br />
true<br />
http<strong>Event</strong>s<br />
Forwarded<strong>Event</strong>s<br />
<br />
<br />
<br />
System <strong>Log</strong> Errors (Sys<strong>Log</strong>s.xml)<br />
<br />
Sys<strong>Log</strong>s<br />
SourceInitiated<br />
<strong>Windows</strong> System <strong>Log</strong>s<br />
true<br />
http://schemas.microsoft.com/wbem/wsman/1/windows/<strong>Event</strong><strong>Log</strong><br />
Custom<br />
<br />
11000<br />
<br />
<br />
<br />
<br />
<br />
*[System[(Level=2 or Level=3 or Level=4 or Level=0) and (<strong>Event</strong>ID=10016 or <strong>Event</strong>ID=11 or <strong>Event</strong>ID=104 or <strong>Event</strong>ID=6 or<br />
<strong>Event</strong>ID=1127 or <strong>Event</strong>ID=1125 or <strong>Event</strong>ID=40964 or <strong>Event</strong>ID=40968)]]<br />
<br />
]]><br />
true<br />
http<strong>Event</strong>s<br />
Forwarded<strong>Event</strong>s<br />
<br />
<br />
<br />
43