Vendor: Microsoft
August 30, 2023 · View on GitHub
Product: Sysmon
| Rules | Models | MITRE ATT&CK® TTPs | Event Types | Parsers |
|---|---|---|---|---|
| 616 | 99 | 128 | 8 | 8 |
| Use-Case | Event Types/Parsers | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| Account Manipulation | process-created ↳xml-sysmon-process-created-2 ↳xml-sysmon-process-created-1 ↳sysmon-process-created ↳l-sysmon-process-created ↳json-sysmon-process-created ↳cef-sysmon-process-created ↳sysmon-process-created-2 ↳sysmon-process-created-1 ↳xml-sysmon-process-created ↳json-sysmon-process-created-1 | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002 |
|
| Audit Tampering | process-created ↳xml-sysmon-process-created-2 ↳xml-sysmon-process-created-1 ↳sysmon-process-created ↳l-sysmon-process-created ↳json-sysmon-process-created ↳cef-sysmon-process-created ↳sysmon-process-created-2 ↳sysmon-process-created-1 ↳xml-sysmon-process-created ↳json-sysmon-process-created-1 | T1059 - Command and Scripting Interperter T1070 - Indicator Removal on Host T1070.001 - Indicator Removal on Host: Clear Windows Event Logs T1546.003 - T1546.003 T1562 - Impair Defenses T1562.006 - T1562.006 |
|
| Data Leak | file-write ↳json-sysmon-file-create ↳json-sysmon-file-create-1 ↳cef-sysmon-file-write-1 ↳l-sysmon-file-create ↳sysmon-file-create ↳xml-sysmon-file-write | T1114.001 - T1114.001 |
|
| Destruction of Data | file-delete ↳sysmon-file-delete | T1070.004 - Indicator Removal on Host: File Deletion T1485 - Data Destruction |
|
| Next Page -->> |