It seems existing sysmon decoders does not have parsers for Network connections which sysmon is capturing, does it?
<rule id="61605" level="0"> <if_sid>61600</if_sid> <field name="win.system.eventID">^3$</field> <description>Sysmon - Event 3: Network connection by $(win.eventdata.sourceImage)</description> <options>no_full_log</options> <group>sysmon_event3,</group> </rule>--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/34c49060-123f-43bc-853d-95bfc845449b%40googlegroups.com.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/34c49060-123f-43bc-853d-95bfc845449b%40googlegroups.com.
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/9a4c7462-0f8f-4809-aded-a8d5dbb6d931%40googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/CAPPXLT9XR3r%3Du9Oo03HAf5jYxdQ7H1BfRzP%2BsmsY1OONr-dx4A%40mail.gmail.com.
Best Regards
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/34c49060-123f-43bc-853d-95bfc845449b%40googlegroups.com.
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/9a4c7462-0f8f-4809-aded-a8d5dbb6d931%40googlegroups.com.
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/CAPPXLT9XR3r%3Du9Oo03HAf5jYxdQ7H1BfRzP%2BsmsY1OONr-dx4A%40mail.gmail.com.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/34c49060-123f-43bc-853d-95bfc845449b%40googlegroups.com.
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/9a4c7462-0f8f-4809-aded-a8d5dbb6d931%40googlegroups.com.
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/CAPPXLT9XR3r%3Du9Oo03HAf5jYxdQ7H1BfRzP%2BsmsY1OONr-dx4A%40mail.gmail.com.
--Best Regards
Miki AlkalayMobile: 972-54-6496293
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/6cb4e815-caf8-425b-92e1-f2d8691ba883%40googlegroups.com.
if we have basic corelated events possible out of Wazuh logs? Like 5 logong failures within 2 mins alert it, etc...
2019 Jun 10 17:11:22 WinEvtLog: Security: AUDIT_FAILURE(4625): Microsoft-Windows-Security-Auditing: (no user): no domain: MYDOMAIN: An account failed to log on. Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Logon Type: 3 Account For Which Logon Failed: Security ID: S-1-0-0 Account Name: AMMINISTRATORE Account Domain: Failure Information: Failure Reason: %%2313 Status: 0xc000006d Sub Status: 0xc0000064 Process Information: Caller Process ID: 0x0 Caller Process Name: - Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: NtLmSsp Authentication Package: NTLM Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon request fails. It is generated on the computer where access was attempted.
**Phase 3: Completed filtering (rules).
Rule id: '18130'
Level: '5'
Description: 'Windows: Logon Failure - Unknown user or bad password.'
Info - Link: 'https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4625'
**Alert to be generated.
<rule id="100002" level="7" frequency="5" timeframe="300"> <if_matched_sid>18130</if_matched_sid> <same_user/> <description>5 failed logon attemps on the same user in 5 minutes.</description> </rule>**Phase 3: Completed filtering (rules). Rule id: '100002' Level: '7' Description: '5 failed logon attemps on the same user in 5 minutes.'**Alert to be generated.To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/34c49060-123f-43bc-853d-95bfc845449b%40googlegroups.com.
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/9a4c7462-0f8f-4809-aded-a8d5dbb6d931%40googlegroups.com.
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/CAPPXLT9XR3r%3Du9Oo03HAf5jYxdQ7H1BfRzP%2BsmsY1OONr-dx4A%40mail.gmail.com.
--Best Regards
Miki AlkalayMobile: 972-54-6496293
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/CAPPXLT8QWMUxP0z1o6dGYfqp4S1AO9EV-u2VNaoA%3DdpM%2BM6e9w%40mail.gmail.com.
<rule id="100100" level="10">
<if_sid>XXXXXX</if_sid>
<list field="srcip" lookup="address_match_key">etc/lists/blacklist1</list>
<description>IP in black list.</description
<rule id="100101" level="10">
<if_sid>XXXXXX</if_sid>
<list field="srcip" lookup="address_match_key">etc/lists/blacklist1</list>
<description>URL in black list.</description<command> <name>netsh</name> <executable>netsh.cmd</executable> <expect>srcip</expect> <timeout_allowed>yes</timeout_allowed></command>
<active-response> <command>netsh</command> <location>local</location> <rules_id>100100</rules_id> <timeout>1800</timeout> </active-response>To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/34c49060-123f-43bc-853d-95bfc845449b%40googlegroups.com.
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/9a4c7462-0f8f-4809-aded-a8d5dbb6d931%40googlegroups.com.
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/CAPPXLT9XR3r%3Du9Oo03HAf5jYxdQ7H1BfRzP%2BsmsY1OONr-dx4A%40mail.gmail.com.
--Best Regards
Miki AlkalayMobile: 972-54-6496293
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/6cb4e815-caf8-425b-92e1-f2d8691ba883%40googlegroups.com.
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/CAPPXLT8QWMUxP0z1o6dGYfqp4S1AO9EV-u2VNaoA%3DdpM%2BM6e9w%40mail.gmail.com.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/34c49060-123f-43bc-853d-95bfc845449b%40googlegroups.com.
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/9a4c7462-0f8f-4809-aded-a8d5dbb6d931%40googlegroups.com.
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/CAPPXLT9XR3r%3Du9Oo03HAf5jYxdQ7H1BfRzP%2BsmsY1OONr-dx4A%40mail.gmail.com.
--Best Regards
Miki AlkalayMobile: 972-54-6496293--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/6cb4e815-caf8-425b-92e1-f2d8691ba883%40googlegroups.com.
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.