--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/b3a0cfc1-b1ef-481f-82cb-226eb0748c4c%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
<group name="sysmon,">
<rule id="255000" level="6">
<if_group>sysmon_event1</if_group>
<field name="win.eventdata.image">\\powershell.exe||\\.ps1||\\.ps2</field>
<description>Sysmon - Event 1: Powershell or Script Execution: $(win.eventdata.image)</description>
</rule>
</group>
** Alert 1559742569.50444: - sysmon,
2019 Jun 05 15:49:29 (win2012) any->EventChannel
Rule:
255000 (level 6) -> 'Sysmon - Event 1: Powershell or Script
Execution: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe'
{"win":{"system":{"providerName":"Microsoft-Windows-Sysmon","providerGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","eventID":"1","version":"5","level":"4","task":"1","opcode":"0","keywords":"0x8000000000000000","systemTime":"2019-06-05T13:49:28.697375000Z","eventRecordID":"24","processID":"1500","threadID":"1368","channel":"Microsoft-Windows-Sysmon/Operational","computer":"WIN-L2B5BQP9D71","severityValue":"INFORMATION","message":"Process
Create:"},"eventdata":{"utcTime":"2019-06-05
13:49:28.697","processGuid":"{ED2E593D-C868-5CF7-0000-00103BF61900}","processId":"2408","image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","fileVersion":"6.3.9600.16384
(winblue_rtm.130821-1623)","description":"Windows
PowerShell","product":"Microsoft® Windows® Operating
System","company":"Microsoft
Corporation","commandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\"","currentDirectory":"C:\\Users\\Administrator\\","user":"WIN-L2B5BQP9D71\\Administrator","logonGuid":"{ED2E593D-B66F-5CF7-0000-0020EE650100}","logonId":"0x165ee","terminalSessionId":"1","integrityLevel":"High","hashes":"MD5=45F9906157E072B92140EAA2A67AE424","parentProcessGuid":"{ED2E593D-B673-5CF7-0000-0010F1780100}","parentProcessId":"1704","parentImage":"C:\\Windows\\explorer.exe","parentCommandLine":"C:\\Windows\\Explorer.EXE"}}}
win.system.providerName: Microsoft-Windows-Sysmon
win.system.providerGuid: {5770385F-C22A-43E0-BF4C-06F5698FFBD9}
win.system.eventID: 1
win.system.version: 5
win.system.level: 4
win.system.task: 1
win.system.opcode: 0
win.system.keywords: 0x8000000000000000
win.system.systemTime: 2019-06-05T13:49:28.697375000Z
win.system.eventRecordID: 24
win.system.processID: 1500
win.system.threadID: 1368
win.system.channel: Microsoft-Windows-Sysmon/Operational
win.system.computer: WIN-L2B5BQP9D71
win.system.severityValue: INFORMATION
win.system.message: Process Create:
win.eventdata.utcTime: 2019-06-05 13:49:28.697
win.eventdata.processGuid: {ED2E593D-C868-5CF7-0000-00103BF61900}
win.eventdata.processId: 2408
win.eventdata.image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
win.eventdata.fileVersion: 6.3.9600.16384 (winblue_rtm.130821-1623)
win.eventdata.description: Windows PowerShell
win.eventdata.product: Microsoft® Windows® Operating System
win.eventdata.company: Microsoft Corporation
win.eventdata.commandLine: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"
win.eventdata.currentDirectory: C:\Users\Administrator\
win.eventdata.user: WIN-L2B5BQP9D71\Administrator
win.eventdata.logonGuid: {ED2E593D-B66F-5CF7-0000-0020EE650100}
win.eventdata.logonId: 0x165ee
win.eventdata.terminalSessionId: 1
win.eventdata.integrityLevel: High
win.eventdata.hashes: MD5=45F9906157E072B92140EAA2A67AE424
win.eventdata.parentProcessGuid: {ED2E593D-B673-5CF7-0000-0010F1780100}
win.eventdata.parentProcessId: 1704
win.eventdata.parentImage: C:\Windows\explorer.exe
win.eventdata.parentCommandLine: C:\Windows\Explorer.EXE--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/04838352-b6bb-4a71-ad80-fedc5b06d48b%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
Best Regards

<localfile><location>Microsoft-Windows-Sysmon/Operational</location><log_format>eventchannel</log_format></localfile><logall>yes</logall>{"win":{"system":{"providerName":"Microsoft-Windows-Sysmon","providerGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","eventID":"1","version":"5","level":"4","task":"1","opcode":"0","keywords":"0x8000000000000000","systemTime":"2019-06-05T13:17:14.713716400Z","eventRecordID":"13","processID":"1500","threadID":"1368","channel":"Microsoft-Windows-Sysmon/Operational","computer":"WIN-L2B5BQP9D71","severityValue":"INFORMATION","message":"Process Create:"},"eventdata":{"utcTime":"2019-06-05 13:17:14.698","processGuid":"{ED2E593D-C0DA-5CF7-0000-00100A621400}","processId":"2192","image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","fileVersion":"6.3.9600.16384 (winblue_rtm.130821-1623)","description":"Windows PowerShell","product":"Microsoft® Windows® Operating System","company":"Microsoft Corporation","commandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\"","currentDirectory":"C:\\Users\\Administrator\\","user":"WIN-L2B5BQP9D71\\Administrator","logonGuid":"{ED2E593D-B66F-5CF7-0000-0020EE650100}","logonId":"0x165ee","terminalSessionId":"1","integrityLevel":"High","hashes":"MD5=45F9906157E072B92140EAA2A67AE424","parentProcessGuid":"{ED2E593D-B673-5CF7-0000-0010F1780100}","parentProcessId":"1704","parentImage":"C:\\Windows\\explorer.exe","parentCommandLine":"C:\\Windows\\Explorer.EXE"}}}--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/82ed9f4e-1b4b-4294-8f32-b956b414032f%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/82ed9f4e-1b4b-4294-8f32-b956b414032f%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/82ed9f4e-1b4b-4294-8f32-b956b414032f%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--Best Regards
Miki AlkalayMobile: 972-54-6496293
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/c2553f41-ab5e-4d23-97e2-6c3124bc7861%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/82ed9f4e-1b4b-4294-8f32-b956b414032f%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--Best Regards
Miki AlkalayMobile: 972-54-6496293
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/c2553f41-ab5e-4d23-97e2-6c3124bc7861%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/82ed9f4e-1b4b-4294-8f32-b956b414032f%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--Best Regards
Miki AlkalayMobile: 972-54-6496293
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/c2553f41-ab5e-4d23-97e2-6c3124bc7861%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--Best Regards
Miki AlkalayMobile: 972-54-6496293
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/ad940e5c-0a7d-48c5-a39f-2d16b0f57054%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/82ed9f4e-1b4b-4294-8f32-b956b414032f%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--Best Regards
Miki AlkalayMobile: 972-54-6496293
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/c2553f41-ab5e-4d23-97e2-6c3124bc7861%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--Best Regards
Miki AlkalayMobile: 972-54-6496293
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/ad940e5c-0a7d-48c5-a39f-2d16b0f57054%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.