Hello,
Unfortunately, we haven’t got rules for the new Sysmon event. We will read these blog posts to try to create new rules.
At the moment only can say that if you need help to create you some rule, send us the event and we will help you.
I recommend you create rules to group new events as do the existing rules. Then, create rules child to generate the alerts you want.
Attached is an example of rules (although it seems that you already have experience in creating rules):
<group name="windows, windows_sysmon">
<rule id="100000" level="0">
<if_sid>61600</if_sid>
<field name="win.system.eventID">^17$</field>
<description>Sysmon - Event 17: PipeEvent (Pipe Created)</description>
<options>no_full_log</options>
<group>sysmon_event_17,</group>
</rule>
<rule id="100001" level="0">
<if_sid>61600</if_sid>
<field name="win.system.eventID">^18$</field>
<description>Sysmon - Event 18: PipeEvent (Pipe Connected)</description>
<options>no_full_log</options>
<group>sysmon_event_18,</group>
</rule>
<rule id="100002" level="0">
<if_sid>61600</if_sid>
<field name="win.system.eventID">^19$</field>
<description>Sysmon - Event 19: WmiEvent (WmiEventFilter activity detected)</description>
<options>no_full_log</options>
<group>sysmon_event_19,</group>
</rule>
<rule id="100003" level="0">
<if_sid>61600</if_sid>
<field name="win.system.eventID">^20$</field>
<description>Sysmon - Event 20: WmiEvent (WmiEventConsumer activity detected)</description>
<options>no_full_log</options>
<group>sysmon_event_20,</group>
</rule>
<rule id="100004" level="0">
<if_sid>61600</if_sid>
<field name="win.system.eventID">^21$</field>
<description>Sysmon - Event 21: WmiEvent (WmiEventConsumerToFilter activity detected)</description>
<options>no_full_log</options>
<group>sysmon_event_21,</group>
</rule>
<rule id="100005" level="0">
<if_sid>61600</if_sid>
<field name="win.system.eventID">^22$</field>
<description>Sysmon - Event 22: DNSEvent (DNS query)</description>
<options>no_full_log</options>
<group>sysmon_event_22,</group>
</rule>
</group>
Regards,
Eva