Hi team,
I need assistance with overwriting the default Sysmon rules. I’ve attempted to lower the rule level for some default rules, but I’m encountering an error.
Default Rules
<rule id="92900" level="12">
<if_group>sysmon_event_10</if_group>
<field name="win.eventdata.targetImage" type="pcre2">(?i)lsass\.exe</field>
<field name="win.eventdata.grantedAccess" type="pcre2">(?i)(0x1010|0x40)</field>
<field name="win.eventdata.sourceImage" type="pcre2" negate="yes">(?i)(C:\\\\Program Files|wmiprvse\.exe)</field>
<options>no_full_log</options>
<description>Lsass process was accessed by $(win.eventdata.sourceImage) with read permissions, possible credential dump</description>
<mitre>
<id>T1003.001</id>
</mitre>
</rule>
<rule id="92910" level="12">
<if_group>sysmon_event_10</if_group>
<field name="win.eventdata.targetImage" type="pcre2">(?i)explorer\.exe</field>
<options>no_full_log</options>
<description>Explorer process was accessed by $(win.eventdata.sourceImage), possible process injection</description>
<mitre>
<id>T1055</id>
</mitre>
</rule>
<rule id="92920" level="14">
<if_group>sysmon_event_10</if_group>
<field name="win.eventdata.targetImage" type="pcre2">(?i)mstsc\.exe</field>
<options>no_full_log</options>
<description>Windows Remote Dektop utility process was accessed by $(win.eventdata.sourceImage), possible process injection</description>
<mitre>
<id>T1055</id>
</mitre>
</rule>
Custom Overwritten Rules
<rule id="92900" level="8" overwrite="yes">
<if_group>sysmon_event_10</if_group>
<field name="win.eventdata.targetImage" type="pcre2">(?i)lsass\.exe</field>
<field name="win.eventdata.grantedAccess" type="pcre2">(?i)(0x1010|0x40)</field>
<field name="win.eventdata.sourceImage" type="pcre2" negate="yes">(?i)(C:\\\\Program Files|wmiprvse\.exe)</field>
<options>no_full_log</options>
<description>Lsass process was accessed by $(win.eventdata.sourceImage) with read permissions, possible credential dump</description>
<mitre>
<id>T1003.001</id>
</mitre>
</rule>
<rule id="92910" level="8" overwrite="yes">
<if_group>sysmon_event_10</if_group>
<field name="win.eventdata.targetImage" type="pcre2">(?i)explorer\.exe</field>
<options>no_full_log</options>
<description>Explorer process was accessed by $(win.eventdata.sourceImage), possible process injection</description>
<mitre>
<id>T1055</id>
</mitre>
</rule>
<rule id="92920" level="8" overwrite="yes">
<if_group>sysmon_event_10</if_group>
<field name="win.eventdata.targetImage" type="pcre2">(?i)mstsc\.exe</field>
<options>no_full_log</options>
<description>Windows Remote Dektop utility process was accessed by $(win.eventdata.sourceImage), possible process injection</description>
<mitre>
<id>T1055</id>
</mitre>
</rule>
I changed the default rule level from 12/14 to 8 to lower their severity. However, the system is returning warnings indicating that the if_group value cannot be overwritten.
Error:WARNING: (7605): It is not possible to overwrite 'if_group' value in rule '92900'. The original value is retained.
WARNING: (7605): It is not possible to overwrite 'if_group' value in rule '92910'. The original value is retained.
WARNING: (7605): It is not possible to overwrite 'if_group' value in rule '92920'. The original value is retained.
INFO: (7202): Session initialized with token 'bfd975ea'
Could you please help me understand why this occurs and how to properly resolve it?
Regards,