diff --git a/sysmon.xml b/sysmon.xml new file mode 100644 index 0000000..cca2aee --- /dev/null +++ b/sysmon.xml @@ -0,0 +1,102 @@ + + + + 61600 + ^22$ + Sysmon - Event 22: DNS Query. + no_full_log + + + 61603 + no_full_log + Sysmon - Event 1: Process creation. + + + 61604 + no_full_log + Sysmon - Event 2: A process changed a file creation time. + + + 61605 + no_full_log + Sysmon - Event 3: Network connection. + + + 61606 + no_full_log + Sysmon - Event 4: Sysmon service state changed. + + + 61607 + no_full_log + Sysmon - Event 5: Process terminated. + + + 61608 + no_full_log + Sysmon - Event 6: Driver loaded. + + + 61609 + no_full_log + Sysmon - Event 7: Image loaded. + + + 61610 + no_full_log + Sysmon - Event 8: CreateRemoteThread. + + + 61611 + no_full_log + Sysmon - Event 9: RawAccessRead. + + + 61612 + no_full_log + Sysmon - Event 10: ProcessAccess. + + + 61613 + no_full_log + Sysmon - Event 11: FileCreate. + + + 61614 + no_full_log + Sysmon - Event 12: RegistryEvent (Object create and delete). + + + 61615 + no_full_log + Sysmon - Event 13: RegistryEvent (Value Set). + + + 61616 + no_full_log + Sysmon - Event 14: RegistryEvent (Key and Value Rename). + + + 61617 + no_full_log + Sysmon - Event 15: FileCreateStreamHash. + + + 101100 + sjca.prod.e2open.com + Sysmon - Event 22: DNS Query to *.sjca.prod.e2open.com + no_full_log + + + 101100 + googleapis.com + Sysmon - Event 22: DNS Query to googleapis.com + no_full_log + + + 101100 + google.com + Sysmon - Event 22: DNS Query to google.com + no_full_log + +