< div class = "column column-3" >
< ul >
< li > < a href = "#sysmon" > Sysmon< / a > < ul >
< li > < a href = "#paths" > Paths< / a > < / li >
< li > < a href = "#configuration" > Configuration< / a > < / li >
< li > < a href = "#installation" > Installation< / a > < / li >
< li > < a href = "#best-practices" > Best Practices< / a > < / li >
< li > < a href = "#filtering-events" > Filtering Events< / a > < ul >
< li > < a href = "#filtering-events-with-powershell" > Filtering Events with Powershell< / a > < / li >
< / ul >
< / li >
< li > < a href = "#evasion-techniques" > Evasion Techniques< / a > < ul >
< li > < a href = "#detecting-evasion-techniques-with-powershell" > Detecting Evasion Techniques with Powershell< / a > < / li >
< / ul >
< / li >
< / ul >
< / li >
< / ul >
< / div >
< h1 id = "sysmon" > Sysmon< / h1 >
< p > Sysmon gathers detailed and high-quality logs as well as event tracing that assists in identifying anomalies in your environment. Sysmon is most commonly used in conjunction with security information and event management (SIEM) system or other log parsing solutions that aggregate, filter, and visualize events. < / p >
< h2 id = "paths" > Paths< / h2 >
< ul >
< li > Logfiles< / li >
< / ul >
< div class = "codehilite" > < pre > < span > < / span > < code > Applications and Services Logs/Microsoft/Windows/Sysmon/Operational
< / code > < / pre > < / div >
< h2 id = "configuration" > Configuration< / h2 >
< ul >
< li > < a href = "https://github.com/SwiftOnSecurity/sysmon-config" > SwiftOnSecurity< / a > < / li >
< li > < a href = "https://github.com/ion-storm/sysmon-config/blob/develop/sysmonconfig-export.xml" > ION-Storm< / a > < / li >
< / ul >
< h2 id = "installation" > Installation< / h2 >
< div class = "codehilite" > < pre > < span > < / span > < code > Downloads-SysInternalsTools C:< span class = "se" > \S< / span > ysinternals
< / code > < / pre > < / div >
< h2 id = "best-practices" > Best Practices< / h2 >
< ul >
< li > Exclude, not include events< / li >
< li > CLI gives further control over filters< / li >
< / ul >
< div class = "codehilite" > < pre > < span > < / span > < code > Get-WinEvent
< / code > < / pre > < / div >
< div class = "codehilite" > < pre > < span > < / span > < code > wevutil.exe
< / code > < / pre > < / div >
< ul >
< li > Know the env before implementation< / li >
< / ul >
< h2 id = "filtering-events" > Filtering Events< / h2 >
< ul >
< li > Actions -> Filter Current Log< / li >
< / ul >
< h3 id = "filtering-events-with-powershell" > Filtering Events with Powershell< / h3 >
< ul >
< li > Logged Events containing port 4444< / li >
< / ul >
< div class = "codehilite" > < pre > < span > < / span > < code > Get-WinEvent -Path < Path to Log> -FilterXPath < span class = "s1" > ' */System/EventID=3 and */EventData/Data[@Name=" DestinationPort" ] and */EventData/Data=4444' < / span >
< / code > < / pre > < / div >
< ul >
< li > Logged Events containing lsass.exe< / li >
< / ul >
< div class = "codehilite" > < pre > < span > < / span > < code > Get-WinEvent -Path < Path to Log> -FilterXPath < span class = "s1" > ' */System/EventID=10 and */EventData/Data[@Name=" TargetImage" ] and */EventData/Data=" C:\Windows\system32\lsass.exe" ' < / span >
< / code > < / pre > < / div >
< ul >
< li > Rats and C2< / li >
< / ul >
< div class = "codehilite" > < pre > < span > < / span > < code > Get-WinEvent -Path < Path to Log> -FilterXPath < span class = "s1" > ' */System/EventID=3 and */EventData/Data[@Name=" DestinationPort" ] and */EventData/Data=< Port> ' < / span >
< / code > < / pre > < / div >
< h2 id = "evasion-techniques" > Evasion Techniques< / h2 >
< ul >
< li > Alternate Data Streams< / li >
< li > Injections< / li >
< li > Masquerading< / li >
< li > Packing/Compression< / li >
< li > Recompiling< / li >
< li > Obfuscation< / li >
< li > Anti-Reversing Techniques< / li >
< li > Remote Thread (OpenThread, ResumeThread)< / li >
< / ul >
< h3 id = "detecting-evasion-techniques-with-powershell" > Detecting Evasion Techniques with Powershell< / h3 >
< div class = "codehilite" > < pre > < span > < / span > < code > Get-WinEvent -Path < Path to Log> -FilterXPath < span class = "s1" > ' */System/EventID=15' < / span >
Get-WinEvent -Path < Path to Log> -FilterXPath < span class = "s1" > ' */System/EventID=8' < / span >
< / code > < / pre > < / div >
