From 313276d2942e7f3e14c0bc5e979547f03ad323ca Mon Sep 17 00:00:00 2001 From: Patrick Bareiss Date: Fri, 8 Nov 2024 11:59:22 +0100 Subject: [PATCH] Update data source for registry detections --- data_sources/sysmon_eventid_12.yml | 8 ++++++++ detections/endpoint/active_setup_registry_autostart.yml | 1 - .../allow_inbound_traffic_by_firewall_rule_registry.yml | 1 - .../endpoint/allow_operation_with_consent_admin.yml | 1 - detections/endpoint/auto_admin_logon_registry_entry.yml | 1 - detections/endpoint/change_default_file_association.yml | 1 - detections/endpoint/disable_amsi_through_registry.yml | 1 - .../endpoint/disable_defender_antivirus_registry.yml | 1 - .../disable_defender_blockatfirstseen_feature.yml | 1 - .../endpoint/disable_defender_mpengine_registry.yml | 1 - detections/endpoint/disable_defender_spynet_reporting.yml | 1 - .../disable_defender_submit_samples_consent_feature.yml | 1 - detections/endpoint/disable_etw_through_registry.yml | 1 - detections/endpoint/disable_registry_tool.yml | 1 - .../disable_security_logs_using_minint_registry.yml | 1 - detections/endpoint/disable_show_hidden_files.yml | 1 - detections/endpoint/disable_uac_remote_restriction.yml | 1 - detections/endpoint/disable_windows_app_hotkeys.yml | 1 - .../endpoint/disable_windows_behavior_monitoring.yml | 1 - .../endpoint/disable_windows_smartscreen_protection.yml | 1 - detections/endpoint/disabling_cmd_application.yml | 1 - detections/endpoint/disabling_controlpanel.yml | 1 - detections/endpoint/disabling_defender_services.yml | 1 - .../endpoint/disabling_folderoptions_windows_feature.yml | 1 - detections/endpoint/disabling_norun_windows_app.yml | 1 - .../endpoint/disabling_remote_user_account_control.yml | 1 - .../endpoint/disabling_systemrestore_in_registry.yml | 1 - detections/endpoint/disabling_task_manager.yml | 1 - detections/endpoint/enable_rdp_in_other_port_number.yml | 1 - .../enable_wdigest_uselogoncredential_registry.yml | 1 - detections/endpoint/etw_registry_disabled.yml | 1 - .../endpoint/hide_user_account_from_sign_in_screen.yml | 1 - .../endpoint/monitor_registry_keys_for_print_monitors.yml | 1 - detections/endpoint/net_profiler_uac_bypass.yml | 1 - .../endpoint/print_processor_registry_autostart.yml | 1 - .../registry_keys_for_creating_shim_databases.yml | 1 - .../endpoint/registry_keys_used_for_persistence.yml | 1 - .../registry_keys_used_for_privilege_escalation.yml | 1 - .../endpoint/screensaver_event_trigger_execution.yml | 1 - .../endpoint/time_provider_persistence_registry.yml | 1 - ...start_execution_lsass_driver_registry_modification.yml | 1 - .../windows_defender_exclusion_registry_entry.yml | 1 - .../windows_disable_change_password_through_registry.yml | 1 - ..._disable_lock_workstation_feature_through_registry.yml | 1 - .../windows_disable_logoff_button_through_registry.yml | 1 - detections/endpoint/windows_disable_memory_crash_dump.yml | 1 - .../endpoint/windows_disable_notification_center.yml | 1 - .../windows_disable_shutdown_button_through_registry.yml | 1 - ...ble_windows_group_policy_features_through_registry.yml | 1 - .../endpoint/windows_disableantispyware_registry.yml | 1 - .../windows_enable_win32_scheduledjob_via_registry.yml | 1 - ...indows_hide_notification_features_through_registry.yml | 1 - ...defense_change_win_defender_health_check_intervals.yml | 1 - ...ir_defense_change_win_defender_quick_scan_interval.yml | 1 - ...s_impair_defense_change_win_defender_throttle_rate.yml | 1 - ...s_impair_defense_change_win_defender_tracing_level.yml | 1 - ...ndows_impair_defense_configure_app_install_control.yml | 1 - ...s_impair_defense_define_win_defender_threat_action.yml | 1 - ...ws_impair_defense_delete_win_defender_context_menu.yml | 1 - ...mpair_defense_delete_win_defender_profile_registry.yml | 1 - ...pair_defense_deny_security_software_with_applocker.yml | 1 - ...ws_impair_defense_disable_controlled_folder_access.yml | 1 - ...pair_defense_disable_defender_firewall_and_network.yml | 1 - ...pair_defense_disable_defender_protocol_recognition.yml | 1 - .../windows_impair_defense_disable_pua_protection.yml | 1 - ...impair_defense_disable_realtime_signature_delivery.yml | 1 - .../windows_impair_defense_disable_web_evaluation.yml | 1 - ...dows_impair_defense_disable_win_defender_app_guard.yml | 1 - ...r_defense_disable_win_defender_compute_file_hashes.yml | 1 - ...ws_impair_defense_disable_win_defender_gen_reports.yml | 1 - ...ir_defense_disable_win_defender_network_protection.yml | 1 - ...pair_defense_disable_win_defender_report_infection.yml | 1 - ...impair_defense_disable_win_defender_scan_on_update.yml | 1 - ..._defense_disable_win_defender_signature_retirement.yml | 1 - ...mpair_defense_overide_win_defender_phishing_filter.yml | 1 - ...windows_impair_defense_override_smartscreen_prompt.yml | 1 - ...efense_set_win_defender_smart_screen_level_to_warn.yml | 1 - .../endpoint/windows_impair_defenses_disable_hvci.yml | 1 - ..._impair_defenses_disable_win_defender_auto_logging.yml | 1 - .../endpoint/windows_lsa_secrets_nolmhash_registry.yml | 1 - ...indows_modify_registry_authenticationleveloverride.yml | 1 - .../windows_modify_registry_auto_minor_updates.yml | 1 - .../windows_modify_registry_auto_update_notif.yml | 1 - .../windows_modify_registry_default_icon_setting.yml | 1 - .../windows_modify_registry_disable_restricted_admin.yml | 1 - ...indows_modify_registry_disable_toast_notifications.yml | 1 - ...dify_registry_disable_win_defender_raw_write_notif.yml | 1 - ..._modify_registry_disable_windefender_notifications.yml | 1 - ...ify_registry_disable_windows_security_center_notif.yml | 1 - ...dows_modify_registry_disableremotedesktopantialias.yml | 1 - .../windows_modify_registry_disablesecuritysettings.yml | 1 - .../windows_modify_registry_disabling_wer_settings.yml | 1 - .../windows_modify_registry_disallow_windows_app.yml | 1 - ...ndows_modify_registry_do_not_connect_to_win_update.yml | 1 - .../endpoint/windows_modify_registry_dontshowui.yml | 1 - .../windows_modify_registry_enablelinkedconnections.yml | 1 - .../endpoint/windows_modify_registry_longpathsenabled.yml | 1 - .../windows_modify_registry_maxconnectionperserver.yml | 1 - ...ows_modify_registry_no_auto_reboot_with_logon_user.yml | 1 - .../endpoint/windows_modify_registry_no_auto_update.yml | 1 - .../windows_modify_registry_nochangingwallpaper.yml | 1 - .../endpoint/windows_modify_registry_proxyenable.yml | 1 - .../endpoint/windows_modify_registry_proxyserver.yml | 1 - ...indows_modify_registry_suppress_win_defender_notif.yml | 1 - .../windows_modify_registry_tamper_protection.yml | 1 - ...ows_modify_registry_to_add_or_modify_firewall_rule.yml | 1 - .../windows_modify_registry_updateserviceurlalternate.yml | 1 - .../endpoint/windows_modify_registry_usewuserver.yml | 1 - .../windows_modify_registry_valleyrat_c2_config.yml | 1 - .../windows_modify_registry_with_md5_reg_key_name.yml | 1 - detections/endpoint/windows_modify_registry_wuserver.yml | 1 - .../endpoint/windows_modify_registry_wustatusserver.yml | 1 - ...s_modify_show_compress_color_and_info_tip_registry.yml | 1 - .../endpoint/windows_mshta_execution_in_registry.yml | 1 - .../windows_njrat_fileless_storage_via_registry.yml | 1 - .../windows_phishing_recent_iso_exec_registry.yml | 1 - detections/endpoint/windows_proxy_via_registry.yml | 1 - .../windows_registry_bootexecute_modification.yml | 1 - .../endpoint/windows_registry_certificate_added.yml | 1 - detections/endpoint/windows_registry_delete_task_sd.yml | 1 - ...ws_registry_modification_for_safe_mode_persistence.yml | 1 - .../windows_registry_sip_provider_modification.yml | 1 - .../windows_remote_access_software_rms_registry.yml | 1 - .../windows_remote_services_allow_remote_assistance.yml | 1 - .../endpoint/windows_remote_services_rdp_enable.yml | 1 - .../windows_service_creation_using_registry_entry.yml | 1 - .../endpoint/windows_service_deletion_in_registry.yml | 1 - ..._malware_registry_modification_wav_openwithprogids.yml | 1 - 128 files changed, 8 insertions(+), 127 deletions(-) diff --git a/data_sources/sysmon_eventid_12.yml b/data_sources/sysmon_eventid_12.yml index 232ca47a23..f1ba265850 100644 --- a/data_sources/sysmon_eventid_12.yml +++ b/data_sources/sysmon_eventid_12.yml @@ -87,6 +87,14 @@ fields: - timestartpos - user_id - vendor_product +field_mappings: +- data_model: cim + data_set: Endpoint.Registry + mapping: + Computer: Registry.dest + ProcessGuid: Registry.process_guid + ProcessId: Registry.process_id + TargetObject: Registry.registry_path example_log: 12241200x80000000000000001055579