Skip to content

Commit

Permalink
revocation check added
Browse files Browse the repository at this point in the history
  • Loading branch information
olafhartong committed Apr 14, 2018
1 parent 4af5805 commit b71a02a
Show file tree
Hide file tree
Showing 135 changed files with 266 additions and 62 deletions.
1 change: 1 addition & 0 deletions .gitignore
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
.DS_Store
3 changes: 2 additions & 1 deletion 10_process_access/exclude_lsass_noise.xml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
1 change: 1 addition & 0 deletions 10_process_access/include_general_commment.xml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
1 change: 1 addition & 0 deletions 10_process_access/include_mimikatz_inmem.xml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
1 change: 1 addition & 0 deletions 11_file_create/exclude_dell_process.xml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
1 change: 1 addition & 0 deletions 11_file_create/exclude_intel_gfx_service.xml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
1 change: 1 addition & 0 deletions 11_file_create/exclude_microsoft_click2run.xml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
1 change: 1 addition & 0 deletions 11_file_create/exclude_microsoft_services.xml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
1 change: 1 addition & 0 deletions 11_file_create/exclude_microsoft_windows_update.xml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
3 changes: 2 additions & 1 deletion 11_file_create/include_appc_shim.xml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
1 change: 1 addition & 0 deletions 11_file_create/include_batch_files.xml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
1 change: 1 addition & 0 deletions 11_file_create/include_default_profile_changes.xml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
1 change: 1 addition & 0 deletions 11_file_create/include_downloaded_files.xml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
1 change: 1 addition & 0 deletions 11_file_create/include_drivers_added.xml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
1 change: 1 addition & 0 deletions 11_file_create/include_executables.xml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
1 change: 1 addition & 0 deletions 11_file_create/include_group_policy_changes.xml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
1 change: 1 addition & 0 deletions 11_file_create/include_hta_scripts.xml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
1 change: 1 addition & 0 deletions 11_file_create/include_microsoft_clickonce.xml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
1 change: 1 addition & 0 deletions 11_file_create/include_microsoft_msbuild_scripts.xml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
1 change: 1 addition & 0 deletions 11_file_create/include_ms_office_documents_with_macros.xml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
1 change: 1 addition & 0 deletions 11_file_create/include_outlook_attachments.xml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
1 change: 1 addition & 0 deletions 11_file_create/include_powershell_changes.xml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
1 change: 1 addition & 0 deletions 11_file_create/include_powershell_scripts.xml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
1 change: 1 addition & 0 deletions 11_file_create/include_scheduled_task_changes.xml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
1 change: 1 addition & 0 deletions 11_file_create/include_start_menu_items.xml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
1 change: 1 addition & 0 deletions 11_file_create/include_startup_items.xml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
1 change: 1 addition & 0 deletions 11_file_create/include_system_driver_files.xml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
1 change: 1 addition & 0 deletions 11_file_create/include_visual_basic_scripts.xml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
1 change: 1 addition & 0 deletions 11_file_create/include_wmi_changes.xml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
1 change: 1 addition & 0 deletions 12_13_14_registry_event/exclude_webroot.xml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
1 change: 1 addition & 0 deletions 12_13_14_registry_event/exclude_widcomm_bt_driver.xml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
1 change: 1 addition & 0 deletions 12_13_14_registry_event/exclude_windows_bootup_control.xml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
1 change: 1 addition & 0 deletions 12_13_14_registry_event/exclude_windows_file_exts.xml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
1 change: 1 addition & 0 deletions 12_13_14_registry_event/exclude_windows_misc.xml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
3 changes: 2 additions & 1 deletion 12_13_14_registry_event/include_accessibility_features.xml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
3 changes: 2 additions & 1 deletion 12_13_14_registry_event/include_appc_shim.xml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
3 changes: 2 additions & 1 deletion 12_13_14_registry_event/include_authentication_package.xml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
3 changes: 2 additions & 1 deletion 12_13_14_registry_event/include_bypass_uac.xml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
1 change: 1 addition & 0 deletions 12_13_14_registry_event/include_com_hijack.xml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
3 changes: 2 additions & 1 deletion 12_13_14_registry_event/include_disable_password_change.xml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
3 changes: 2 additions & 1 deletion 12_13_14_registry_event/include_dns_serverdll_injection.xml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
1 change: 1 addition & 0 deletions 12_13_14_registry_event/include_group_policy_integrity.xml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
3 changes: 2 additions & 1 deletion 12_13_14_registry_event/include_local_port_monitor.xml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<Sysmon schemaversion="4.0">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<HashAlgorithms>*</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include"/>
Expand Down
Loading

0 comments on commit b71a02a

Please sign in to comment.