From 3fde11fa4498b2fd0879fd8a2e9c70b2f5ea885e Mon Sep 17 00:00:00 2001 From: Bytewolf Date: Fri, 23 Dec 2022 11:28:58 +0100 Subject: [PATCH 1/5] Update sysmonconfig-export.xml --- sysmonconfig-export.xml | 3023 +++++++++++++++++++++++---------------- 1 file changed, 1824 insertions(+), 1199 deletions(-) diff --git a/sysmonconfig-export.xml b/sysmonconfig-export.xml index 028d373..cd62eca 100644 --- a/sysmonconfig-export.xml +++ b/sysmonconfig-export.xml @@ -1,1200 +1,1825 @@ - - - - - md5,sha256,IMPHASH - - - - - - - - - - - - - - - - - "C:\Windows\system32\wermgr.exe" "-queuereporting_svc" - C:\Windows\system32\DllHost.exe /Processid - C:\Windows\system32\wbem\wmiprvse.exe -Embedding - C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding - C:\Windows\system32\wermgr.exe -upload - C:\Windows\system32\SearchIndexer.exe /Embedding - C:\windows\system32\wermgr.exe -queuereporting - \??\C:\Windows\system32\autochk.exe * - \SystemRoot\System32\smss.exe - C:\Windows\System32\RuntimeBroker.exe -Embedding - C:\Program Files (x86)\Common Files\microsoft shared\ink\TabTip32.exe - C:\Windows\System32\TokenBrokerCookies.exe - C:\Windows\System32\plasrv.exe - C:\Windows\System32\wifitask.exe - C:\Windows\system32\CompatTelRunner.exe - C:\Windows\system32\PrintIsolationHost.exe - C:\Windows\system32\SppExtComObj.Exe - C:\Windows\system32\audiodg.exe - C:\Windows\system32\conhost.exe - C:\Windows\system32\mobsync.exe - C:\Windows\system32\musNotification.exe - C:\Windows\system32\musNotificationUx.exe - C:\Windows\system32\powercfg.exe - C:\Windows\system32\sndVol.exe - C:\Windows\system32\sppsvc.exe - C:\Windows\system32\wbem\WmiApSrv.exe - AppContainer - %%SystemRoot%%\system32\csrss.exe ObjectDirectory=\Windows - C:\windows\system32\wermgr.exe -queuereporting - C:\WINDOWS\system32\devicecensus.exe UserCxt - C:\Windows\System32\usocoreworker.exe -Embedding - C:\Windows\system32\SearchIndexer.exe - - C:\Windows\system32\svchost.exe -k appmodel -s StateRepository - C:\Windows\system32\svchost.exe -k appmodel -p -s camsvc - C:\Windows\system32\svchost.exe -k appmodel - C:\Windows\system32\svchost.exe -k appmodel -p -s tiledatamodelsvc - C:\Windows\system32\svchost.exe -k camera -s FrameServer - C:\Windows\system32\svchost.exe -k dcomlaunch -s LSM - C:\Windows\system32\svchost.exe -k dcomlaunch -s PlugPlay - C:\Windows\system32\svchost.exe -k defragsvc - C:\Windows\system32\svchost.exe -k devicesflow -s DevicesFlowUserSvc - C:\Windows\system32\svchost.exe -k imgsvc - C:\Windows\system32\svchost.exe -k localService -s EventSystem - C:\Windows\system32\svchost.exe -k localService -s bthserv - C:\Windows\system32\svchost.exe -k LocalService -p -s BthAvctpSvc - C:\Windows\system32\svchost.exe -k localService -s nsi - C:\Windows\system32\svchost.exe -k localService -s w32Time - C:\Windows\system32\svchost.exe -k localServiceAndNoImpersonation - C:\Windows\system32\svchost.exe -k localServiceAndNoImpersonation -p - C:\Windows\system32\svchost.exe -k localServiceNetworkRestricted -s Dhcp - C:\Windows\system32\svchost.exe -k localServiceNetworkRestricted -s EventLog - C:\Windows\system32\svchost.exe -k localServiceNetworkRestricted -s TimeBrokerSvc - C:\Windows\system32\svchost.exe -k localServiceNetworkRestricted -s WFDSConMgrSvc - C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -s BTAGService - C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s NcbService - C:\Windows\system32\svchost.exe -k localServiceNetworkRestricted - C:\Windows\system32\svchost.exe -k localServiceAndNoImpersonation -s SensrSvc - C:\Windows\system32\svchost.exe -k localServiceAndNoImpersonation -p -s SSDPSRV - C:\Windows\system32\svchost.exe -k localServiceNoNetwork - C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -p -s WPDBusEnum - C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -p -s fhsvc - C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s DeviceAssociationService - C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s NcbService - C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s SensorService - C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s TabletInputService - C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s UmRdpService - C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s WPDBusEnum - C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -p -s NgcSvc - C:\Windows\system32\svchost.exe -k localServiceNetworkRestricted -p -s NgcCtnrSvc - C:\Windows\system32\svchost.exe -k localServiceAndNoImpersonation -s SCardSvr - C:\Windows\system32\svchost.exe -k netsvcs -p -s wuauserv - C:\Windows\System32\svchost.exe -k netsvcs -p -s SessionEnv - C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s WdiSystemHost - C:\Windows\System32\svchost.exe -k localSystemNetworkRestricted -p -s WdiSystemHost - C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted - C:\Windows\system32\svchost.exe -k netsvcs -p -s wlidsvc - C:\Windows\system32\svchost.exe -k netsvcs -p -s ncaSvc - C:\Windows\system32\svchost.exe -k netsvcs -s BDESVC - C:\Windows\System32\svchost.exe -k netsvcs -p -s BDESVC - C:\Windows\system32\svchost.exe -k netsvcs -p -s BITS - C:\Windows\system32\svchost.exe -k netsvcs -s BITS - C:\Windows\system32\svchost.exe -k netsvcs -s CertPropSvc - C:\Windows\system32\svchost.exe -k netsvcs -s DsmSvc - C:\Windows\system32\svchost.exe -k netsvcs -p -s Appinfo - C:\Windows\system32\svchost.exe -k netsvcs -s Gpsvc - C:\Windows\system32\svchost.exe -k netsvcs -s ProfSvc - C:\Windows\system32\svchost.exe -k netsvcs -s SENS - C:\Windows\system32\svchost.exe -k netsvcs -s SessionEnv - C:\Windows\system32\svchost.exe -k netsvcs -s Themes - C:\Windows\system32\svchost.exe -k netsvcs -s Winmgmt - C:\Windows\system32\svchost.exe -k netsvcs - C:\Windows\system32\svchost.exe -k networkService -p -s DoSvc - C:\Windows\system32\svchost.exe -k networkService -s Dnscache - C:\Windows\system32\svchost.exe -k networkService -s LanmanWorkstation - C:\Windows\system32\svchost.exe -k networkService -s NlaSvc - C:\Windows\system32\svchost.exe -k networkService -s TermService - C:\Windows\system32\svchost.exe -k networkService - C:\Windows\system32\svchost.exe -k networkService -p - C:\Windows\system32\svchost.exe -k networkServiceNetworkRestricted - C:\Windows\system32\svchost.exe -k rPCSS - C:\Windows\system32\svchost.exe -k secsvcs - C:\Windows\system32\svchost.exe -k swprv - C:\Windows\system32\svchost.exe -k unistackSvcGroup - C:\Windows\system32\svchost.exe -k utcsvc - C:\Windows\system32\svchost.exe -k wbioSvcGroup - C:\Windows\system32\svchost.exe -k werSvcGroup - C:\Windows\system32\svchost.exe -k wusvcs -p -s WaaSMedicSvc - C:\Windows\System32\svchost.exe -k wsappx -p -s ClipSVC - C:\Windows\system32\svchost.exe -k wsappx -p -s AppXSvc - C:\Windows\system32\svchost.exe -k wsappx -s ClipSVC - C:\Windows\system32\svchost.exe -k wsappx - C:\Windows\system32\svchost.exe -k netsvcs - C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted - C:\Windows\system32\deviceenroller.exe /c /AutoEnrollMDM - - "C:\Program Files (x86)\Microsoft\Edge Dev\Application\msedge.exe" --type= - - C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe - C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\Ngen.exe - C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngentask.exe - C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\ngentask.exe - C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe - C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe - C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngentask.exe - C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe - C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngentask.exe - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe - C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngentask.exe - - C:\Program Files\Microsoft Office\Office16\MSOSYNC.EXE - C:\Program Files (x86)\Microsoft Office\Office16\MSOSYNC.EXE - C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE - C:\Program Files\Microsoft Office\Office16\msoia.exe - C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe - - C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe - C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe - C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe - - C:\Program Files\Windows Media Player\wmpnscfg.exe - - "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type= - "C:\Program Files\Google\Chrome\Application\chrome.exe" --type= - - - - - - - - - - C:\Users - .exe - \Device\HarddiskVolumeShadowCopy - - - - - - OneDrive.exe - C:\Windows\system32\backgroundTaskHost.exe - setup - install - Update\ - redist.exe - msiexec.exe - TrustedInstaller.exe - \NVIDIA\NvBackend\ApplicationOntology\ - - - - - - - - - - - - - - - - - C:\Users - C:\Recycle - C:\ProgramData - C:\Windows\Temp - \ - C:\perflogs - C:\intel - C:\Windows\fonts - C:\Windows\system32\config - - at.exe - certutil.exe - cmd.exe - cmstp.exe - cscript.exe - driverquery.exe - dsquery.exe - hh.exe - infDefaultInstall.exe - java.exe - javaw.exe - javaws.exe - mmc.exe - msbuild.exe - mshta.exe - msiexec.exe - nbtstat.exe - net.exe - net1.exe - notepad.exe - nslookup.exe + + + + + * + + + + + + + + + + + + + + + + + + + C:\Windows\system32\svchost.exe + C:\ProgramData\Microsoft\Windows Defender\platform\ + MsMpEng.exe + + C:\ProgramData\Microsoft\Windows Defender\Platform\ + MsMpEng.exe + + + + + + \Machine\Scripts\Startup\ipamprovisioning.ps1 + + + "C:\Windows\system32\wermgr.exe" "-queuereporting_svc" + C:\Windows\system32\DllHost.exe /Processid + C:\Windows\system32\wbem\wmiprvse.exe -Embedding + C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding + C:\Windows\system32\wermgr.exe -upload + C:\Windows\system32\SearchIndexer.exe /Embedding + C:\windows\system32\wermgr.exe -queuereporting + \??\C:\Windows\system32\autochk.exe * + \SystemRoot\System32\smss.exe + C:\Windows\System32\RuntimeBroker.exe -Embedding + C:\Program Files (x86)\Common Files\microsoft shared\ink\TabTip32.exe + C:\Windows\System32\TokenBrokerCookies.exe + C:\Windows\System32\plasrv.exe + C:\Windows\System32\wifitask.exe + C:\Windows\system32\CompatTelRunner.exe + C:\Windows\system32\PrintIsolationHost.exe + C:\Windows\system32\SppExtComObj.Exe + C:\Windows\system32\audiodg.exe + C:\Windows\system32\conhost.exe + C:\Windows\system32\mobsync.exe + C:\Windows\system32\musNotification.exe + C:\Windows\system32\musNotificationUx.exe + C:\Windows\system32\powercfg.exe + C:\Windows\system32\sndVol.exe + C:\Windows\system32\sppsvc.exe + C:\Windows\system32\wbem\WmiApSrv.exe + AppContainer + %%SystemRoot%%\system32\csrss.exe ObjectDirectory=\Windows + C:\windows\system32\wermgr.exe -queuereporting + C:\WINDOWS\system32\devicecensus.exe UserCxt + C:\Windows\System32\usocoreworker.exe -Embedding + C:\Windows\system32\SearchIndexer.exe + + + C:\Windows\system32\svchost.exe -k appmodel -s StateRepository + C:\Windows\system32\svchost.exe -k appmodel -p -s camsvc + C:\Windows\system32\svchost.exe -k appmodel + C:\Windows\system32\svchost.exe -k appmodel -p -s tiledatamodelsvc + C:\Windows\system32\svchost.exe -k camera -s FrameServer + C:\Windows\system32\svchost.exe -k dcomlaunch -s LSM + C:\Windows\system32\svchost.exe -k dcomlaunch -s PlugPlay + C:\Windows\system32\svchost.exe -k defragsvc + C:\Windows\system32\svchost.exe -k devicesflow -s DevicesFlowUserSvc + C:\Windows\system32\svchost.exe -k imgsvc + C:\Windows\system32\svchost.exe -k localService -s EventSystem + C:\Windows\system32\svchost.exe -k localService -s bthserv + C:\Windows\system32\svchost.exe -k LocalService -p -s BthAvctpSvc + C:\Windows\system32\svchost.exe -k localService -s nsi + C:\Windows\system32\svchost.exe -k localService -s w32Time + C:\Windows\system32\svchost.exe -k localServiceAndNoImpersonation + C:\Windows\system32\svchost.exe -k localServiceAndNoImpersonation -p + C:\Windows\system32\svchost.exe -k localServiceNetworkRestricted -s Dhcp + C:\Windows\system32\svchost.exe -k localServiceNetworkRestricted -s EventLog + C:\Windows\system32\svchost.exe -k localServiceNetworkRestricted -s TimeBrokerSvc + C:\Windows\system32\svchost.exe -k localServiceNetworkRestricted -s WFDSConMgrSvc + C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -s BTAGService + C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s NcbService + C:\Windows\system32\svchost.exe -k localServiceNetworkRestricted + C:\Windows\system32\svchost.exe -k localServiceAndNoImpersonation -s SensrSvc + C:\Windows\system32\svchost.exe -k localServiceAndNoImpersonation -p -s SSDPSRV + C:\Windows\system32\svchost.exe -k localServiceNoNetwork + C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -p -s WPDBusEnum + C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -p -s fhsvc + C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s DeviceAssociationService + C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s NcbService + C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s SensorService + C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s TabletInputService + C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s UmRdpService + C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s WPDBusEnum + C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -p -s NgcSvc + C:\Windows\system32\svchost.exe -k localServiceNetworkRestricted -p -s NgcCtnrSvc + C:\Windows\system32\svchost.exe -k localServiceAndNoImpersonation -s SCardSvr + C:\Windows\system32\svchost.exe -k netsvcs -p -s wuauserv + C:\Windows\System32\svchost.exe -k netsvcs -p -s SessionEnv + C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s WdiSystemHost + C:\Windows\System32\svchost.exe -k localSystemNetworkRestricted -p -s WdiSystemHost + C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted + C:\Windows\system32\svchost.exe -k netsvcs -p -s wlidsvc + C:\Windows\system32\svchost.exe -k netsvcs -p -s ncaSvc + C:\Windows\system32\svchost.exe -k netsvcs -s BDESVC + C:\Windows\System32\svchost.exe -k netsvcs -p -s BDESVC + C:\Windows\system32\svchost.exe -k netsvcs -p -s BITS + C:\Windows\system32\svchost.exe -k netsvcs -s BITS + C:\Windows\system32\svchost.exe -k netsvcs -s CertPropSvc + C:\Windows\system32\svchost.exe -k netsvcs -s DsmSvc + C:\Windows\system32\svchost.exe -k netsvcs -p -s Appinfo + C:\Windows\system32\svchost.exe -k netsvcs -s Gpsvc + C:\Windows\system32\svchost.exe -k netsvcs -s ProfSvc + C:\Windows\system32\svchost.exe -k netsvcs -s SENS + C:\Windows\system32\svchost.exe -k netsvcs -s SessionEnv + C:\Windows\system32\svchost.exe -k netsvcs -s Themes + C:\Windows\system32\svchost.exe -k netsvcs -s Winmgmt + C:\Windows\system32\svchost.exe -k netsvcs + C:\Windows\system32\svchost.exe -k networkService -p -s DoSvc + C:\Windows\system32\svchost.exe -k networkService -s Dnscache + C:\Windows\system32\svchost.exe -k networkService -s LanmanWorkstation + C:\Windows\system32\svchost.exe -k networkService -s NlaSvc + C:\Windows\system32\svchost.exe -k networkService -s TermService + C:\Windows\system32\svchost.exe -k networkService + C:\Windows\system32\svchost.exe -k networkService -p + C:\Windows\system32\svchost.exe -k networkServiceNetworkRestricted + C:\Windows\system32\svchost.exe -k rPCSS + C:\Windows\system32\svchost.exe -k secsvcs + C:\Windows\system32\svchost.exe -k swprv + C:\Windows\system32\svchost.exe -k unistackSvcGroup + C:\Windows\system32\svchost.exe -k utcsvc + C:\Windows\system32\svchost.exe -k wbioSvcGroup + C:\Windows\system32\svchost.exe -k werSvcGroup + C:\Windows\system32\svchost.exe -k wusvcs -p -s WaaSMedicSvc + C:\Windows\System32\svchost.exe -k wsappx -p -s ClipSVC + C:\Windows\system32\svchost.exe -k wsappx -p -s AppXSvc + C:\Windows\system32\svchost.exe -k wsappx -s ClipSVC + C:\Windows\system32\svchost.exe -k wsappx + C:\Windows\system32\svchost.exe -k netsvcs + C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted + C:\Windows\system32\deviceenroller.exe /c /AutoEnrollMDM + + "C:\Program Files (x86)\Microsoft\Edge Dev\Application\msedge.exe" --type= + + C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe + C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\Ngen.exe + C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngentask.exe + C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\ngentask.exe + C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe + C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe + C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe + C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngentask.exe + C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe + C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngentask.exe + C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe + C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngentask.exe + + C:\Program Files\Microsoft Office\Office16\MSOSYNC.EXE + C:\Program Files (x86)\Microsoft Office\Office16\MSOSYNC.EXE + C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE + C:\Program Files\Microsoft Office\Office16\msoia.exe + C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe + + C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe + C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe + C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe + + C:\Program Files\Windows Media Player\wmpnscfg.exe + + "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type= + "C:\Program Files\Google\Chrome\Application\chrome.exe" --type= + + + + + + + + + + C:\Users + .exe + \Device\HarddiskVolumeShadowCopy + + + + + + OneDrive.exe + C:\Windows\system32\backgroundTaskHost.exe + setup + install + Update\ + redist.exe + msiexec.exe + TrustedInstaller.exe + \NVIDIA\NvBackend\ApplicationOntology\ + + + + + + + + + + + + + + + + + C:\Users + C:\Recycle + C:\ProgramData + C:\Windows\Temp + C:\Temp + \ + C:\perflogs + C:\intel + C:\Windows\fonts + C:\Windows\system32\config + + + at.exe + certutil.exe + cmd.exe + cmstp.exe + cscript.exe + driverquery.exe + dsquery.exe + hh.exe + infDefaultInstall.exe + java.exe + javaw.exe + javaws.exe + mmc.exe + msbuild.exe + mshta.exe + msiexec.exe + nbtstat.exe + net.exe + net1.exe + notepad.exe + nslookup.exe powershell.exe - powershell_ise.exe - qprocess.exe - qwinsta.exe - qwinsta.exe - reg.exe - regsvcs.exe - regsvr32.exe - rundll32.exe - rwinsta.exe - sc.exe - schtasks.exe - taskkill.exe - tasklist.exe - wmic.exe - wscript.exe - - bitsadmin.exe - esentutl.exe - expand.exe - extrac32.exe - findstr.exe - GfxDownloadWrapper.exe - ieexec.exe - makecab.exe - replace.exe - Excel.exe - Powerpnt.exe - Winword.exe - squirrel.exe - - nc.exe - ncat.exe - psexec.exe - psexesvc.exe - tor.exe - vnc.exe - vncservice.exe - vncviewer.exe - winexesvc.exe - nmap.exe - psinfo.exe - - 22 - 23 - 25 - 143 - 3389 - 5800 - 5900 - 4444 - - 1080 - 3128 - 8080 - - 1723 - 9001 - 9030 - - - - - - - C:\ProgramData\Microsoft\Windows Defender\Platform\ - AppData\Local\Microsoft\Teams\current\Teams.exe - .microsoft.com - microsoft.com.akadns.net - microsoft.com.nsatc.net - - 23.4.43.27 - 72.21.91.29 - - 127.0.0.1 - fe80:0:0:0 - - - - - - - - - - - - - - - C:\Users - \ - - - - - - - - - - - - - - - - microsoft - windows - Intel - - - - - - - - - - - - - - - - - - - - - - C:\Windows\system32\wbem\WmiPrvSE.exe - C:\Windows\system32\svchost.exe - C:\Windows\system32\wininit.exe - C:\Windows\system32\csrss.exe - C:\Windows\system32\services.exe - C:\Windows\system32\winlogon.exe - C:\Windows\system32\audiodg.exe - C:\Windows\system32\kernel32.dll - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - \Start Menu - \Startup\ - \Content.Outlook\ - \Downloads\ - .application - .appref-ms - .bat - .chm - .cmd - .cmdline - .crx - .dmp - .docm - .dll - .exe - .exe.log - .jar - .jnlp - .jse - .hta - .job - .pptm - .ps1 - .sct - .sys - .scr - .vbe - .vbs - .wsc - .wsf - .xlsm - .ocx - proj - .sln - .xls - C:\Users\Default - C:\Windows\system32\Drivers - C:\Windows\SysWOW64\Drivers - C:\Windows\system32\GroupPolicy\Machine\Scripts - C:\Windows\system32\GroupPolicy\User\Scripts - C:\Windows\system32\Wbem - C:\Windows\SysWOW64\Wbem - C:\Windows\system32\WindowsPowerShell - C:\Windows\SysWOW64\WindowsPowerShell - C:\Windows\Tasks\ - C:\Windows\system32\Tasks - C:\Windows\SysWOW64\Tasks - \Device\HarddiskVolumeShadowCopy - - C:\Windows\AppPatch\Custom - VirtualStore - - .xls - .ppt - .rtf - - - - - - - C:\Program Files (x86)\EMET 5.5\EMET_Service.exe - - C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe - - C:\Windows\system32\smss.exe - C:\Windows\system32\CompatTelRunner.exe - \\?\C:\Windows\system32\wbem\WMIADAP.EXE - C:\Windows\system32\mobsync.exe - C:\Windows\system32\DriverStore\Temp\ - C:\Windows\system32\wbem\Performance\ - C:\Windows\Installer\ - - C:\$WINDOWS.~BT\Sources\ - C:\Windows\winsxs\amd64_microsoft-windows - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - CurrentVersion\Run - Policies\Explorer\Run - Group Policy\Scripts - Windows\System\Scripts - CurrentVersion\Windows\Load - CurrentVersion\Windows\Run - CurrentVersion\Winlogon\Shell - CurrentVersion\Winlogon\System - HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify - HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell - HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit - HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32 - HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\BootExecute - HKLM\Software\Microsoft\Windows NT\CurrentVersion\AeDebug - UserInitMprLogonScript - user shell folders\startup - - \ServiceDll - \ServiceManifest - \ImagePath - \Start - - Control\Terminal Server\WinStations\RDP-Tcp\PortNumber - Control\Terminal Server\fSingleSessionPerUser - fDenyTSConnections - LastLoggedOnUser - RDP-tcp\PortNumber - Services\PortProxy\v4tov4 - - \command\ - \ddeexec\ - {86C86720-42A0-1069-A2E8-08002B30309D} - exefile - - \InprocServer32\(Default) - - \Hidden - \ShowSuperHidden - \HideFileExt - - Classes\*\ - Classes\AllFilesystemObjects\ - Classes\Directory\ - Classes\Drive\ - Classes\Folder\ - Classes\PROTOCOLS\ - ContextMenuHandlers\ - CurrentVersion\Shell - HKLM\Software\Microsoft\Windows\CurrentVersion\explorer\ShellExecuteHooks - HKLM\Software\Microsoft\Windows\CurrentVersion\explorer\ShellServiceObjectDelayLoad - HKLM\Software\Microsoft\Windows\CurrentVersion\explorer\ShellIconOverlayIdentifiers - - HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\ - - HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp\InitialProgram - - HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\ - - HKLM\SYSTEM\CurrentControlSet\Services\WinSock - \ProxyServer - - HKLM\Software\Microsoft\Windows\CurrentVersion\Authentication\Credential Provider - HKLM\SYSTEM\CurrentControlSet\Control\Lsa\ - HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders - HKLM\Software\Microsoft\Netsh - Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable - - HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order\ - HKLM\Software\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles - \EnableFirewall - \DoNotAllowExceptions - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List - - HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\Appinit_Dlls\ - HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows\Appinit_Dlls\ - HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls\ - - Microsoft\Office\Outlook\Addins\ - Office Test\ - Security\Trusted Documents\TrustRecords - \EnableBHO - - Internet Explorer\Toolbar\ - Internet Explorer\Extensions\ - Browser Helper Objects\ - \DisableSecuritySettingsCheck - \3\1206 - \3\2500 - \3\1809 - - HKLM\Software\Classes\CLSID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\ - HKLM\Software\Classes\WOW6432Node\CLSID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\ - HKLM\Software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\ - HKLM\Software\Classes\WOW6432Node\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\ - - \UrlUpdateInfo - \InstallSource - \EulaAccepted - - \DisableAntiSpyware - \DisableAntiVirus - \SpynetReporting - DisableRealtimeMonitoring - \SubmitSamplesConsent - HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\ - - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\LocalAccountTokenFilterPolicy - - HKLM\Software\Microsoft\Security Center\ - SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\HideSCAHealth - - HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom - HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\InstalledSDB - VirtualStore - - HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ - HKLM\Software\Microsoft\Windows\CurrentVersion\WINEVT\ - HKLM\SYSTEM\CurrentControlSet\Control\Safeboot\ - HKLM\SYSTEM\CurrentControlSet\Control\Winlogon\ - \FriendlyName - HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\InProgress\(Default) - HKLM\Software\Microsoft\Tracing\RASAPI32 - HKLM\Software\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\ConsentStore\ - \Keyboard Layout\Preload - \Keyboard Layout\Substitutes - - \LowerCaseLongPath - \Publisher - \BinProductVersion - \DriverVersion - \DriverVerVersion - \LinkDate - Compatibility Assistant\Store\ - - regedit.exe - \ - - - - - - - - \{CAFEEFAC- - CreateKey - HKLM\COMPONENTS - - HKLM\Software\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache - - Toolbar\WebBrowser - Browser\ITBar7Height - Browser\ITBar7Layout - Internet Explorer\Toolbar\Locked - Toolbar\WebBrowser\{47833539-D0C5-4125-9FA8-0819E2EAAC93} - }\PreviousPolicyAreas - \Control\WMI\Autologger\ - HKLM\SYSTEM\CurrentControlSet\Services\UsoSvc\Start - \Lsa\OfflineJoin\CurrentValue - HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\ - _Classes\AppX - HKLM\Software\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\ - - HKLM\SYSTEM\CurrentControlSet\Control\Lsa\LsaPid - HKLM\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache - HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Domains - - \Services\BITS\Start - \services\clr_optimization_v2.0.50727_32\Start - \services\clr_optimization_v2.0.50727_64\Start - \services\clr_optimization_v4.0.30319_32\Start - \services\clr_optimization_v4.0.30319_64\Start - \services\deviceAssociationService\Start - \services\fhsvc\Start - \services\nal\Start - \services\trustedInstaller\Start - \services\tunnel\Start - \services\usoSvc\Start - - \UserChoice\ProgId - \UserChoice\Hash - \OpenWithList\MRUList - Shell Extentions\Cached - - HKLM\System\CurrentControlSet\Control\Lsa\Audit\SpecialGroups - SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Startup\0\PSScriptOrder - SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Startup\0\SOM-ID - SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Startup\0\GPO-ID - SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Startup\0\0\IsPowershell - SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Startup\0\0\ExecTime - SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Shutdown\0\PSScriptOrder - SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Shutdown\0\SOM-ID - SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Shutdown\0\GPO-ID - SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Shutdown\0\0\IsPowershell - SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Shutdown\0\0\ExecTime - \safer\codeidentifiers\0\HASHES\{ - - VirtualStore\MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\ - HKLM\SOFTWARE\Microsoft\Office\ClickToRun\ - - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe - HKCR\VLC. - HKCR\iTunes. - - HKLM\Software\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{945a8954-c147-4acd-923f-40c45405a658} - - - - - - - - - - - Downloads - Temp\7z - Startup - .bat - .cmd - .doc - .hta - .jse - .lnk - .ppt - .ps1 - .ps2 - .reg - .sct - .vb - .vbe - .vbs - .wsc - .wsf - - - - - - - - - - - - - - - - - - - - - - - - - - paexec;remcom;csexec - - \lsadump;\cachedump;\wceservicepipe - - \isapi_http;\isapi_dg;\isapi_dg2;\sdlrpc;\ahexec;\winsession;\lsassw;\46a676ab7f179e511e30dd2dc41bd388;\9f81f59bc58452127884ce513865ed20;\e710f28d59aa529d6792ca6ff0ca1b34;\rpchlp_3;\NamePipe_MoreWindows;\pcheap_reuse;\gruntsvc;\583da945-62af-10e8-4902-a8f205c72b2e;\bizkaz;\svcctl;\Posh;\jaccdpqnvbrrxlaf;\csexecsvc - \atctl;\userpipe;\iehelper;\sdlrpc;\comnap - - MSSE-;-server - \postex_ - \postex_ssh_ - \status_ - \msagent_ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - .arpa. - .arpa - .msftncsi.com - ..localmachine - localhost - - -pushp.svc.ms - .b-msedge.net - .bing.com - .hotmail.com - .live.com - .live.net - .s-microsoft.com - .microsoft.com - .microsoftonline.com - .microsoftstore.com - .ms-acdc.office.com - .msedge.net - .msn.com - .msocdn.com - .skype.com - .skype.net - .windows.com - .windows.net.nsatc.net - .windowsupdate.com - .xboxlive.com - login.windows.net - C:\ProgramData\Microsoft\Windows Defender\Platform\ - - .activedirectory.windowsazure.com - .aria.microsoft.com - .msauth.net - .msftauth.net - .office.net - .opinsights.azure.com - .res.office365.com - acdc-direct.office.com - atm-fp-direct.office.com - loki.delve.office.com - management.azure.com - messaging.office.com - outlook.office365.com - portal.azure.com - protection.outlook.com - substrate.office.com - .measure.office.com - - .adobe.com - .adobe.io - .mozaws.net - .mozilla.com - .mozilla.net - .mozilla.org - .spotify.com - .spotify.map.fastly.net - .wbx2.com - .webex.com - clients1.google.com - clients2.google.com - clients3.google.com - clients4.google.com - clients5.google.com - clients6.google.com - safebrowsing.googleapis.com - - .akadns.net - .netflix.com - aspnetcdn.com - ajax.googleapis.com - cdnjs.cloudflare.com - fonts.googleapis.com - .typekit.net - cdnjs.cloudflare.com - .stackassets.com - .steamcontent.com - play.google.com - content-autofill.googleapis.com - - .disqus.com - .fontawesome.com - disqus.com - - .1rx.io - .2mdn.net - .3lift.com - .adadvisor.net - .adap.tv - .addthis.com - .adform.net - .adnxs.com - .adroll.com - .adrta.com - .adsafeprotected.com - .adsrvr.org - .adsymptotic.com - .advertising.com - .agkn.com - .amazon-adsystem.com - .amazon-adsystem.com - .analytics.yahoo.com - .aol.com - .betrad.com - .bidswitch.net - .casalemedia.com - .chartbeat.net - .cnn.com - .convertro.com - .criteo.com - .criteo.net - .crwdcntrl.net - .demdex.net - .domdex.com - .dotomi.com - .doubleclick.net - .doubleverify.com - .emxdgt.com - .everesttech.net - .exelator.com - .google-analytics.com - .googleadservices.com - .googlesyndication.com - .googletagmanager.com - .googlevideo.com - .gstatic.com - .gvt1.com - .gvt2.com - .ib-ibi.com - .jivox.com - .krxd.net - .lijit.com - .mathtag.com - .moatads.com - .moatpixel.com - .mookie1.com - .myvisualiq.net - .netmng.com - .nexac.com - .openx.net - .optimizely.com - .outbrain.com - .pardot.com - .phx.gbl - .pinterest.com - .pubmatic.com - .quantcount.com - .quantserve.com - .revsci.net - .rfihub.net - .rlcdn.com - .rubiconproject.com - .scdn.co - .scorecardresearch.com - .serving-sys.com - .sharethrough.com - .simpli.fi - .sitescout.com - .smartadserver.com - .snapads.com - .spotxchange.com - .taboola.com - .taboola.map.fastly.net - .tapad.com - .tidaltv.com - .trafficmanager.net - .tremorhub.com - .tribalfusion.com - .turn.com - .twimg.com - .tynt.com - .w55c.net - .ytimg.com - .zorosrv.com - 1rx.io - adservice.google.com - ampcid.google.com - clientservices.googleapis.com - googleadapis.l.google.com - imasdk.googleapis.com - l.google.com - ml314.com - mtalk.google.com - update.googleapis.com - www.googletagservices.com - - .pscp.tv - - .amazontrust.com - .digicert.com - .globalsign.com - .globalsign.net - .intel.com - .symcb.com - .symcd.com - .thawte.com - .usertrust.com - .verisign.com - ocsp.identrust.com - pki.goog - msocsp.com - ocsp.comodoca.com - ocsp.entrust.net - ocsp.godaddy.com - ocsp.int-x3.letsencrypt.org - ocsp.msocsp.com - pki.goog - ocsp.godaddy.com - amazontrust.com - ocsp.sectigo.com - pki-goog.l.google.com - .usertrust.com - ocsp.comodoca.com - ocsp.verisign.com - ocsp.entrust.net - ocsp.identrust.com - status.rapidssl.com - status.thawte.com - ocsp.int-x3.letsencrypt.org - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + powershell_ise.exe + qprocess.exe + qwinsta.exe + reg.exe + regsvcs.exe + regsvr32.exe + rundll32.exe + rwinsta.exe + sc.exe + schtasks.exe + taskkill.exe + tasklist.exe + wmic.exe + wscript.exe + + + bitsadmin.exe + esentutl.exe + expand.exe + extrac32.exe + findstr.exe + GfxDownloadWrapper.exe + ieexec.exe + makecab.exe + replace.exe + Excel.exe + Powerpnt.exe + Winword.exe + squirrel.exe + + + netcat.exe + nc.exe + nc64.exe + ncat.exe + procdump.exe + procdump64.exe + psexec.exe + psexec64.exe + psexesvc.exe + tor.exe + vnc.exe + vncservice.exe + vncviewer.exe + winexesvc.exe + nmap.exe + psinfo.exe + + + SyncAppvPublishingServer.exe + Mavinject.exe + + + 22 + 23 + 25 + 143 + 3389 + 5800 + 5900 + 4444 + 5985 + 5986 + + + 1080 + 3128 + 8080 + + + 1723 + 9001 + 9030 + 9040 + 9050 + 9051 + 9150 + + + + + + + C:\ProgramData\Microsoft\Windows Defender\Platform\ + AppData\Local\Microsoft\Teams\current\Teams.exe + microsoft.com + .microsoft.com + + + 23.4.43.27 + 72.21.91.29 + microsoft.com.akadns.net + .microsoft.com.nsatc.net + + 127.0.0.1 + fe80:0:0:0 + + + + + + + + + + + + + + + C:\Users + \ + + + + + + + + + + + + + + + + microsoft + windows + Intel + + + + + + + + + + + + + + + + + + + + + + C:\Windows\system32\wbem\WmiPrvSE.exe + C:\Windows\system32\svchost.exe + C:\Windows\system32\wininit.exe + C:\Windows\system32\csrss.exe + C:\Windows\system32\services.exe + C:\Windows\system32\winlogon.exe + C:\Windows\system32\audiodg.exe + C:\Windows\system32\kernel32.dll + C:\Program Files (x86)\Google\Chrome\Application\chrome.exe + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + \Start Menu + \Startup\ + \Content.Outlook\ + \Downloads\ + .application + .appref-ms + .bat + .chm + .cmd + .cmdline + .crx + .dmp + .docm + .dll + .exe + .exe.log + .jar + .jnlp + .jse + .js + .hta + .aspx + .asp + .job + .pptm + .ps1 + .sct + .sys + .scr + .vbe + .vbs + .wsc + .wsf + .xlsm + .ocx + proj + .sln + .xls + C:\Users\Default + C:\Windows\system32\Drivers + C:\Windows\SysWOW64\Drivers + C:\Windows\system32\GroupPolicy\Machine\Scripts + C:\Windows\system32\GroupPolicy\User\Scripts + C:\Windows\system32\Wbem + C:\Windows\SysWOW64\Wbem + C:\Windows\system32\WindowsPowerShell + C:\Windows\SysWOW64\WindowsPowerShell + C:\Windows\Tasks\ + C:\Windows\system32\Tasks + C:\Windows\SysWOW64\Tasks + \Device\HarddiskVolumeShadowCopy + + C:\Windows\AppPatch\Custom + VirtualStore + + .xls + .ppt + .rtf + + .php + .asp + .aspx + .ashx + .jsp + .pl + + \SAM-20 + \SAM-haxx + \Sam.save + \hive_sam_ + C:\windows\temp\sam + C:\Windows\System32\spool\drivers\x64 + + + decrypt all files + _h_e_l_p_recover_instructions + help_recover_instructions + how_recover + @please_read_me@ + -read-for-hellpp.html + readme_decrypt_hydra_id_ + readme_decrypt_umbre_id_ + recover_files_ + recover_file_ + recovery_file_ + recovery + -sorry-for-files.html + @wanadecryptor@.exe + about_files.txt + allfilesarelocked_.bmp + attention.rtf + bitcryptorfilelist.txt + bleepedfiles.txt + buyunlockcode + coin.locker.txt + cryptinfo.txt + cryptlogfile.txt + decrypt all files *.bmp + decryptallfiles.txt + decryptallfiles_.txt + decrypt_instructions.html + decrypt_instructions.txt + decrypt_instruction.txt + # decrypt my files #.html + # decrypt my files #.txt + # decrypt my files #.vbs + decrypt_readme.txt.readme + decrypt_readme.txt + decrypt_your_files.html + encryptor_raas_readme_liesmich.txt + exit.hhr.obleep + filesaregone.txt + getyoufiles.txt + hellothere.txt + help_decrypt.txt + help_decrypt_your_files.html + help_decyprt_your_files.html + *-help_for_decrypt_file.html + help recover files.txt + help_recover_files.txt + help_restore_files.txt + help_to_decrypt_your_files.txt + help_to_save_files.txt + help_yourfiles.html + help_your_files.txt + howdecrypt.gif + how_decrypt.txt + _how_recover_.txt + how to decrypt files.html + how-to-decrypt-files.html + how to decrypt files.txt + how_to_decrypt_files.txt + how_to_decrypt.html + how to get data.txt + how_to_recover_files.txt + howto_recover_file_.txt + how_to_restore_files.txt + howto_restore_files.txt + howto_restore_files_.txt + iamreadytopay.txt + ihaveyoursecret.key + important read me.txt + kryptolocker_readme.txt + _locky_recover_instructions.txt + nefilim-decrypt.txt + qwer2.html + qwer.html + readdecryptfileshere.txt + read if you want your files back.html + readme10.txt + readme1.txt + readme2.txt + readme3.txt + readme4.txt + readme5.txt + readme6.txt + readme7.txt + readme8.txt + readme9.txt + readme.txt + readthisnow!!!.txt + read.txt + recovery_files.txt + recovery_file.txt + recovery_key.txt + restore_files_.txt + ryukreadme.html + _secret_code.txt + secretidhere.key + secret.key + unblockfiles.vbs + your_files_are_encrypted.html + your_files.html + your_files.url + + cpyt + crypt + darkness + decipher + enc + exx + @gmail_com_ + help_restore + help_your_files + how_to_recover + .hydracrypt_id_ + @india.com + install_tor + keemail.me + qq_com + restore_fi + ukr.net + .unbrecrypt_id_ + want your files back + .0x0 + .1999 + .1cbu1 + .1txt + .73i87a + .777 + .7h9r + .8lock8 + .a5zfn + .aaa + .abc + .adk + .adr + .aes256 + aes256 + .aesir + .afd + .aga + ._airacropencrypted + .alcatraz + .amba + .angelamerkel + .angleware + .antihacker2017 + .areyoulovemyransfile + .areyoulovemyrans + .asier + .atlas + .axx + .barrax + .bart + .bart.zip + .better_call_saul + .bin + .bitstak + .bleep + .bleepyourfiles + .blocatto + .bloc + .braincrypt + .breaking_bad + .breeding123 + .bript + .btcbtcbtc + .btc-help-you + .btc + .canihelpyou + .cbf + .cccrrrppp + .ccc + .cerber2 + .cerber3 + .cerber + .checkdiskenced + .chifrator@qq_com + .cifgksaffsfyghd + .clf + .coded + .code + .comrade + .conficker + .confirmation.key + .country82000 + .coverton + .crab + .crashed + .crime + .crinf + .criptiko + .criptokod + .criptoko + .cripttt + .crjocker + .crjoker + .crptrgr + .crrrt + .cryeye + .cryp1 + .crypt38 + .crypted + .crypte + .cryptolocker + .crypto + crypto + .cryptotorlocker2015! + .cryptowall + ._crypt + .crypt + .cryptz + .crypz + .crysis + .cry + cry + .ctb2 + .ctbl2 + .ctbl + .czvxce + .d4nk + .dale + .damage + .darkness + .da_vinci_code + .dcrypt + .decrypt2017 + .ded + .dexter + .dharma + .disposed2017 + .dll + .domino + .dxxd + .dyatel@qq_com + .ecc + .edgel + .encedrsa + .enc_files.txt + .enciphered + .encmywork + .encoderpass + .encr + .encryptedaes + .encryptedrsa + .encrypted + .encrypted + .encryptedyourfiles + .encrypt + .enc + .enigma + .epic + .evillock + .exotic + .exx + .ezz + .fantom + .file0locked + .filegofprencrp + .fileiscryptedhard + .filock + .frtrss + .fucked + .fuck + .fucku + .fuckyourdata + .fun + .gefickt + .globe + .goforhelp + .good + .grt + .gruzin@qq_com + .gws + .h3ll + .ha3 + .happenencedfiles + .hb15 + .helpdecrypt@ukr.net + .helpmeencedfiles + .herbst + .hnumkhotep + .howcanihelpusir + .hush + .iaufkakfhsaraf + .ifuckedyou + .iloveworld + .infected + .info + -instruction.html + .isis + .iwanthelpuuu + .iwishiyou + .justbtcwillhelpyou + kb15 + .kernel_complete + .kernel_pid + .kernel_time + .keybtc@inbox_com + .keyh0les + .keyz + .kimcilware + .kkk + .korrektor + .kostya + .kraken + kraken + .kratos + .kyra + .last_chance.txt + .lcked + .lechiffre + .legion + .lesli + .letmetrydecfiles + .lock93 + .locked + locked + .locklock + .lock + .locky + .loli + .lol! + .loveransisgood + .lovewindows + .madebyadam + .magic + .maya + .mention9823 + .merry + .message.txt + .micro + .mole + .moments2900 + .mp3 + .mrcr1 + .myransext2017 + .nalog@qq_com + .nefilim + .nochance + nochance + .noproblemwedecfiles + .notfoundrans + .nuclear55 + .odcodc + .odin + .omg! + .onion + .only-we_can-help_you + .oops + .oor + .oplata@qq_com + .oshit + oshit + .osiris + .otherinformation + .p5tkjw + .padcrypt + .paybtcs + .paymrss + .payms + .paymst + .paym + .paymts + .payransom + .payrms + .pays + .pdcr + .pec + .pegs1 + .perl + .pizda@qq_com + .poar2w + .porno + .poshkoder + .potato + .powerfulldecryp + .powerfulldecrypt + .prosperous666 + .pubg + .purge + .pzdc + .r16m01d05 + .r4a + .r5a + .radamant + .rad + .raid10 + .rare1 + .razy + .rdm + .realfs0ciety@sigaint.org.fs0ciety + .recovery_file.txt + .recovery_key.txt + .rekt + .relock@qq_com + .remind + .rip + .rmcm1 + .rmd + .rnsmwr + .rokku + .rrk + .rsnslocked + .rsplited + .ruby + .ryk + ._ryp + .sage + .sanctioned + .sanction + .scl + .securecrypted + .serpent + .serp + .sexy + .shino + .shit + .silent + .skjdthghh + .spora + .sport + .stn + .stubbin + .supercrypt + .supported2017 + .suppose665 + .suppose666 + .surprise + .szf + .theworldisyours + .thor + .toxcrypt + .troyancoder@qq_com + .trun + .ttt + .tzu + .unavailable + .vault.hta + .vault.key + .vault + .vault.txt + .vbransom + .vekanhelpu + .venusf + .venusp + .vforvendetta + .vindows + .vscrypt + .vvv + .vxlock + .wallet + .wcry + .weapologize + .weareyourfriends + .weencedufiles + .wflx + .whereisyourfiles + .where_my_files.txt + .windows10 + .wncry + .wncryt + .wnry + .wowreadfordecryp + .wowwhereismyfiles + .xcri + .xort + .xrnt + .xrtn + .xtbl + .xxx + .xyz + .ytbl + .z81928819 + .zc3791 + .zcrypt + .zepto + .zorro + .zyklon + .zzz + .zzzzz + + + + + + + C:\Program Files (x86)\EMET 5.5\EMET_Service.exe + + C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe + + C:\Windows\system32\smss.exe + C:\Windows\system32\CompatTelRunner.exe + \\?\C:\Windows\system32\wbem\WMIADAP.EXE + C:\Windows\system32\mobsync.exe + C:\Windows\System32\WUDFHost.exe + C:\Windows\system32\DriverStore\Temp\ + C:\Windows\system32\wbem\Performance\ + C:\Windows\Installer\ + + C:\Windows\system32\cleanmgr.exe + + C:\$WINDOWS.~BT\Sources\ + C:\Windows\winsxs\amd64_microsoft-windows + + + + + + + + C:\Program Files\Mozilla Firefox\firefox.exe + backgroundupdate\prefs + .js + + + + + + + C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe + AppData\Local\Temp\__PSScriptPolicyTest + .ps1 + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + \MiniNT + CurrentVersion\Run + Policies\Explorer\Run + Group Policy\Scripts + Windows\System\Scripts + CurrentVersion\Windows\Load + CurrentVersion\Windows\Run + CurrentVersion\Winlogon\Shell + CurrentVersion\Winlogon\System + HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify + HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell + HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit + HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32 + HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\BootExecute + HKLM\Software\Microsoft\Windows NT\CurrentVersion\AeDebug + UserInitMprLogonScript + user shell folders\startup + + \ServiceDll + \ServiceManifest + \ImagePath + \Start + + Control\Terminal Server\WinStations\RDP-Tcp\PortNumber + Control\Terminal Server\fSingleSessionPerUser + fDenyTSConnections + LastLoggedOnUser + RDP-tcp\PortNumber + Services\PortProxy\v4tov4 + + \command\ + \ddeexec\ + {86C86720-42A0-1069-A2E8-08002B30309D} + exefile + + \InprocServer32\(Default) + + \Hidden + \ShowSuperHidden + \HideFileExt + + Classes\*\ + Classes\AllFilesystemObjects\ + Classes\Directory\ + Classes\Drive\ + Classes\Folder\ + Classes\PROTOCOLS\ + ContextMenuHandlers\ + CurrentVersion\Shell + HKLM\Software\Microsoft\Windows\CurrentVersion\explorer\ShellExecuteHooks + HKLM\Software\Microsoft\Windows\CurrentVersion\explorer\ShellServiceObjectDelayLoad + HKLM\Software\Microsoft\Windows\CurrentVersion\explorer\ShellIconOverlayIdentifiers + + HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\ + + HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp\InitialProgram + + HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\ + + HKLM\SYSTEM\CurrentControlSet\Services\WinSock + \ProxyServer + + HKLM\Software\Microsoft\Windows\CurrentVersion\Authentication\Credential Provider + HKLM\SYSTEM\CurrentControlSet\Control\Lsa\ + HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders + HKLM\Software\Microsoft\Netsh + Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable + + HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order\ + HKLM\Software\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles + \EnableFirewall + \DoNotAllowExceptions + HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List + HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List + + HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\Appinit_Dlls\ + HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows\Appinit_Dlls\ + HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls\ + + Microsoft\Office\Outlook\Addins\ + Office Test\ + \Software\Microsoft\Office\;\Outlook\WebView\;URL + Security\Trusted Documents\TrustRecords + \EnableBHO + + Internet Explorer\Toolbar\ + Internet Explorer\Extensions\ + Browser Helper Objects\ + \DisableSecuritySettingsCheck + \3\1206 + \3\2500 + \3\1809 + + HKLM\Software\Classes\CLSID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\ + HKLM\Software\Classes\WOW6432Node\CLSID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\ + HKLM\Software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\ + HKLM\Software\Classes\WOW6432Node\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\ + + \UrlUpdateInfo + \InstallSource + \EulaAccepted + + \DisableAntiSpyware + \DisableAntiVirus + \SpynetReporting + DisableRealtimeMonitoring + \SubmitSamplesConsent + HKLM\SOFTWARE\Policies\Microsoft\Windows Defender + HKLM\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify + + + HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA + HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\LocalAccountTokenFilterPolicy + HKLM\SOFTWARE\Microsoft\Security Center\UacDisableNotify + HKLM\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify + + + HKLM\Software\Microsoft\Security Center\ + SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\HideSCAHealth + + HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom + HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\InstalledSDB + VirtualStore + + HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ + HKLM\Software\Microsoft\Windows\CurrentVersion\WINEVT\ + HKLM\SYSTEM\CurrentControlSet\Control\Safeboot\ + HKLM\SYSTEM\CurrentControlSet\Control\Winlogon\ + \FriendlyName + HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\InProgress\(Default) + + + + Microsoft\Cryptography\OID\ + WOW6432Node\Microsoft\Cryptography\OID\ + Microsoft\Cryptography\Providers\Trust\ + WOW6432Node\Microsoft\Cryptography\Providers\Trust\ + + HKLM\Software\Microsoft\Tracing\RASAPI32 + HKLM\Software\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\ConsentStore\ + \Keyboard Layout\Preload + \Keyboard Layout\Substitutes + + \LowerCaseLongPath + \Publisher + \BinProductVersion + \DriverVersion + \DriverVerVersion + \LinkDate + Compatibility Assistant\Store\ + HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Ports + \Keyboard Layout\Preload + \Keyboard Layout\Substitutes + + regedit.exe + \ + HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\ + HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\ + + + Microsoft\Cryptography\OID\ + WOW6432Node\Microsoft\Cryptography\OID\ + Microsoft\Cryptography\Providers\Trust\ + WOW6432Node\Microsoft\Cryptography\Providers\Trust\ + Control\Print\Environments\Windows x64\Drivers + + + + + + + + \{CAFEEFAC- + CreateKey + HKLM\COMPONENTS + + + HKLM\Software\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache + + + Toolbar\WebBrowser + Browser\ITBar7Height + Browser\ITBar7Layout + Internet Explorer\Toolbar\Locked + Toolbar\WebBrowser\{47833539-D0C5-4125-9FA8-0819E2EAAC93} + }\PreviousPolicyAreas + \Control\WMI\Autologger\ + HKLM\SYSTEM\CurrentControlSet\Services\UsoSvc\Start + \Lsa\OfflineJoin\CurrentValue + HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\ + _Classes\AppX + HKLM\Software\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\ + + + HKLM\SYSTEM\CurrentControlSet\Control\Lsa\LsaPid + HKLM\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache + HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Domains + + + \Services\BITS\Start + \services\clr_optimization_v2.0.50727_32\Start + \services\clr_optimization_v2.0.50727_64\Start + \services\clr_optimization_v4.0.30319_32\Start + \services\clr_optimization_v4.0.30319_64\Start + \services\deviceAssociationService\Start + \services\fhsvc\Start + \services\nal\Start + \services\trustedInstaller\Start + \services\tunnel\Start + \services\usoSvc\Start + + + \UserChoice\ProgId + \UserChoice\Hash + \OpenWithList\MRUList + Shell Extentions\Cached + + + HKLM\System\CurrentControlSet\Control\Lsa\Audit\SpecialGroups + SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Startup\0\PSScriptOrder + SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Startup\0\SOM-ID + SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Startup\0\GPO-ID + SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Startup\0\0\IsPowershell + SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Startup\0\0\ExecTime + SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Shutdown\0\PSScriptOrder + SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Shutdown\0\SOM-ID + SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Shutdown\0\GPO-ID + SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Shutdown\0\0\IsPowershell + SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Shutdown\0\0\ExecTime + \safer\codeidentifiers\0\HASHES\{ + + + VirtualStore\MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\ + HKLM\SOFTWARE\Microsoft\Office\ClickToRun\ + + + C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe + HKCR\VLC. + HKCR\iTunes. + + + HKLM\Software\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{945a8954-c147-4acd-923f-40c45405a658} + + + + + + + + + + + Downloads + Temp\7z + Startup + .bat + .cmd + .doc + .hta + .jse + .lnk + .ppt + .ps1 + .ps2 + .reg + .js + .sct + .vb + .vbe + .vbs + .wsc + .wsf + .docm + .docx + .xls + .xlsm + .xlsx + .pptm + .pptx + .rtf + .pdf + .zip + .7z + + + + + + + + + + + + + + + + + + + + + + + + + + + paexec;remcom;csexec + + + \lsadump;\cachedump;\wceservicepipe + + + \isapi_http;\isapi_dg;\isapi_dg2;\sdlrpc;\ahexec;\winsession;\lsassw;\46a676ab7f179e511e30dd2dc41bd388;\9f81f59bc58452127884ce513865ed20;\e710f28d59aa529d6792ca6ff0ca1b34;\rpchlp_3;\NamePipe_MoreWindows;\pcheap_reuse;\gruntsvc;\583da945-62af-10e8-4902-a8f205c72b2e;\bizkaz;\svcctl;\Posh;\jaccdpqnvbrrxlaf;\csexecsvc + \atctl;\userpipe;\iehelper;\sdlrpc;\comnap + + + MSSE-;-server + \postex_ + \postex_ssh_ + \status_ + \msagent_ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + .arpa. + .arpa + .msftncsi.com + ..localmachine + localhost + + + -pushp.svc.ms + .b-msedge.net + .bing.com + .hotmail.com + .live.com + .live.net + .s-microsoft.com + .microsoft.com + .microsoftonline.com + .microsoftstore.com + .ms-acdc.office.com + .msedge.net + .msn.com + .msocdn.com + .skype.com + .skype.net + .windows.com + .windows.net.nsatc.net + .windowsupdate.com + .xboxlive.com + login.windows.net + C:\ProgramData\Microsoft\Windows Defender\Platform\ + + + .activedirectory.windowsazure.com + .aria.microsoft.com + .msauth.net + .msftauth.net + .office.net + .opinsights.azure.com + .res.office365.com + acdc-direct.office.com + atm-fp-direct.office.com + loki.delve.office.com + management.azure.com + messaging.office.com + outlook.office365.com + portal.azure.com + protection.outlook.com + substrate.office.com + .measure.office.com + + + .adobe.com + .adobe.io + .mozaws.net + .mozilla.com + .mozilla.net + .mozilla.org + .spotify.com + .spotify.map.fastly.net + .wbx2.com + .webex.com + clients1.google.com + clients2.google.com + clients3.google.com + clients4.google.com + clients5.google.com + clients6.google.com + safebrowsing.googleapis.com + + + .akadns.net + .netflix.com + aspnetcdn.com + .aspnetcdn.com + ajax.googleapis.com + cdnjs.cloudflare.com + fonts.googleapis.com + .typekit.net + cdnjs.cloudflare.com + .stackassets.com + .steamcontent.com + play.google.com + content-autofill.googleapis.com + + + .disqus.com + .fontawesome.com + disqus.com + + + .1rx.io + .2mdn.net + .3lift.com + .adadvisor.net + .adap.tv + .addthis.com + .adform.net + .adnxs.com + .adroll.com + .adrta.com + .adsafeprotected.com + .adsrvr.org + .adsymptotic.com + .advertising.com + .agkn.com + .amazon-adsystem.com + .amazon-adsystem.com + .analytics.yahoo.com + .aol.com + .betrad.com + .bidswitch.net + .casalemedia.com + .chartbeat.net + .cnn.com + .convertro.com + .criteo.com + .criteo.net + .crwdcntrl.net + .demdex.net + .domdex.com + .dotomi.com + .doubleclick.net + .doubleverify.com + .emxdgt.com + .everesttech.net + .exelator.com + .google-analytics.com + .googleadservices.com + .googlesyndication.com + .googletagmanager.com + .googlevideo.com + .gstatic.com + .gvt1.com + .gvt2.com + .ib-ibi.com + .jivox.com + .krxd.net + .lijit.com + .mathtag.com + .moatads.com + .moatpixel.com + .mookie1.com + .myvisualiq.net + .netmng.com + .nexac.com + .openx.net + .optimizely.com + .outbrain.com + .pardot.com + .phx.gbl + .pinterest.com + .pubmatic.com + .quantcount.com + .quantserve.com + .revsci.net + .rfihub.net + .rlcdn.com + .rubiconproject.com + .scdn.co + .scorecardresearch.com + .serving-sys.com + .sharethrough.com + .simpli.fi + .sitescout.com + .smartadserver.com + .snapads.com + .spotxchange.com + .taboola.com + .taboola.map.fastly.net + .tapad.com + .tidaltv.com + .trafficmanager.net + .tremorhub.com + .tribalfusion.com + .turn.com + .twimg.com + .tynt.com + .w55c.net + .ytimg.com + .zorosrv.com + 1rx.io + adservice.google.com + ampcid.google.com + clientservices.googleapis.com + googleadapis.l.google.com + imasdk.googleapis.com + l.google.com + ml314.com + mtalk.google.com + update.googleapis.com + www.googletagservices.com + + + .pscp.tv + + + .amazontrust.com + .digicert.com + .globalsign.com + .globalsign.net + .intel.com + .symcb.com + .symcd.com + .thawte.com + .usertrust.com + .verisign.com + ocsp.identrust.com + pki.goog + pki.goog + msocsp.com + ocsp.comodoca.com + ocsp.entrust.net + ocsp.godaddy.com + ocsp.int-x3.letsencrypt.org + ocsp.msocsp.com + pki.goog + ocsp.godaddy.com + amazontrust.com + amazontrust.com + ocsp.sectigo.com + pki-goog.l.google.com + .usertrust.com + ocsp.comodoca.com + ocsp.verisign.com + ocsp.entrust.net + ocsp.identrust.com + .ocsp.identrust.com + status.rapidssl.com + status.thawte.com + ocsp.int-x3.letsencrypt.org + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + From d147cf74a025ee6ecd1adfeae3db18d11b34c754 Mon Sep 17 00:00:00 2001 From: Bytewolf Date: Fri, 23 Dec 2022 11:37:30 +0100 Subject: [PATCH 2/5] Update README.md --- README.md | 17 ++++++++++++----- 1 file changed, 12 insertions(+), 5 deletions(-) diff --git a/README.md b/README.md index 6e4ec41..7369085 100644 --- a/README.md +++ b/README.md @@ -1,8 +1,11 @@ # sysmon-config | A Sysmon configuration file for everybody to fork # -This is a Microsoft Sysinternals Sysmon configuration file template with default high-quality event tracing. +This is a Microsoft Sysinternals Sysmon configuration file template. +It contains multiple pull-requests from the SwiftOnSecurity repository as well as some modifications from the environment where it's deployed. -The file should function as a great starting point for system change monitoring in a self-contained and accessible package. This configuration and results should give you a good idea of what's possible for Sysmon. Note that this does not track things like authentication and other Windows events that are also vital for incident investigation. +The file should function as a great starting point for system change monitoring in a self-contained and accessible package. +This configuration and results should give you a good idea of what's possible for Sysmon. +Note that this does not track things like authentication and other Windows events that are also vital for incident investigation.       **[sysmonconfig-export.xml](https://github.com/SwiftOnSecurity/sysmon-config/blob/master/sysmonconfig-export.xml)** @@ -38,12 +41,16 @@ sysmon.exe -u ## Required actions ## ### Prerequisites ### -Highly recommend using [Notepad++](https://notepad-plus-plus.org/) to edit this configuration. It understands UNIX newline format and does XML syntax highlighting, which makes this very understandable. I do not recommend using the built-in Notepad.exe. +Highly recommend using [Notepad++](https://notepad-plus-plus.org/) or [Visual Studio Code](https://code.visualstudio.com/) to edit this configuration. +They understand UNIX newline format and do XML syntax highlighting, which makes this very understandable. ### Customization ### -You will need to install and observe the results of the configuration in your own environment before deploying it widely. For example, you will need to exclude actions of your antivirus, which will otherwise likely fill up your logs with useless information. +You will need to install and observe the results of the configuration in your own environment before deploying it widely. +For example, you will need to exclude actions of your antivirus, which will otherwise likely fill up your logs with useless information. The configuration is highly commented and designed to be self-explanatory to assist you in this customization to your environment. ### Design notes ### -This configuration expects software to be installed system-wide and NOT in the C:\Users folder. Various pieces of software install themselves in User directories, which are subject to extra monitoring. Where possible, you should install the system-wide version of these pieces of software, like Chrome. See the configuration file for more instructions. +This configuration expects software to be installed system-wide and NOT in the C:\Users folder. +Various pieces of software install themselves in User directories, which are subject to extra monitoring. +Where possible, you should install the system-wide version of these pieces of software, like Chrome. See the configuration file for more instructions. From 6d71ecc6a0bedb4ff70351caaabf15f49b31fdef Mon Sep 17 00:00:00 2001 From: Bytewolf Date: Fri, 23 Dec 2022 11:39:09 +0100 Subject: [PATCH 3/5] Update README.md --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index 7369085..88dfa4f 100644 --- a/README.md +++ b/README.md @@ -1,4 +1,4 @@ -# sysmon-config | A Sysmon configuration file for everybody to fork # +# sysmon-config | A Sysmon configuration file fork # This is a Microsoft Sysinternals Sysmon configuration file template. It contains multiple pull-requests from the SwiftOnSecurity repository as well as some modifications from the environment where it's deployed. From 473b35d4cb40a1ac920d5db4eb6a1f3b2bdde38b Mon Sep 17 00:00:00 2001 From: Bytewolf Date: Fri, 23 Dec 2022 13:47:12 +0100 Subject: [PATCH 4/5] Add files via upload Script for installing / updating / removing Sysmon64 with the provided config-file --- install_update.cmd | 46 ++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 46 insertions(+) create mode 100644 install_update.cmd diff --git a/install_update.cmd b/install_update.cmd new file mode 100644 index 0000000..2bb52b0 --- /dev/null +++ b/install_update.cmd @@ -0,0 +1,46 @@ +@echo off +SETLOCAL ENABLEEXTENSIONS +SET MYDIR= %~dp0 +SET CMD_SWITCH=%1 +cls + +REM Reset any Errorlevel to zero +ver >NUL + +REM Check for Administrative permissions +net session >NUL 2>&1 +IF %ERRORLEVEL% NEQ 0 ( + echo Administrative permissions required. + goto EOF +) + +IF DEFINED CMD_SWITCH ( + IF "%CMD_SWITCH%"=="u" ( + echo Removing SYSMON... + %MYDIR%sysmon64 -u force >NUL 2>&1 + goto EOF + ) + echo To uninstall SYSMON use this script with parameter u. + goto EOF +) + +REM Reset any Errorlevel to zero +ver >NUL + +REM Check if Sysmon64 is already installed +sc query sysmon64 | find /I "TYPE" >NUL + +IF %ERRORLEVEL% NEQ 0 ( + REM SYSMON is not installed -> New system + echo Installing Sysmon + %MYDIR%sysmon64 -i %MYDIR%sysmonconfig-export.xml -accepteula >NUL 2>&1 +) ELSE ( + REM SYSMON is installed -> Config will be updated + echo Updating Config + %MYDIR%sysmon64 -c %MYDIR%sysmonconfig-export.xml >NUL 2>&1 +) + +ENDLOCAL + +:EOF + From 248290ec66684db56a95c9f78a19a45e6751eadd Mon Sep 17 00:00:00 2001 From: Bytewolf Date: Fri, 23 Dec 2022 13:50:27 +0100 Subject: [PATCH 5/5] Update README.md Added Script to the description --- README.md | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/README.md b/README.md index 88dfa4f..36a0283 100644 --- a/README.md +++ b/README.md @@ -20,6 +20,20 @@ Note: Exact syntax and filtering choices in the configuration are highly deliber       **[See other forks of this configuration](https://github.com/SwiftOnSecurity/sysmon-config/network)** ## Use ## + +### Install / Update / Uninstall - via Script ### +Run with administrator rights + +#### Install / Update #### +~~~~ +install_update.cmd +~~~~ + +#### Uninstall #### +~~~~ +install_update.cmd u +~~~~ + ### Install ### Run with administrator rights ~~~~