Skip to content

Commit 3159737

Browse files
Merge pull request #171 from AndrewRathbun/master
Update Sysmon events with User fields
2 parents 1ceebdf + 00d11cf commit 3159737

18 files changed

+193
-2
lines changed

evtx/Maps/Microsoft-Windows-Sysmon-Operational_Microsoft-Windows-Sysmon_1.map

+7-1
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,13 @@ EventId: 1
44
Channel: Microsoft-Windows-Sysmon/Operational
55
Provider: Microsoft-Windows-Sysmon
66
Maps:
7-
7+
-
8+
Property: UserName
9+
PropertyValue: "ParentUser: %ParentUser%"
10+
Values:
11+
-
12+
Name: ParentUser
13+
Value: "/Event/EventData/Data[@Name=\"ParentUser\"]"
814
-
915
Property: ExecutableInfo
1016
PropertyValue: "%CommandLine%"

evtx/Maps/Microsoft-Windows-Sysmon-Operational_Microsoft-Windows-Sysmon_10.map

+10
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,16 @@ EventId: 10
44
Channel: Microsoft-Windows-Sysmon/Operational
55
Provider: Microsoft-Windows-Sysmon
66
Maps:
7+
-
8+
Property: UserName
9+
PropertyValue: "SourceUser: %SourceUser% | TargetUser: %TargetUser%"
10+
Values:
11+
-
12+
Name: SourceUser
13+
Value: "/Event/EventData/Data[@Name=\"SourceUser\"]"
14+
-
15+
Name: TargetUser
16+
Value: "/Event/EventData/Data[@Name=\"TargetUser\"]"
717
-
818
Property: ExecutableInfo
919
PropertyValue: "CallTrace: %CallTrace%"

evtx/Maps/Microsoft-Windows-Sysmon-Operational_Microsoft-Windows-Sysmon_11.map

+7
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,13 @@ EventId: 11
44
Channel: Microsoft-Windows-Sysmon/Operational
55
Provider: Microsoft-Windows-Sysmon
66
Maps:
7+
-
8+
Property: UserName
9+
PropertyValue: "%User%"
10+
Values:
11+
-
12+
Name: User
13+
Value: "/Event/EventData/Data[@Name=\"User\"]"
714
-
815
Property: PayloadData1
916
PropertyValue: "ProcessID: %ProcessID%, ProcessGUID: %ProcessGUID%"

evtx/Maps/Microsoft-Windows-Sysmon-Operational_Microsoft-Windows-Sysmon_12.map

+7
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,13 @@ EventId: 12
44
Channel: Microsoft-Windows-Sysmon/Operational
55
Provider: Microsoft-Windows-Sysmon
66
Maps:
7+
-
8+
Property: UserName
9+
PropertyValue: "%User%"
10+
Values:
11+
-
12+
Name: User
13+
Value: "/Event/EventData/Data[@Name=\"User\"]"
714
-
815
Property: PayloadData1
916
PropertyValue: "ProcessID: %ProcessID%, ProcessGUID: %ProcessGUID%"

evtx/Maps/Microsoft-Windows-Sysmon-Operational_Microsoft-Windows-Sysmon_13.map

+7
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,13 @@ EventId: 13
44
Channel: Microsoft-Windows-Sysmon/Operational
55
Provider: Microsoft-Windows-Sysmon
66
Maps:
7+
-
8+
Property: UserName
9+
PropertyValue: "%User%"
10+
Values:
11+
-
12+
Name: User
13+
Value: "/Event/EventData/Data[@Name=\"User\"]"
714
-
815
Property: PayloadData1
916
PropertyValue: "ProcessID: %ProcessID%, ProcessGUID: %ProcessGUID%"

evtx/Maps/Microsoft-Windows-Sysmon-Operational_Microsoft-Windows-Sysmon_14.map

+7
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,13 @@ EventId: 14
44
Channel: Microsoft-Windows-Sysmon/Operational
55
Provider: Microsoft-Windows-Sysmon
66
Maps:
7+
-
8+
Property: UserName
9+
PropertyValue: "%User%"
10+
Values:
11+
-
12+
Name: User
13+
Value: "/Event/EventData/Data[@Name=\"User\"]"
714
-
815
Property: PayloadData1
916
PropertyValue: "ProcessID: %ProcessID%, ProcessGUID: %ProcessGUID%"

evtx/Maps/Microsoft-Windows-Sysmon-Operational_Microsoft-Windows-Sysmon_15.map

+7
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,13 @@ EventId: 15
44
Channel: Microsoft-Windows-Sysmon/Operational
55
Provider: Microsoft-Windows-Sysmon
66
Maps:
7+
-
8+
Property: UserName
9+
PropertyValue: "%User%"
10+
Values:
11+
-
12+
Name: User
13+
Value: "/Event/EventData/Data[@Name=\"User\"]"
714
-
815
Property: PayloadData1
916
PropertyValue: "ProcessID: %ProcessID%, ProcessGUID: %ProcessGUID%"

evtx/Maps/Microsoft-Windows-Sysmon-Operational_Microsoft-Windows-Sysmon_17.map

+7
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,13 @@ EventId: 17
44
Channel: Microsoft-Windows-Sysmon/Operational
55
Provider: Microsoft-Windows-Sysmon
66
Maps:
7+
-
8+
Property: UserName
9+
PropertyValue: "%User%"
10+
Values:
11+
-
12+
Name: User
13+
Value: "/Event/EventData/Data[@Name=\"User\"]"
714
-
815
Property: PayloadData1
916
PropertyValue: "ProcessID: %ProcessID%, ProcessGUID: %ProcessGUID%"

evtx/Maps/Microsoft-Windows-Sysmon-Operational_Microsoft-Windows-Sysmon_18.map

+7
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,13 @@ EventId: 18
44
Channel: Microsoft-Windows-Sysmon/Operational
55
Provider: Microsoft-Windows-Sysmon
66
Maps:
7+
-
8+
Property: UserName
9+
PropertyValue: "%User%"
10+
Values:
11+
-
12+
Name: User
13+
Value: "/Event/EventData/Data[@Name=\"User\"]"
714
-
815
Property: PayloadData1
916
PropertyValue: "ProcessID: %ProcessID%, ProcessGUID: %ProcessGUID%"

evtx/Maps/Microsoft-Windows-Sysmon-Operational_Microsoft-Windows-Sysmon_2.map

+7-1
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,13 @@ EventId: 2
44
Channel: Microsoft-Windows-Sysmon/Operational
55
Provider: Microsoft-Windows-Sysmon
66
Maps:
7-
7+
-
8+
Property: UserName
9+
PropertyValue: "%User%"
10+
Values:
11+
-
12+
Name: User
13+
Value: "/Event/EventData/Data[@Name=\"User\"]"
814
-
915
Property: PayloadData1
1016
PropertyValue: "ProcessID: %ProcessID%, ProcessGUID: %ProcessGUID%"

evtx/Maps/Microsoft-Windows-Sysmon-Operational_Microsoft-Windows-Sysmon_22.map

+7
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,13 @@ EventId: 22
44
Channel: Microsoft-Windows-Sysmon/Operational
55
Provider: Microsoft-Windows-Sysmon
66
Maps:
7+
-
8+
Property: UserName
9+
PropertyValue: "%User%"
10+
Values:
11+
-
12+
Name: User
13+
Value: "/Event/EventData/Data[@Name=\"User\"]"
714
-
815
Property: PayloadData1
916
PropertyValue: "ProcessID: %ProcessID%, ProcessGUID: %ProcessGUID%"

evtx/Maps/Microsoft-Windows-Sysmon-Operational_Microsoft-Windows-Sysmon_24.map

+7
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,13 @@ EventId: 24
44
Channel: Microsoft-Windows-Sysmon/Operational
55
Provider: Microsoft-Windows-Sysmon
66
Maps:
7+
-
8+
Property: UserName
9+
PropertyValue: "%User%"
10+
Values:
11+
-
12+
Name: User
13+
Value: "/Event/EventData/Data[@Name=\"User\"]"
714
-
815
Property: ExecutableInfo
916
PropertyValue: "%Image%"

evtx/Maps/Microsoft-Windows-Sysmon-Operational_Microsoft-Windows-Sysmon_25.map

+7
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,13 @@ EventId: 25
44
Channel: Microsoft-Windows-Sysmon/Operational
55
Provider: Microsoft-Windows-Sysmon
66
Maps:
7+
-
8+
Property: UserName
9+
PropertyValue: "%User%"
10+
Values:
11+
-
12+
Name: User
13+
Value: "/Event/EventData/Data[@Name=\"User\"]"
714
-
815
Property: ExecutableInfo
916
PropertyValue: "%Image%"

evtx/Maps/Microsoft-Windows-Sysmon-Operational_Microsoft-Windows-Sysmon_5.map

+7
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,13 @@ EventId: 5
44
Channel: Microsoft-Windows-Sysmon/Operational
55
Provider: Microsoft-Windows-Sysmon
66
Maps:
7+
-
8+
Property: UserName
9+
PropertyValue: "%User%"
10+
Values:
11+
-
12+
Name: User
13+
Value: "/Event/EventData/Data[@Name=\"User\"]"
714
-
815
Property: ExecutableInfo
916
PropertyValue: "%FilePath%"

evtx/Maps/Microsoft-Windows-Sysmon-Operational_Microsoft-Windows-Sysmon_7.map

+7
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,13 @@ EventId: 7
44
Channel: Microsoft-Windows-Sysmon/Operational
55
Provider: Microsoft-Windows-Sysmon
66
Maps:
7+
-
8+
Property: UserName
9+
PropertyValue: "%User%"
10+
Values:
11+
-
12+
Name: User
13+
Value: "/Event/EventData/Data[@Name=\"User\"]"
714
-
815
Property: ExecutableInfo
916
PropertyValue: "%ImageLoaded%"

evtx/Maps/Microsoft-Windows-Sysmon-Operational_Microsoft-Windows-Sysmon_8.map

+10
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,16 @@ EventId: 8
44
Channel: Microsoft-Windows-Sysmon/Operational
55
Provider: Microsoft-Windows-Sysmon
66
Maps:
7+
-
8+
Property: UserName
9+
PropertyValue: "SourceUser: %SourceUser% | TargetUser: %TargetUser%"
10+
Values:
11+
-
12+
Name: SourceUser
13+
Value: "/Event/EventData/Data[@Name=\"SourceUser\"]"
14+
-
15+
Name: TargetUser
16+
Value: "/Event/EventData/Data[@Name=\"TargetUser\"]"
717
-
818
Property: PayloadData1
919
PropertyValue: "StartAddress: %StartAddress%"

evtx/Maps/Microsoft-Windows-Sysmon-Operational_Microsoft-Windows-Sysmon_9.map

+7
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,13 @@ EventId: 9
44
Channel: Microsoft-Windows-Sysmon/Operational
55
Provider: Microsoft-Windows-Sysmon
66
Maps:
7+
-
8+
Property: UserName
9+
PropertyValue: "%User%"
10+
Values:
11+
-
12+
Name: User
13+
Value: "/Event/EventData/Data[@Name=\"User\"]"
714
-
815
Property: PayloadData1
916
PropertyValue: "ProcessID: %ProcessID%, ProcessGUID: %ProcessGUID%"
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,68 @@
1+
Author: Andrew Rathbun
2+
Description: Pipeline Execution Details
3+
EventId: 800
4+
Channel: Windows PowerShell
5+
Provider: PowerShell
6+
Maps:
7+
-
8+
Property: PayloadData1
9+
PropertyValue: "%HostApplication%"
10+
Values:
11+
-
12+
Name: HostApplication
13+
Value: "/Event/EventData/Data"
14+
Refine: "HostApplication=(.+)"
15+
-
16+
Property: PayloadData2
17+
PropertyValue: "%HostName%"
18+
Values:
19+
-
20+
Name: HostName
21+
Value: "/Event/EventData/Data"
22+
Refine: "HostName=(.+)"
23+
-
24+
Property: PayloadData3
25+
PropertyValue: "%HostVersion%"
26+
Values:
27+
-
28+
Name: HostVersion
29+
Value: "/Event/EventData/Data"
30+
Refine: "HostVersion=(.+)"
31+
32+
# Documentation:
33+
# https://www.myeventlog.com/search/show/975
34+
#
35+
# Example Event Data:
36+
# <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
37+
# <System>
38+
# <Provider Name="PowerShell" />
39+
# <EventID Qualifiers="0">600</EventID>
40+
# <Level>4</Level>
41+
# <Task>6</Task>
42+
# <Keywords>0x80000000000000</Keywords>
43+
# <TimeCreated SystemTime="2001-01-01T01:01:01.012345678Z" />
44+
# <EventRecordID>18</EventRecordID>
45+
# <Channel>Windows PowerShell</Channel>
46+
# <Computer>name.domain.tld</Computer>
47+
# <Security />
48+
# </System>
49+
# <EventData>
50+
# <Data>Registry, Started, ProviderName=Registry
51+
# NewProviderState=Started
52+
#
53+
# SequenceNumber=1
54+
#
55+
# HostName=ConsoleHost
56+
# HostVersion=5.1.18362.145
57+
# HostId=b3dfcb89-d2f8-4b8b-a784-a6a9bcf61bd8
58+
# HostApplication=powershell -command Set-ItemProperty -Path HKCU:\Software\Microsoft\Office\16.0\Outlook\AutoDiscover -Name 'ExcludeExplicitO365Endpoint' -Value 1 -Type DWORD -Force
59+
# EngineVersion=
60+
# RunspaceId=
61+
# PipelineId=
62+
# CommandName=
63+
# CommandType=
64+
# ScriptName=
65+
# CommandPath=
66+
# CommandLine=</Data>
67+
# </EventData>
68+
# </Event>

0 commit comments

Comments
 (0)