Skip to content

Commit 7b82a72

Browse files
Merge pull request #200 from forensenellanebbia/master
Deletion of old VHDMP maps and upload of new legacy/current maps
2 parents 5aa1d99 + a5696a8 commit 7b82a72

4 files changed

+131
-13
lines changed
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
1-
Author: Phill Moore, Hyun Yi @hyuunnn
1+
Author: Gabriele Zambelli @gazambelli
22
Description: A VHD has been created
33
EventId: 1
4-
Channel: "Microsoft-Windows-VHDMP/Operational"
4+
Channel: Microsoft-Windows-VHDMP-Operational
55
Provider: Microsoft-Windows-VHDMP
66
Maps:
77
-
@@ -14,31 +14,39 @@ Maps:
1414
-
1515
Name: VhdNumber
1616
Value: "/Event/EventData/Data[@Name=\"VhdDiskNumber\"]"
17+
-
18+
Property: PayloadData2
19+
PropertyValue: "VhdName: %VhdName%"
20+
Values:
21+
-
22+
Name: VhdName
23+
Value: "/Event/EventData/Data[@Name=\"VhdFileName\"]"
1724

1825
# Documentation:
1926
# https://nasbench.medium.com/finding-forensic-goodness-in-obscure-windows-event-logs-60e978ea45a3
27+
# This map applies to Windows 10 / Windows 11 / Windows Server 2019
2028
#
2129
# Example Event Data:
22-
# <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
30+
# <Event>
2331
# <System>
24-
# <Provider Name="Microsoft-Windows-VHDMP" Guid="{GUID}" />
32+
# <Provider Name="Microsoft-Windows-VHDMP" Guid="e2816346-87f4-4f85-95c3-0c79409aa89d" />
2533
# <EventID>1</EventID>
2634
# <Version>0</Version>
2735
# <Level>4</Level>
2836
# <Task>1205</Task>
2937
# <Opcode>2</Opcode>
3038
# <Keywords>0x8000000000000001</Keywords>
31-
# <TimeCreated SystemTime="2020-12-29T02:31:57.0588526Z" />
32-
# <EventRecordID>3316</EventRecordID>
39+
# <TimeCreated SystemTime="2022-07-13 05:38:10.0560840" />
40+
# <EventRecordID>15</EventRecordID>
3341
# <Correlation />
34-
# <Execution ProcessID="4" ThreadID="14296" />
42+
# <Execution ProcessID="4" ThreadID="312" />
3543
# <Channel>Microsoft-Windows-VHDMP-Operational</Channel>
36-
# <Computer>ComputerName</Computer>
37-
# <Security UserID="{UserID}" />
44+
# <Computer>VMWIN11</Computer>
45+
# <Security UserID="S-1-5-18" />
3846
# </System>
3947
# <EventData>
40-
# <Data Name="VhdFileName">C:\Users\hyuunnn\Desktop\test.vhd</Data>
41-
# <Data Name="VhdDiskNumber">3</Data>
42-
# <Data Name="VirtualDisk">0xffffdf0130cd8280</Data>
48+
# <Data Name="VhdFileName">C:\Users\standard\Desktop\TEST.vhdx</Data>
49+
# <Data Name="VhdDiskNumber">1</Data>
50+
# <Data Name="VirtualDisk">0xFFFFB188D20EF040</Data>
4351
# </EventData>
4452
# </Event>
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,51 @@
1+
Author: Phill Moore, Hyun Yi @hyuunnn, Gabriele Zambelli
2+
Description: A VHD has been created
3+
EventId: 1
4+
Channel: "Microsoft-Windows-VHDMP/Operational"
5+
Provider: Microsoft-Windows-VHDMP
6+
Maps:
7+
-
8+
Property: PayloadData1
9+
PropertyValue: "The VHD %VhdName% has been created (surfaced) as disk number %VhdNumber%"
10+
Values:
11+
-
12+
Name: VhdName
13+
Value: "/Event/EventData/Data[@Name=\"VhdFileName\"]"
14+
-
15+
Name: VhdNumber
16+
Value: "/Event/EventData/Data[@Name=\"VhdDiskNumber\"]"
17+
-
18+
Property: PayloadData2
19+
PropertyValue: "VhdName: %VhdName%"
20+
Values:
21+
-
22+
Name: VhdName
23+
Value: "/Event/EventData/Data[@Name=\"VhdFileName\"]"
24+
25+
# Documentation:
26+
# https://nasbench.medium.com/finding-forensic-goodness-in-obscure-windows-event-logs-60e978ea45a3
27+
# This legacy map applies to Windows 8 / Windows Server 2012. The channel name "Microsoft-Windows-VHDMP/Operational" was renamed to "Microsoft-Windows-VHDMP-Operational" in more recent operating systems.
28+
#
29+
# Example Event Data:
30+
# <Event>
31+
# <System>
32+
# <Provider Name="Microsoft-Windows-VHDMP" Guid="e2816346-87f4-4f85-95c3-0c79409aa89d" />
33+
# <EventID>1</EventID>
34+
# <Version>0</Version>
35+
# <Level>4</Level>
36+
# <Task>0</Task>
37+
# <Opcode>0</Opcode>
38+
# <Keywords>0x8000000000000000</Keywords>
39+
# <TimeCreated SystemTime="2022-07-11 14:02:51.0410456" />
40+
# <EventRecordID>1</EventRecordID>
41+
# <Correlation />
42+
# <Execution ProcessID="4" ThreadID="3868" />
43+
# <Channel>Microsoft-Windows-VHDMP/Operational</Channel>
44+
# <Computer>WIN-QSQO10V59K4</Computer>
45+
# <Security UserID="S-1-5-18" />
46+
# </System>
47+
# <EventData>
48+
# <Data Name="VhdFileName">C:\Users\Administrator\Desktop\TEST.vhdx</Data>
49+
# <Data Name="VhdDiskNumber">1</Data>
50+
# </EventData>
51+
# </Event>
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,51 @@
1+
Author: Gabriele Zambelli @gazambelli
2+
Description: A VHD has been removed
3+
EventId: 2
4+
Channel: Microsoft-Windows-VHDMP-Operational
5+
Provider: Microsoft-Windows-VHDMP
6+
Maps:
7+
-
8+
Property: PayloadData1
9+
PropertyValue: "The VHD %VhdName% has been removed (unsurfaced) as disk number %VhdNumber%"
10+
Values:
11+
-
12+
Name: VhdName
13+
Value: "/Event/EventData/Data[@Name=\"VhdFileName\"]"
14+
-
15+
Name: VhdNumber
16+
Value: "/Event/EventData/Data[@Name=\"VhdDiskNumber\"]"
17+
-
18+
Property: PayloadData2
19+
PropertyValue: "VhdName: %VhdName%"
20+
Values:
21+
-
22+
Name: VhdName
23+
Value: "/Event/EventData/Data[@Name=\"VhdFileName\"]"
24+
25+
# Documentation:
26+
# https://nasbench.medium.com/finding-forensic-goodness-in-obscure-windows-event-logs-60e978ea45a3
27+
# This map applies to Windows 10 / Windows 11 / Windows Server 2019
28+
#
29+
# Example Event Data:
30+
# <Event>
31+
# <System>
32+
# <Provider Name="Microsoft-Windows-VHDMP" Guid="e2816346-87f4-4f85-95c3-0c79409aa89d" />
33+
# <EventID>2</EventID>
34+
# <Version>0</Version>
35+
# <Level>4</Level>
36+
# <Task>0</Task>
37+
# <Opcode>0</Opcode>
38+
# <Keywords>0x8000000000000000</Keywords>
39+
# <TimeCreated SystemTime="2022-06-18 18:09:53.7040183" />
40+
# <EventRecordID>4</EventRecordID>
41+
# <Correlation />
42+
# <Execution ProcessID="4864" ThreadID="3524" />
43+
# <Channel>Microsoft-Windows-VHDMP-Operational</Channel>
44+
# <Computer>WIN-M2J77GC10N1</Computer>
45+
# <Security UserID="S-1-5-21-1018296586-1262379815-4003437281-500" />
46+
# </System>
47+
# <EventData>
48+
# <Data Name="VhdFileName">C:\Users\Administrator\Documents\TEST.vhdx</Data>
49+
# <Data Name="VhdDiskNumber">1</Data>
50+
# </EventData>
51+
# </Event>

evtx/Maps/Microsoft-Windows-VHDMP-Operational_Microsoft-Windows-VHDMP_2.map evtx/Maps/Microsoft-Windows-VHDMP-Operational_Microsoft-Windows-VHDMP_2_Legacy.map

+9-1
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
Author: Phill Moore
1+
Author: Phill Moore, Gabriele Zambelli
22
Description: A VHD has been removed
33
EventId: 2
44
Channel: "Microsoft-Windows-VHDMP/Operational"
@@ -14,9 +14,17 @@ Maps:
1414
-
1515
Name: VhdNumber
1616
Value: "/Event/EventData/Data[@Name=\"VhdDiskNumber\"]"
17+
-
18+
Property: PayloadData2
19+
PropertyValue: "VhdName: %VhdName%"
20+
Values:
21+
-
22+
Name: VhdName
23+
Value: "/Event/EventData/Data[@Name=\"VhdFileName\"]"
1724

1825
# Documentation:
1926
# https://nasbench.medium.com/finding-forensic-goodness-in-obscure-windows-event-logs-60e978ea45a3
27+
# This legacy map applies to Windows 8 / Windows Server 2012. The channel name "Microsoft-Windows-VHDMP/Operational" was renamed to "Microsoft-Windows-VHDMP-Operational" in more recent operating systems.
2028
#
2129
# Example Event Data:
2230
# <Event>

0 commit comments

Comments
 (0)