Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Parser/Sysmon missing MITRE attribution details for EventID 22 #19

Open
CyberSecOps opened this issue Sep 18, 2019 · 1 comment
Open
Labels
enhancement New feature or request

Comments

@CyberSecOps
Copy link

CyberSecOps commented Sep 18, 2019

Parser-EventID-22

There's no technique_id, technique_name or phase_name attributed in Sysmon EventID 22.

@netevert
Copy link
Owner

In the current sysmonconfig.xml we only have exclusion rules for Sysmon EventID 22 defined at the moment; there is definitely scope to insert inclusion rules mapped to MITRE ATT&CK. Looping in @olafhartong for visibility.

@netevert netevert added the enhancement New feature or request label Sep 18, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants