Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add new Event IDs for virus/tamper matches #718

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

jjrbg
Copy link
Contributor

@jjrbg jjrbg commented Jul 2, 2020

Example logs...

2020 Jul 01 14:29:17 WinEvtLog: Application: ERROR(51): Symantec AntiVirus: SYSTEM: NT AUTHORITY: agent123: Security Risk Found! signature123 in File: c:\windows\system32\windowspowershell\v1.0\powershell.exe by: scan scan. Action: . Action Description: Access Denied

2020 Jul 01 14:08:20 WinEvtLog: Application: INFORMATION(45): Symantec AntiVirus: SYSTEM: NT AUTHORITY: agent123: Scan type: Tamper Protection Scan Event: Tamper Protection Detection Security risk detected: C:\PROGRAM FILES (X86)\THING\THING.EXE File: C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\14.0.3897.1101.105\Bin\ccSvcHst.exe Location: C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\14.0.3897.1101.105\Bin Computer: AGENT123 User: SYSTEM Action taken: Access denied Date found: 01 July 2020 14:08:20

xample logs...

2020 Jul 01 14:29:17 WinEvtLog: Application: ERROR(51): Symantec AntiVirus: SYSTEM: NT AUTHORITY: agent123:       Security Risk Found! signature123 in File: c:\windows\system32\windowspowershell\v1.0\powershell.exe by: scan scan.  Action: .  Action Description: Access Denied

2020 Jul 01 14:08:20 WinEvtLog: Application: INFORMATION(45): Symantec AntiVirus: SYSTEM: NT AUTHORITY: agent123:       Scan type: Tamper Protection Scan  Event: Tamper Protection Detection  Security risk detected: C:\PROGRAM FILES (X86)\THING\THING.EXE  File: C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\14.0.3897.1101.105\Bin\ccSvcHst.exe  Location: C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\14.0.3897.1101.105\Bin  Computer: AGENT123  User: SYSTEM  Action taken: Access denied  Date found: 01 July 2020  14:08:20
@vikman90 vikman90 changed the base branch from master to develop July 31, 2020 12:04
@vikman90 vikman90 changed the base branch from develop to master September 25, 2020 08:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant