diff --git a/windows/sysmon/events/event-1.yml b/windows/sysmon/events/event-1.yml index a2b7b2cb4..b2e62ee7a 100644 --- a/windows/sysmon/events/event-1.yml +++ b/windows/sysmon/events/event-1.yml @@ -192,46 +192,46 @@ event_sample: The publisher has been disabled and its resource is not available. This usually occurs when the publisher is in the process of being uninstalled or upgraded - format: xml sample: |- - - - - 1 - 5 - 4 - 1 - 0 - 0x8000000000000000 - - 2472309 - - - Microsoft-Windows-Sysmon/Operational - pedro-computer - - - - - - 2022-09-23 00:00:46.275 - {564ff025-f72e-632c-c407-000000000500} - 7860 - C:\Windows\System32\svchost.exe - 10.0.18362.1 (WinBuild.160101.0800) - Host Process for Windows Services - Microsoft® Windows® Operating System - Microsoft Corporation - svchost.exe - C:\Windows\system32\svchost.exe -k netsvcs -p -s wlidsvc - C:\Windows\system32\ - NT AUTHORITY\SYSTEM - {564ff025-d424-62f6-e703-000000000000} - 0x3e7 - 0 - System - SHA1=75C5A97F521F760E32A4A9639A653EED862E9C61,MD5=9520A99E77D6196D0D09833146424113,SHA256=DD191A5B23DF92E12A8852291F9FB5ED594B76A28A5A464418442584AFD1E048,IMPHASH=247B9220E5D9B720A82B2C8B5069AD69 - {564ff025-d424-62f6-0b00-000000000500} - 584 - C:\Windows\System32\services.exe - C:\Windows\system32\services.exe - NT AUTHORITY\SYSTEM - - + + + + 1 + 5 + 4 + 1 + 0 + 0x8000000000000000 + + 2472309 + + + Microsoft-Windows-Sysmon/Operational + pedro-computer + + + + - + 2022-09-23 00:00:46.275 + {564ff025-f72e-632c-c407-000000000500} + 7860 + C:\Windows\System32\svchost.exe + 10.0.18362.1 (WinBuild.160101.0800) + Host Process for Windows Services + Microsoft® Windows® Operating System + Microsoft Corporation + svchost.exe + C:\Windows\system32\svchost.exe -k netsvcs -p -s wlidsvc + C:\Windows\system32\ + NT AUTHORITY\SYSTEM + {564ff025-d424-62f6-e703-000000000000} + 0x3e7 + 0 + System + SHA1=75C5A97F521F760E32A4A9639A653EED862E9C61,MD5=9520A99E77D6196D0D09833146424113,SHA256=DD191A5B23DF92E12A8852291F9FB5ED594B76A28A5A464418442584AFD1E048,IMPHASH=247B9220E5D9B720A82B2C8B5069AD69 + {564ff025-d424-62f6-0b00-000000000500} + 584 + C:\Windows\System32\services.exe + C:\Windows\system32\services.exe + NT AUTHORITY\SYSTEM + + diff --git a/windows/sysmon/events/event-15.yml b/windows/sysmon/events/event-15.yml index d90fe87d4..c11ad7ad0 100644 --- a/windows/sysmon/events/event-15.yml +++ b/windows/sysmon/events/event-15.yml @@ -58,7 +58,7 @@ event_fields: name: Contents type: string description: Content of the file - sample_value: [ZoneTransfer] ZoneId=3 ReferrerUrl=Z:\files\last_sysmon\Sysmon.zip + sample_value: '[ZoneTransfer] ZoneId=3 ReferrerUrl=Z:\files\last_sysmon\Sysmon.zip' references: - text: Sysmon Source link: https://docs.microsoft.com/en-us/sysinternals/downloads/sysmon#event-id-15-filecreatestreamhash @@ -125,4 +125,4 @@ event_sample: SHA1=000F277774DD28D7F4D00E174B4741F71D8828E4,MD5=2004CA2A9BFEBFB45B145B5D80B3FD76,SHA256=2AD30B0FA4239B95D7059A1E5D7BC16328F98B23C89D3A437A3F1661F05F82F0,IMPHASH=00000000000000000000000000000000 [ZoneTransfer] ZoneId=3 ReferrerUrl=Z:\files\last_sysmon\Sysmon.zip - \ No newline at end of file +