-
Notifications
You must be signed in to change notification settings - Fork 202
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Ruleset update to support new Sysmon 10 capabilities #431
Comments
Thanks for creating it so quickly after Sysmon v10 was released. I'll be sure to try out rules made here once you start developing them. |
Hello team The main Sysmon rules are already created. Now you have to create rules that generate alerts. There are two options:
Maybe the second option is the best because users will be able to modify this list and add or remove the programs they want. In addition, it must be determined for which programs will generate alerts. Regards, Eva |
What about additions to the decoder? For example should there be an entry in https://github.com/wazuh/wazuh-ruleset/blob/master/decoders/0380-windows_decoders.xml for the new Event ID 22: DNSEvent (DNS query)? |
Hi Paul, Thank you for your feedback. Regards, Eva. |
We're on the latest version, 3.9.2. Thanks for your work on this invaluable feature! |
Hi team,
Let's make Wazuh-Ruleset support events including new features on Sysmon 10.
Sysmon 10 new features to check:
Best regards,
Juan Pablo Sáez
The text was updated successfully, but these errors were encountered: