Sysmon_OSSEC icon indicating copy to clipboard operation
Sysmon_OSSEC copied to clipboard

Other windows rules stop firing.

Open strengthnotes opened this issue 10 years ago • 9 comments

Josh, Been playing with variations of this for Sysmon3 when I write my decoder similar to yours with parent and type as windows, OSSEC stops alerting on other windows events. Have you notices this type of behaviour?

strengthnotes avatar Jun 15 '15 14:06 strengthnotes

I am deploying Sysmonv3 in my test environment Thursday.. I will let you know what I find by the end of this week...

defensivedepth avatar Jun 15 '15 15:06 defensivedepth

Yeah I have not worked much with custom parsers/rules so may be doing something wrong but Brian Kellogg mentioned having the same issue here.

https://groups.google.com/forum/#!topic/security-onion/hBmJ2q5NuaY

strengthnotes avatar Jun 15 '15 16:06 strengthnotes

Just an update on this issue... I am currently tweaking the ELSA & OSSEC parsers for Sysmon v3, and hope to have them done & tested within the next week or two.

defensivedepth avatar Jun 28 '15 12:06 defensivedepth

Sounds good let me know if I can assist in any way.

strengthnotes avatar Jul 06 '15 20:07 strengthnotes

I just posted the v3 decoder, as well as an updated version of the v1 decoder. Try removing the tag and see if that helps as well....

https://github.com/defensivedepth/Sysmon_OSSEC/blob/master/Sysmon_OSSEC-Decoders.xml

defensivedepth avatar Jul 12 '15 10:07 defensivedepth

Thanks Josh I will check it out sometime this week or next. What do you mean by "try removing the tag"

strengthnotes avatar Jul 12 '15 14:07 strengthnotes

Sorry, left out a word... On the v1 decoder, I removed the tag, which should not have been in there...

defensivedepth avatar Jul 13 '15 01:07 defensivedepth

Side note, are you running the decoder + rules in a SO distributed environment?

defensivedepth avatar Jul 13 '15 11:07 defensivedepth

Not currently just single SO standalone.

strengthnotes avatar Jul 13 '15 12:07 strengthnotes