sentinel-attack icon indicating copy to clipboard operation
sentinel-attack copied to clipboard

Parser/Sysmon missing MITRE attribution details for EventID 22

Open CyberSecOps opened this issue 6 years ago • 1 comments

Parser-EventID-22

There's no technique_id, technique_name or phase_name attributed in Sysmon EventID 22.

CyberSecOps avatar Sep 18 '19 11:09 CyberSecOps

In the current sysmonconfig.xml we only have exclusion rules for Sysmon EventID 22 defined at the moment; there is definitely scope to insert inclusion rules mapped to MITRE ATT&CK. Looping in @olafhartong for visibility.

netevert avatar Sep 18 '19 14:09 netevert