From 867b37a48b739fbea8b0b207ea678b4de2090538 Mon Sep 17 00:00:00 2001 From: Florian Roth Date: Thu, 27 May 2021 19:42:26 +0200 Subject: [PATCH 1/2] Important and relevant NamedPipe names The events generated by an explicit matches on the listed pipe names should be few and highly relevant. --- sysmonconfig-export.xml | 19 +++++++++++++------ 1 file changed, 13 insertions(+), 6 deletions(-) diff --git a/sysmonconfig-export.xml b/sysmonconfig-export.xml index f4acf26..0a5aac8 100644 --- a/sysmonconfig-export.xml +++ b/sysmonconfig-export.xml @@ -820,11 +820,18 @@ - - - - - + + + paexec;remcom;csexec + \lsadump;\cachedump;\wceservicepipe + \isapi_http;\isapi_dg;\isapi_dg2;\sdlrpc;\ahexec;\winsession;\lsassw;\46a676ab7f179e511e30dd2dc41bd388;\9f81f59bc58452127884ce513865ed20;\e710f28d59aa529d6792ca6ff0ca1b34;\rpchlp_3;\NamePipe_MoreWindows;\pcheap_reuse;\gruntsvc;\583da945-62af-10e8-4902-a8f205c72b2e;\bizkaz;\svcctl;\Posh;\jaccdpqnvbrrxlaf;\csexecsvc + MSSE-;-server + \postex_ + \postex_ssh_ + \status_ + \atctl;\userpipe;\iehelper;\sdlrpc;\comnap + + @@ -1156,4 +1163,4 @@ - \ No newline at end of file + From 83b7a06ac483d8abfe6abe7c61c60500d4b795f3 Mon Sep 17 00:00:00 2001 From: Florian Roth Date: Fri, 28 May 2021 09:28:09 +0200 Subject: [PATCH 2/2] Added missing CS pipe and some comments --- sysmonconfig-export.xml | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/sysmonconfig-export.xml b/sysmonconfig-export.xml index 0a5aac8..93aa92e 100644 --- a/sysmonconfig-export.xml +++ b/sysmonconfig-export.xml @@ -822,14 +822,19 @@ + paexec;remcom;csexec + \lsadump;\cachedump;\wceservicepipe + \isapi_http;\isapi_dg;\isapi_dg2;\sdlrpc;\ahexec;\winsession;\lsassw;\46a676ab7f179e511e30dd2dc41bd388;\9f81f59bc58452127884ce513865ed20;\e710f28d59aa529d6792ca6ff0ca1b34;\rpchlp_3;\NamePipe_MoreWindows;\pcheap_reuse;\gruntsvc;\583da945-62af-10e8-4902-a8f205c72b2e;\bizkaz;\svcctl;\Posh;\jaccdpqnvbrrxlaf;\csexecsvc + \atctl;\userpipe;\iehelper;\sdlrpc;\comnap + MSSE-;-server \postex_ \postex_ssh_ \status_ - \atctl;\userpipe;\iehelper;\sdlrpc;\comnap + \msagent_