Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Windows Sysmon Event ID 3 ASIM Parser #6888

Draft
wants to merge 94 commits into
base: master
Choose a base branch
from
Draft
Changes from 1 commit
Commits
Show all changes
94 commits
Select commit Hold shift + click to select a range
7df75d6
Add files via upload
Dec 13, 2022
54b36e8
Update Indenting
Dec 13, 2022
c7ebbc4
Update vimNetworkSessionMicrosoftSysmon.yaml
Dec 13, 2022
f71ee92
Update ASimNetworkSessionMicrosoftSysmon.yaml
Dec 13, 2022
1dda523
Update ASimNetworkSessionMicrosoftSysmon.yaml
Dec 13, 2022
5ade777
Update ASimNetworkSessionMicrosoftSysmon.yaml
Dec 13, 2022
6ac9fff
Update vimNetworkSessionMicrosoftSysmon.yaml
Dec 14, 2022
ad47678
Update vimNetworkSessionMicrosoftSysmon.yaml
Dec 14, 2022
452138e
Update vimNetworkSessionMicrosoftSysmon.yaml
Dec 14, 2022
702b9c2
Update vimNetworkSessionMicrosoftSysmon.yaml
Dec 14, 2022
c7f55d3
Update vimNetworkSessionMicrosoftSysmon.yaml
Dec 14, 2022
8e11428
Update vimNetworkSessionMicrosoftSysmon.yaml
Dec 14, 2022
dc42e24
Update vimNetworkSessionMicrosoftSysmon.yaml
Dec 14, 2022
7884c08
Update vimNetworkSessionMicrosoftSysmon.yaml
Dec 14, 2022
13f2aec
Update vimNetworkSessionMicrosoftSysmon.yaml
Dec 14, 2022
2de129b
Update vimNetworkSessionMicrosoftSysmon.yaml
Dec 15, 2022
ba7c5d8
Update vimNetworkSessionMicrosoftSysmon.yaml
Dec 15, 2022
24b46b5
Update vimNetworkSessionMicrosoftSysmon.yaml
Dec 15, 2022
1c5d5ba
Update vimNetworkSessionMicrosoftSysmon.yaml
Dec 15, 2022
37a567d
Update vimNetworkSessionMicrosoftSysmon.yaml
Dec 19, 2022
f3cafdb
Update vimNetworkSessionMicrosoftSysmon.yaml
Dec 19, 2022
37588fe
Update vimNetworkSessionMicrosoftSysmon.yaml
Dec 19, 2022
6eea59d
Update ASimNetworkSessionMicrosoftSysmon.yaml
Dec 19, 2022
30d4997
Update vimNetworkSessionMicrosoftSysmon.yaml
Dec 19, 2022
65f3cfa
Update ASimNetworkSessionMicrosoftSysmon.yaml
Dec 19, 2022
d71bc0d
Update vimNetworkSessionMicrosoftSysmon.yaml
Dec 19, 2022
ebe820b
Update vimNetworkSessionMicrosoftSysmon.yaml
Dec 19, 2022
11ccfd7
Update ASimNetworkSessionMicrosoftSysmon.yaml
Dec 19, 2022
31909c7
Update ASimNetworkSessionMicrosoftSysmon.yaml
Dec 20, 2022
557b070
Update vimNetworkSessionMicrosoftSysmon.yaml
Dec 20, 2022
8d1132b
Update ASimNetworkSessionMicrosoftSysmon.yaml
Dec 20, 2022
179c1d0
Update vimNetworkSessionMicrosoftSysmon.yaml
Dec 20, 2022
f230d72
Update ASimNetworkSessionMicrosoftSysmon.yaml
Dec 20, 2022
c7597c7
Update vimNetworkSessionMicrosoftSysmon.yaml
Dec 20, 2022
147a091
Update vimNetworkSessionMicrosoftSysmon.yaml
Dec 20, 2022
76e827c
Update ASimNetworkSessionMicrosoftSysmon.yaml
Dec 20, 2022
4db9ae8
Update vimNetworkSessionMicrosoftSysmon.yaml
Dec 20, 2022
73559eb
Update vimNetworkSessionMicrosoftSysmon.yaml
Dec 20, 2022
5c0eedc
Update ASimNetworkSessionMicrosoftSysmon.yaml
Dec 20, 2022
f6d5015
Update ASimNetworkSessionMicrosoftSysmon.yaml
Dec 20, 2022
58b732d
Update vimNetworkSessionMicrosoftSysmon.yaml
Dec 20, 2022
7b54f0d
Update vimNetworkSessionMicrosoftSysmon.yaml
Dec 20, 2022
0b4921e
Update vimNetworkSessionMicrosoftSysmon.yaml
Dec 20, 2022
203a57b
Update ASimNetworkSessionMicrosoftSysmon.yaml
Dec 20, 2022
6e0c964
Update vimNetworkSessionMicrosoftSysmon.yaml
Dec 20, 2022
413f4e5
Update vimNetworkSessionMicrosoftSysmon.yaml
Dec 20, 2022
751a6b2
Update ASimNetworkSessionMicrosoftSysmon.yaml
Dec 20, 2022
5ff1ec5
Update vimNetworkSessionMicrosoftSysmon.yaml
Dec 20, 2022
24c98f9
Update vimNetworkSessionMicrosoftSysmon.yaml
Dec 20, 2022
43b3763
Update ASimNetworkSessionMicrosoftSysmon.yaml
Dec 20, 2022
8a4179e
Update imNetworkSession.yaml
Dec 21, 2022
b2b67df
Update ASimNetworkSessionMicrosoftSysmon.yaml
Dec 28, 2022
2b54b41
Update ASimNetworkSessionMicrosoftSysmon.yaml
Dec 29, 2022
484c84d
Update vimNetworkSessionMicrosoftSysmon.yaml
Dec 29, 2022
49ac77d
Update ASimNetworkSessionMicrosoftSysmon.yaml
Jan 2, 2023
7822a91
Update vimNetworkSessionMicrosoftSysmon.yaml
Jan 2, 2023
5d62875
Update vimNetworkSessionMicrosoftSysmon.yaml
Jan 2, 2023
d3b6392
Update ASimNetworkSessionMicrosoftSysmon.yaml
Jan 2, 2023
c0d0bbf
Update ASimNetworkSessionMicrosoftSysmon.yaml
Jan 2, 2023
db3a008
Update vimNetworkSessionMicrosoftSysmon.yaml
Jan 2, 2023
76c13e2
Update vimNetworkSessionMicrosoftSysmon.yaml
Jan 3, 2023
252d74f
Update vimNetworkSessionMicrosoftSysmon.yaml
Jan 3, 2023
b758c12
Update vimNetworkSessionMicrosoftSysmon.yaml
Jan 3, 2023
217aa91
Update vimNetworkSessionMicrosoftSysmon.yaml
Jan 3, 2023
9d0f9b9
Update vimNetworkSessionMicrosoftSysmon.yaml
Jan 3, 2023
b345228
Update vimNetworkSessionMicrosoftSysmon.yaml
Jan 3, 2023
7a53e45
Update vimNetworkSessionMicrosoftSysmon.yaml
Jan 3, 2023
e8ff8c6
Update vimNetworkSessionMicrosoftSysmon.yaml
Jan 3, 2023
159d0f4
Update vimNetworkSessionMicrosoftSysmon.yaml
Jan 3, 2023
7e68afe
Update ASimNetworkSessionMicrosoftSysmon.yaml
Jan 3, 2023
caf48a6
Update ASimNetworkSessionMicrosoftSysmon.yaml
Jan 3, 2023
f29aa65
Update vimNetworkSessionMicrosoftSysmon.yaml
Jan 3, 2023
999abc2
Update vimNetworkSessionMicrosoftSysmon.yaml
Jan 3, 2023
257bd64
Update vimNetworkSessionMicrosoftSysmon.yaml
Jan 4, 2023
e19f8a1
Update ASimNetworkSessionMicrosoftSysmon.yaml
Jan 4, 2023
d87fb94
Update vimNetworkSessionMicrosoftSysmon.yaml
Jan 4, 2023
fce73e5
Update ASimNetworkSessionMicrosoftSysmon.yaml
Jan 4, 2023
fed647b
Update vimNetworkSessionMicrosoftSysmon.yaml
Jan 4, 2023
28d7edc
Update vimNetworkSessionMicrosoftSysmon.yaml
Jan 4, 2023
1c21ac4
Update ASimNetworkSessionMicrosoftSysmon.yaml
Jan 4, 2023
8b1a509
Update vimNetworkSessionMicrosoftSysmon.yaml
Jan 4, 2023
3a0640d
Update ASimNetworkSessionMicrosoftSysmon.yaml
Jan 4, 2023
a16acb2
Update vimNetworkSessionMicrosoftSysmon.yaml
Jan 4, 2023
5892244
Update ASimNetworkSessionMicrosoftSysmon.yaml
Jan 4, 2023
3c4a471
Update vimNetworkSessionMicrosoftSysmon.yaml
Jan 4, 2023
72106ff
Update vimNetworkSessionMicrosoftSysmon.yaml
Jan 4, 2023
05e4468
Update ASimNetworkSessionMicrosoftSysmon.yaml
Jan 5, 2023
f7b8e53
Update vimNetworkSessionMicrosoftSysmon.yaml
Jan 5, 2023
e2ecb92
Update vimNetworkSessionMicrosoftSysmon.yaml
Jan 9, 2023
86dff03
Update vimNetworkSessionMicrosoftSysmon.yaml
Jan 9, 2023
97dd9dc
Update vimNetworkSessionMicrosoftSysmon.yaml
Jan 9, 2023
e6e2926
Update vimNetworkSessionMicrosoftSysmon.yaml
Jan 9, 2023
2feb316
Update vimNetworkSessionMicrosoftSysmon.yaml
Jan 9, 2023
721a73d
Merge branch 'master' into pr/6888
v-atulyadav Jun 16, 2023
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
Update ASimNetworkSessionMicrosoftSysmon.yaml
  • Loading branch information
Goos authored Jan 4, 2023
commit e19f8a135491900c33fe53ec15c8f42392a83f87
Original file line number Diff line number Diff line change
Expand Up @@ -46,12 +46,11 @@ ParserQuery: |
DestinationPort:int,
DestinationPortName:string
) with (regex=@'<Data Name="(\w+)">{?([^>]*)}?</Data>')
| parse EventData with * '<Data Name="ProcessGuid">{' ProcessGuid "}" *
| project-away EventData
| project-rename
SrcHostname = SourceHostname,
DstHostname = DestinationHostname
| extend
ProcessGuid = tostring(split(split(ProcessGuid, "{")[-1], "}")[0])
};
let Sysmon3_WindowsEvent=(disabled:bool=false){
WindowsEvent
Expand All @@ -64,7 +63,6 @@ ParserQuery: |
SrcHostname = tostring(EventData.SrcHostname),
RuleName = tostring(EventData.RuleName),
UtcTime = todatetime(EventData.UtcTime),
ProcessGuid = tostring(split(split(EventData.ProcessGuid, "{")[-1], "}")[0]),
ProcessId = tostring(EventData.ProcessId),
Image = tostring(EventData.Image),
User = tostring(EventData.User),
Expand All @@ -76,6 +74,7 @@ ParserQuery: |
DestinationIsIpv6 = tobool(EventData.DestinationIsIpv6),
DestinationPort = toint(EventData.DestinationPort),
DestinationPortName = tostring(EventData.DestinationPortName)
| parse EventData.ProcessGuid with * "{" ProcessGuid "}" *
| project-away EventData
};
union Sysmon3_Event,Sysmon3_WindowsEvent
goosvorbook marked this conversation as resolved.
Show resolved Hide resolved
Expand Down