-
Notifications
You must be signed in to change notification settings - Fork 4
Expand file tree
/
Copy pathbaseline.rules
More file actions
206 lines (151 loc) · 7.09 KB
/
baseline.rules
File metadata and controls
206 lines (151 loc) · 7.09 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
[{
"explorer.exe":{ "max_ttl": 1000000,"min_ttl": 20, "Points": 10,
"1":{"Points": 30,
"Image":{"Points": 100, "Value": "EXPLORER_IMAGES"},
"ParentImage":{"Points": 50, "Value": "EXPLORER_PARENT_IMAGE"},
"-User":{"Points": 100, "Value": "system"},
"CurrentDirectory":{"Points": 20, "Value": "C:\\Windows\\"},
"-TerminalSessionId":{"Points": 100, "Value": "0"},
"IntegrityLevel":{"Points": 50, "Value": "Medium"},
"Company":{"Points": 100, "Value": "Microsoft Corporation"},
"Description":{"Points": 100, "Value": "Windows Explorer"},
"OriginalFileName":{"Points": 100, "Value": "EXPLORER.EXE"}
},
"100":{"Points": 10, "N": 30, "Seconds": 3600},
"2":{"Points": 5, "N": 30, "Seconds": 86400,
"TargetFilename":{"Points": 5, "Value": "AppData"}
},
"3":{"Points": 25, "N": 20, "Seconds": 3600,
"Initiated": {"Points": 30, "Value": "true"}
},
"7":{"Points": 10,
"ImageLoaded": {"Points": 10, "Value": "EXPLORER_IMAGE_LOADED_PATH"},
"SignatureStatus": {"Points": 50, "Value": "MODULE_SIGNATURE_STATUS"}
},
"-8":{"Points": 100},
"108":{"Points": 10,
"SourceImage":{"Points": 30, "Value": "WINLOGON_EXPLORER_THREAD_CREATED_FROM_REMOTE_PROCESS"}},
"9":{"Points": 10, "N": 100, "Seconds": 86400,
"Device":{"Points": 100, "Value": "\\Device\\HarddiskVolume"}
},
"11":{"Points": 10, "N": 100, "Seconds": 86400},
"-14":{"Points": 10},
"-15":{"Points": 10},
"-17":{"Points": 60},
"18":{"Points": 20, "N": 20, "Seconds": 3600,
"PipeName":{"Points": 50, "Value": "EXPLORER_CONNECT_PIPES"}
}
},
"lsass.exe":{ "max_ttl": 1000000,"min_ttl": 20, "Points": 10,
"1":{"Points": 100,
"Image":{"Points": 100, "Value": "C:\\WINDOWS\\system32\\lsass.exe"},
"ParentImage":{"Points": 100, "Value": "C:\\Windows\\System32\\wininit.exe"},
"CurrentDirectory":{"Points": 100, "Value": "C:\\Windows\\System32\\"},
"User":{"Points": 100, "Value": "system"},
"TerminalSessionId":{"Points": 100, "Value": "0"},
"IntegrityLevel":{"Points": 100, "Value": "system"}
},
"100":{"Points": 30, "N": 3, "Seconds": 86400,
"ChildImage":{"Points": 100, "Value": "C:\\Windows\\System32\\efsui.exe"}
},
"-2":{"Points": 100},
"3":{"Points": 30, "N": 20, "Seconds": 3600},
"7":{"Points": 30, "N": 120, "Seconds": 86400,
"ImageLoaded": {"Points": 100, "Value": "c:\\Windows\\System32\\"},
"SignatureStatus": {"Points": 50, "Value": "MODULE_SIGNATURE_STATUS"}
},
"-8":{"Points": 100},
"108":{"Points": 10, "N": 5, "Seconds": 86400,
"SourceImage": {"Points": 20, "Value": "LSASS_THREAD_CREATED_FROM_REMOTE_PROCESS"}
},
"9":{"Points": 30, "N": 50, "Seconds": 3600,
"Device":{"Points": 100, "Value": "\\Device\\HarddiskVolume"}
},
"11":{"Points": 30, "N": 50, "Seconds": 3600,
"TargetFilename": {"Points": 10, "Value": "LSASS_FILE_CREATE"}
},
"-14":{"Points": 100},
"-15":{"Points": 100},
"17":{"Points": 30, "N": 6, "Seconds": 3600,
"PipeName":{"Points": 50, "Value": "LSASS_CREATE_PIPES"}
},
"18":{"Points": 30, "N": 5, "Seconds": 3600,
"PipeName":{"Points": 50, "Value": "LSASS_CONNECT_PIPES"}
}
},
"winlogon.exe":{ "max_ttl": 1000000,"min_ttl": 20, "Points": 10,
"1":{"Points": 100,
"Image":{"Points": 100, "Value": "C:\\WINDOWS\\system32\\winlogon.exe"},
"ParentImage":{"Points": 100, "Value": "C:\\Windows\\System32\\smss.exe"},
"CurrentDirectory":{"Points": 100, "Value": "C:\\Windows\\System32"},
"User":{"Points": 100, "Value": "system"},
"-TerminalSessionId":{"Points": 100, "Value": "0"},
"IntegrityLevel":{"Points": 100, "Value": "system"}
},
"100":{"Points": 30,
"ChildImage":{"Points": 25, "Value": "WINLOGON_CHILDS"}
},
"-2":{"Points": 100},
"-3":{"Points": 100},
"7":{"Points": 30, "N": 60, "Seconds": 86400,
"ImageLoaded": {"Points": 100, "Value": "c:\\Windows\\System32\\"},
"SignatureStatus": {"Points": 50, "Value": "MODULE_SIGNATURE_STATUS"}
},
"8":{"Points": 10, "StartModule": {"Points": 50, "Value": "C:\\Windows\\SYSTEM32\\ntdll.dll"}
},
"108":{"Points": 10, "N": 3, "Seconds": 86400,
"SourceImage": {"Points": 20, "Value": "WINLOGON_EXPLORER_THREAD_CREATED_FROM_REMOTE_PROCESS"}
},
"9":{"Points": 20, "N": 15, "Seconds": 3600,
"Device":{"Points": 100, "Value": "\\Device\\HarddiskVolume"}
},
"10":{"Points": 10,
"TargetImage":{"Points": 25, "Value": "WINLOGON_CHILDS"}
},
"11":{"Points": 10, "N": 50, "Seconds": 3600,
"TargetFilename": {"Points": 50, "Value": "C:\\Windows\\Resources\\Themes\\aero\\"}
},
"-14":{"Points": 100},
"-15":{"Points": 100},
"-17":{"Points": 100},
"18":{"Points": 30, "N": 5, "Seconds": 3600,
"PipeName":{"Points": 50, "Value": "\\wkssvc"}
}
},
"services.exe":{ "max_ttl": 1000000,"min_ttl": 20, "Points": 10,
"1":{"Points": 100,
"Image":{"Points": 100, "Value": "C:\\WINDOWS\\system32\\services.exe"},
"ParentImage":{"Points": 100, "Value": "C:\\Windows\\System32\\wininit.exe"},
"CurrentDirectory":{"Points": 100, "Value": "C:\\Windows\\System32"},
"User":{"Points": 100, "Value": "system"},
"TerminalSessionId":{"Points": 100, "Value": "0"},
"IntegrityLevel":{"Points": 100, "Value": "system"}
},
"100":{"Points": 10, "N": 200, "Seconds": 3600},
"-2":{"Points": 100},
"-3":{"Points": 25},
"7":{"Points": 30, "N": 40, "Seconds": 86400,
"ImageLoaded": {"Points": 100, "Value": "c:\\Windows\\System32\\"},
"SignatureStatus": {"Points": 50, "Value": "MODULE_SIGNATURE_STATUS"},
"Signature": {"Points": 10, "Value": "Microsoft Windows"}
},
"-8":{"Points": 50, "N": 4, "Seconds": 86400,
"TargetImage": {"Points": 50, "Value": "SERVICES_THREAD_CREATED_TO_REMOTE_PROCESS"}
},
"108":{"Points": 10, "N": 3, "Seconds": 86400,
"SourceImage": {"Points": 20, "Value": "C:\\Windows\\System32\\csrss.exe"}
},
"-9":{"Points": 10},
"11":{"Points": 10, "N": 50, "Seconds": 3600,
"TargetFilename": {"Points": 50, "Value": "C:\\Windows\\System32\\LogFiles\\"}
},
"-14":{"Points": 100},
"-15":{"Points": 100},
"17":{"Points": 30, "N": 4, "Seconds": 86400,
"PipeName":{"Points": 50, "Value": "SERVICES_CREATE_PIPES"}
},
"18":{"Points": 30, "N": 2, "Seconds": 86400,
"PipeName":{"Points": 50, "Value": "SERVICES_CONNECT_PIPES"}
}
}
}]