Skip to content

Commit 83b7a06

Browse files
authored
Added missing CS pipe and some comments
1 parent 867b37a commit 83b7a06

File tree

1 file changed

+6
-1
lines changed

1 file changed

+6
-1
lines changed

sysmonconfig-export.xml

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -822,14 +822,19 @@
822822
<!--DATA: UtcTime, ProcessGuid, ProcessId, PipeName, Image-->
823823
<RuleGroup name="" groupRelation="or">
824824
<PipeEvent onmatch="include">
825+
<!-- Remote Command Execution Tools -->
825826
<PipeName condition="contains any">paexec;remcom;csexec</PipeName>
827+
<!-- Password or Credential Dumpers -->
826828
<PipeName condition="contains any">\lsadump;\cachedump;\wceservicepipe</PipeName>
829+
<!-- Malware -->
827830
<PipeName condition="contains any">\isapi_http;\isapi_dg;\isapi_dg2;\sdlrpc;\ahexec;\winsession;\lsassw;\46a676ab7f179e511e30dd2dc41bd388;\9f81f59bc58452127884ce513865ed20;\e710f28d59aa529d6792ca6ff0ca1b34;\rpchlp_3;\NamePipe_MoreWindows;\pcheap_reuse;\gruntsvc;\583da945-62af-10e8-4902-a8f205c72b2e;\bizkaz;\svcctl;\Posh;\jaccdpqnvbrrxlaf;\csexecsvc</PipeName>
831+
<PipeName condition="contains any">\atctl;\userpipe;\iehelper;\sdlrpc;\comnap</PipeName>
832+
<!-- Cobalt Strike Pipe Names -->
828833
<PipeName condition="contains all">MSSE-;-server</PipeName>
829834
<PipeName condition="begin with">\postex_</PipeName>
830835
<PipeName condition="begin with">\postex_ssh_</PipeName>
831836
<PipeName condition="begin with">\status_</PipeName>
832-
<PipeName condition="contains any">\atctl;\userpipe;\iehelper;\sdlrpc;\comnap</PipeName>
837+
<PipeName condition="begin with">\msagent_</PipeName>
833838
</PipeEvent>
834839
</RuleGroup>
835840

0 commit comments

Comments
 (0)