11[metadata ]
22creation_date = " 2022/01/12"
3- integration = [" windows" , " m365_defender" , " sentinel_one_cloud_funnel" ]
3+ integration = [" windows" , " m365_defender" , " sentinel_one_cloud_funnel" , " crowdstrike " ]
44maturity = " production"
5- updated_date = " 2025/03/20 "
5+ updated_date = " 2025/08/26 "
66
77[rule ]
88author = [" Elastic" ]
@@ -18,6 +18,7 @@ index = [
1818 " endgame-*" ,
1919 " logs-m365_defender.event-*" ,
2020 " logs-sentinel_one_cloud_funnel.*" ,
21+ " logs-crowdstrike.fdr*" ,
2122]
2223language = " eql"
2324license = " Elastic License v2"
@@ -82,35 +83,21 @@ tags = [
8283 " Data Source: Sysmon" ,
8384 " Data Source: Microsoft Defender for Endpoint" ,
8485 " Data Source: SentinelOne" ,
86+ " Data Source: Crowdstrike" ,
8587]
8688timestamp_override = " event.ingested"
8789type = " eql"
8890
8991query = '''
90- registry where host.os.type == "windows" and event.type == "change" and registry.value : ("AccessVBOM", "VbaWarnings") and
91- registry.path : (
92- /* Sysmon */
93- "HKU\\S-1-5-21-*\\SOFTWARE\\Microsoft\\Office\\*\\Security\\AccessVBOM",
94- "HKU\\S-1-5-21-*\\SOFTWARE\\Microsoft\\Office\\*\\Security\\VbaWarnings",
95- "HKU\\S-1-12-1-*\\SOFTWARE\\Microsoft\\Office\\*\\Security\\AccessVBOM",
96- "HKU\\S-1-12-1-*\\SOFTWARE\\Microsoft\\Office\\*\\Security\\VbaWarnings",
97- /* MDE */
98- "HKCU\\S-1-5-21-*\\SOFTWARE\\Microsoft\\Office\\*\\Security\\AccessVBOM",
99- "HKCU\\S-1-5-21-*\\SOFTWARE\\Microsoft\\Office\\*\\Security\\VbaWarnings",
100- "HKCU\\S-1-12-1-*\\SOFTWARE\\Microsoft\\Office\\*\\Security\\AccessVBOM",
101- "HKCU\\S-1-12-1-*\\SOFTWARE\\Microsoft\\Office\\*\\Security\\VbaWarnings",
102- /* Endgame */
103- "\\REGISTRY\\USER\\S-1-5-21-*\\SOFTWARE\\Microsoft\\Office\\*\\Security\\AccessVBOM",
104- "\\REGISTRY\\USER\\S-1-5-21-*\\SOFTWARE\\Microsoft\\Office\\*\\Security\\VbaWarnings",
105- "\\REGISTRY\\USER\\S-1-12-1-*\\SOFTWARE\\Microsoft\\Office\\*\\Security\\AccessVBOM",
106- "\\REGISTRY\\USER\\S-1-12-1-*\\SOFTWARE\\Microsoft\\Office\\*\\Security\\VbaWarnings",
107- /* SentinelOne */
108- "USER\\S-1-5-21-*\\SOFTWARE\\Microsoft\\Office\\*\\Security\\AccessVBOM",
109- "USER\\S-1-5-21-*\\SOFTWARE\\Microsoft\\Office\\*\\Security\\VbaWarnings",
110- "USER\\S-1-12-1-*\\SOFTWARE\\Microsoft\\Office\\*\\Security\\AccessVBOM",
111- "USER\\S-1-12-1-*\\SOFTWARE\\Microsoft\\Office\\*\\Security\\VbaWarnings"
112- ) and
92+ registry where host.os.type == "windows" and event.type == "change" and
93+ registry.value : ("AccessVBOM", "VbaWarnings") and
11394 registry.data.strings : ("0x00000001", "1")
95+
96+ /*
97+ Full registry key paths omitted due to data source variations:
98+ "HKCU\\S-1-*\\SOFTWARE\\Microsoft\\Office\\*\\Security\\AccessVBOM"
99+ "HKCU\\S-1-*\\SOFTWARE\\Microsoft\\Office\\*\\Security\\VbaWarnings"
100+ */
114101'''
115102
116103
0 commit comments