Detection rules › Sigma

Sysmon Configuration Modification

Status
test
Severity
high
Log source
product windows, category sysmon_status
Author
frack113
Source
github.com/SigmaHQ/sigma

Detects when an attacker tries to hide from Sysmon by disabling or stopping it

MITRE ATT&CK coverage

TacticTechniques
StealthT1564 Hide Artifacts

Event coverage

Rule body yaml

title: Sysmon Configuration Modification
id: 1f2b5353-573f-4880-8e33-7d04dcf97744
status: test
description: Detects when an attacker tries to hide from Sysmon by disabling or stopping it
references:
    - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1562.001/T1562.001.md
    - https://talesfrominfosec.blogspot.com/2017/12/killing-sysmon-silently.html
author: frack113
date: 2021-06-04
modified: 2022-08-02
tags:
    - attack.stealth
    - attack.t1564
logsource:
    product: windows
    category: sysmon_status
detection:
    selection_stop:
        State: Stopped
    selection_conf:
        - 'Sysmon config state changed'
    filter:
        State: Started
    condition: 1 of selection_* and not filter
falsepositives:
    - Legitimate administrative action
level: high

Stages and Predicates

Stage 0: condition

1 of selection_* and not filter

Stage 1: selection_stop

selection_stop:
    State: Stopped

Stage 2: selection_conf

selection_conf:
    - 'Sysmon config state changed'

Stage 3: not filter

filter:
    State: Started

Exclusions

Top-level NOT(...) conjuncts: predicates this rule actively suppresses.

FieldKindExcluded values
StateeqStarted

Indicators

Each row is a field, operator, and value that the rule matches. The corpus column counts how many other rules in the catalog look for the same combination: high numbers point to widely-used, community-vetted indicators. Blank or 1 shows that the indicator is specific to this rule.

FieldKindValues
Stateeq
  • Stopped