Detection rules › Sigma

Sysmon Configuration Modification

Status
test
Severity
high
Log source
category sysmon_status, product windows
Author
frack113
Source
github.com/SigmaHQ/sigma

Detects when an attacker tries to hide from Sysmon by disabling or stopping it

Known false positives

  • Legitimate administrative action

MITRE ATT&CK coverage

TacticTechniques
Stealth

Telemetry coverage

Rule body

title: Sysmon Configuration Modification
id: 1f2b5353-573f-4880-8e33-7d04dcf97744
status: test
description: Detects when an attacker tries to hide from Sysmon by disabling or stopping it
references:
    - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1562.001/T1562.001.md
    - https://talesfrominfosec.blogspot.com/2017/12/killing-sysmon-silently.html
author: frack113
date: 2021-06-04
modified: 2022-08-02
tags:
    - attack.stealth
    - attack.t1564
logsource:
    product: windows
    category: sysmon_status
detection:
    selection_stop:
        State: Stopped
    selection_conf:
        - 'Sysmon config state changed'
    filter:
        State: Started
    condition: 1 of selection_* and not filter
falsepositives:
    - Legitimate administrative action
level: high

Stages and Predicates

Stage 0: condition

1 of selection_* and not filter

Stage 1: selection_stop

selection_stop:
    State: Stopped

Stage 2: selection_conf

selection_conf:
    - 'Sysmon config state changed'

Stage 3: not filter

filter:
    State: Started

Exclusions

The rule actively suppresses these predicates.

FieldKindExcluded valuesSearch
StateeqStartedexcludes:State field:"State" value:"Started"

Indicators

These rows show field, operator, and value matches.

FieldKindValuesSearch
Stateeq
  • Stopped
field:"State" kind:eq value:"Stopped"