From 3d5f1796e6611dd2a2f442c9a064e93bb1bfdd50 Mon Sep 17 00:00:00 2001 From: Daniel Melgarejo Date: Wed, 6 May 2020 14:21:08 +0200 Subject: [PATCH] Added more rules related to Windows Eventlog --- rules/0590-win-system_rules.xml | 20 ++++++++++++++++++++ rules/0610-win-ms_logs_rules.xml | 13 +++++++++++++ 2 files changed, 33 insertions(+) diff --git a/rules/0590-win-system_rules.xml b/rules/0590-win-system_rules.xml index 0247b22a7..181438af8 100644 --- a/rules/0590-win-system_rules.xml +++ b/rules/0590-win-system_rules.xml @@ -323,4 +323,24 @@ no_email_alert + + 61102 + ^6008$ + Unexpected system shutdown. + + T1529 + + no_full_log + + + + 61100 + ^1074$ + System has been shutdown by a process/user. + + T1529 + + no_full_log + + diff --git a/rules/0610-win-ms_logs_rules.xml b/rules/0610-win-ms_logs_rules.xml index e0abe8563..7acdcf535 100644 --- a/rules/0610-win-ms_logs_rules.xml +++ b/rules/0610-win-ms_logs_rules.xml @@ -58,6 +58,8 @@ log_clearing,gpg13_10.1,gdpr_II_5.1.f, + + 63100 @@ -81,4 +83,15 @@ Multiple Eventlog warning events no_full_log + + + 63100 + ^6006$ + The Event log service was stopped. + + T1529 + + no_full_log + +