diff --git a/sysmonconfig-export-block.xml b/sysmonconfig-export-block.xml index 00cf2ae8..9f4489cf 100644 --- a/sysmonconfig-export-block.xml +++ b/sysmonconfig-export-block.xml @@ -946,7 +946,6 @@ \netlogon_ \srvsvc_ \lsarpc_ - \wkssvc_ \demon_pipe @@ -957,8 +956,6 @@ \mypipe-f \mypipe-h \windows.update.manager - \ntsvcs_ - \scerpc_ \demoagent_ \PGMessagePipe @@ -970,6 +967,7 @@ \f53f \rpc_ \spoolss_ + \Winsock2\CatalogChangeListener \win_svc \SearchTextHarvester \adschemerpc @@ -977,7 +975,14 @@ \bc367 \bc31a7 \testPipe - + + \adprinterpipe + + :\PerfLogs\ + :\Users\Public\ + :\Windows\System32\Tasks\ + :\Windows\Tasks\ + \scerpc \ntsvcs \wkssvc @@ -988,6 +993,14 @@ ConnectPipe \MICROSOFT##WID\tsql\query + \coerced\ + thisispipe + \pipe\ + \imposecost;\imposingcost + \PAExec + \RemCom + \PSEXESVC + \PSEXECSVC @@ -997,6 +1010,14 @@ \scerpc \ntsvcs \wkssvc + \MsFteWds + \PGMessagePipe + \SearchTextHarvester + \spoolss + \srvsvc + + \aurora-agent-64.exe + \aurora-agent.exe diff --git a/sysmonconfig-export.xml b/sysmonconfig-export.xml index 056b4171..73610206 100644 --- a/sysmonconfig-export.xml +++ b/sysmonconfig-export.xml @@ -990,7 +990,6 @@ \netlogon_ \srvsvc_ \lsarpc_ - \wkssvc_ \demon_pipe @@ -1001,8 +1000,6 @@ \mypipe-f \mypipe-h \windows.update.manager - \ntsvcs_ - \scerpc_ \demoagent_ \PGMessagePipe @@ -1014,6 +1011,7 @@ \f53f \rpc_ \spoolss_ + \Winsock2\CatalogChangeListener \win_svc \SearchTextHarvester \adschemerpc @@ -1021,6 +1019,14 @@ \bc367 \bc31a7 \testPipe + + \adprinterpipe + + :\PerfLogs\ + :\Users\Public\ + :\Windows\System32\Tasks\ + :\Windows\Tasks\ + \Microsoft\Windows\Start Menu\Programs\Startup\ \scerpc \ntsvcs @@ -1032,6 +1038,14 @@ ConnectPipe \MICROSOFT##WID\tsql\query + \coerced\ + thisispipe + \pipe\ + \imposecost;\imposingcost + \PAExec + \RemCom + \PSEXESVC + \PSEXECSVC @@ -1041,6 +1055,14 @@ \scerpc \ntsvcs \wkssvc + \MsFteWds + \PGMessagePipe + \SearchTextHarvester + \spoolss + \srvsvc + + \aurora-agent-64.exe + \aurora-agent.exe