Skip to content

[Rule Tuning] Volume Shadow Copy Deleted or Resized via VssAdmin - Sysmon#1757

Merged
brokensound77 merged 2 commits intomainfrom
vssadmin_sysmon
Feb 11, 2022
Merged

[Rule Tuning] Volume Shadow Copy Deleted or Resized via VssAdmin - Sysmon#1757
brokensound77 merged 2 commits intomainfrom
vssadmin_sysmon

Conversation

@w0rk3r
Copy link
Copy Markdown
Contributor

@w0rk3r w0rk3r commented Feb 4, 2022

Summary

Removes the event.action == "start" condition, so the rule will be compatible with sysmon.

Sysmon event.action for this kind of event is Process Create (rule: ProcessCreate)

image

@w0rk3r w0rk3r added Rule: Tuning tweaking or tuning an existing rule OS: Windows windows related rules Domain: Endpoint labels Feb 4, 2022
@w0rk3r w0rk3r self-assigned this Feb 4, 2022
@brokensound77 brokensound77 merged commit aa9fedd into main Feb 11, 2022
@brokensound77 brokensound77 deleted the vssadmin_sysmon branch February 11, 2022 17:15
protectionsmachine pushed a commit that referenced this pull request Feb 11, 2022
protectionsmachine pushed a commit that referenced this pull request Feb 11, 2022
protectionsmachine pushed a commit that referenced this pull request Feb 11, 2022
protectionsmachine pushed a commit that referenced this pull request Feb 11, 2022
protectionsmachine pushed a commit that referenced this pull request Feb 11, 2022
protectionsmachine pushed a commit that referenced this pull request Feb 11, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport: auto Domain: Endpoint OS: Windows windows related rules Rule: Tuning tweaking or tuning an existing rule

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants