Skip to content

Instantly share code, notes, and snippets.

@Cyb3rWard0g
Last active June 19, 2019 14:54
Show Gist options
  • Star 1 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save Cyb3rWard0g/6f69475a667ef298d829370bd26ba8c2 to your computer and use it in GitHub Desktop.
Save Cyb3rWard0g/6f69475a667ef298d829370bd26ba8c2 to your computer and use it in GitHub Desktop.
<Sysmon schemaversion="4.1">
<!-- Capture all hashes -->
<HashAlgorithms>*</HashAlgorithms>
<EventFiltering>
<!-- Event ID 1 == Process Creation. -->
<ProcessCreate onmatch="include">
<Image name="Calculator Rule" condition="end with">Calculator.exe</Image>
</ProcessCreate>
</EventFiltering>
</Sysmon>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment