Skip to content

Instantly share code, notes, and snippets.

@oz9un
Created October 19, 2021 11:03
Show Gist options
  • Save oz9un/ebc1f3e5684d1f62227d075d64e0ba21 to your computer and use it in GitHub Desktop.
Save oz9un/ebc1f3e5684d1f62227d075d64e0ba21 to your computer and use it in GitHub Desktop.
[SysmonForLinux] Description Fields - NetworkConnection
<Sysmon schemaversion="4.70">
<EventFiltering>
<RuleGroup name="" groupRelation="or">
<ProcessCreate onmatch="include" />
</RuleGroup>
<RuleGroup name="" groupRelation="or">
<ProcessTerminate onmatch="include" />
</RuleGroup>
<RuleGroup name="" groupRelation="or">
<RawAccessRead onmatch="include" />
</RuleGroup>
<RuleGroup name="" groupRelation="or">
<ProcessAccess onmatch="include" />
</RuleGroup>
<RuleGroup name="" groupRelation="or">
<FileCreate onmatch="include" />
</RuleGroup>
<RuleGroup name="" groupRelation="or">
<FileDelete onmatch="include" />
</RuleGroup>
<RuleGroup name="autoCreated" groupRelation="or">
<NetworkConnect onmatch="include">
<RuleName condition="">value</RuleName>
<UtcTime condition="">value</UtcTime>
<ProcessGuid condition="">value</ProcessGuid>
<ProcessId condition="">value</ProcessId>
<Image condition="">value</Image>
<User condition="">value</User>
<Protocol condition="">value</Protocol>
<Initiated condition="">value</Initiated>
<SourceIsIpv6 condition="">value</SourceIsIpv6>
<SourceIp condition="">value</SourceIp>
<SourceHostname condition="">value</SourceHostname>
<SourcePort condition="">value</SourcePort>
<SourcePortName condition="">value</SourcePortName>
<DestinationIsIpv6 condition="">value</DestinationIsIpv6>
<DestinationIp condition="">value</DestinationIp>
<DestinationHostname condition="">value</DestinationHostname>
<DestinationPort condition="">value</DestinationPort>
<DestinationPortName condition="">value</DestinationPortName>
</NetworkConnect>
</RuleGroup>
</EventFiltering>
</Sysmon>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment