You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I am using the latest version of Sysmon along with olafhartong's sysmonconfig.xml configuration https://github.com/olafhartong/sysmon-modula. Wazuh rules 102101-MITER_TECHNIQUES_FROM_SYSMON_EVENT3.xml are also installed on the server.
In the Event Viewer, I see the logs I need when establishing connections to remote computers.
For example, there are two logs (both have RuleName: technique_id=T1021,technique_name=Remote Services): when establishing a connection through the TOTALCMD.EXE and RDCMan.exe processes, respectively.
Wazuh only accepts logs from TOTALCMD.EXE for some reason. I can't figure out what's wrong. Are there any suggestions that it might be wrong with your rules?
Greetings!
I am using the latest version of Sysmon along with olafhartong's sysmonconfig.xml configuration https://github.com/olafhartong/sysmon-modula. Wazuh rules 102101-MITER_TECHNIQUES_FROM_SYSMON_EVENT3.xml are also installed on the server.
In the Event Viewer, I see the logs I need when establishing connections to remote computers.
For example, there are two logs (both have RuleName: technique_id=T1021,technique_name=Remote Services): when establishing a connection through the TOTALCMD.EXE and RDCMan.exe processes, respectively.
Wazuh only accepts logs from TOTALCMD.EXE for some reason. I can't figure out what's wrong. Are there any suggestions that it might be wrong with your rules?
The text was updated successfully, but these errors were encountered: