Skip to content
This repository has been archived by the owner on Apr 19, 2021. It is now read-only.

Sysmon RemoteThread ELSA parsers #10

Merged
merged 7 commits into from
Jul 29, 2016
Merged

Sysmon RemoteThread ELSA parsers #10

merged 7 commits into from
Jul 29, 2016

Conversation

strengthnotes
Copy link
Contributor

Doug what are your thoughts on included Sysmon remote thread ELSA parser(s) in a future update ? I have been testing the updated version for about a week need a little more testing but think they are close. These tend to fire when using tools that migrate processes i.e. meterpreter. I need to test but we might see the same behavior with malware in the wild.

@dougburks
Copy link
Contributor

Hi James,

This sounds like a great idea!

The next few weeks are going to be very busy for me, so this should give you plenty of time to test and make sure this is a solid solution before I merge.

Thanks!

@defensivedepth
Copy link
Contributor

@dougburks FYI, I have this running in PROD just fine....

@dougburks
Copy link
Contributor

Thanks @defensivedepth !

@strengthnotes
Copy link
Contributor Author

@defensivedepth just heads up after we talked a couple of weeks ago I went ahead and tweaked these again for 3.10. might need to modify your SQL just a bit. Let me know if you see any issues or have any problems.

@defensivedepth
Copy link
Contributor

@jtaylo78 This morning I tested this updated parser with 3.1 logs and all looks good.

Thanks!

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants