This commit is contained in:
99
deploy/rules/windows-account-admin.json
Normal file
99
deploy/rules/windows-account-admin.json
Normal file
@@ -0,0 +1,99 @@
|
||||
{
|
||||
"id": "windows-account-admin",
|
||||
"name": "Windows Account & Privilege Management",
|
||||
"description": "Konten, Gruppen und privilegierte Änderungen.",
|
||||
"version": 1,
|
||||
"enabled": true,
|
||||
"rules": [
|
||||
{
|
||||
"id": "win-privileged-group-change",
|
||||
"title": "Privilegierte Gruppenmitgliedschaft geändert",
|
||||
"description": "Mitglied zu privilegierter lokaler, globaler oder universeller Gruppe hinzugefügt.",
|
||||
"severity": "critical",
|
||||
"score": 9.2,
|
||||
"enabled": true,
|
||||
"kind": "event",
|
||||
"channels": ["Security"],
|
||||
"event_codes": [4728, 4732, 4756],
|
||||
"group_by": ["host", "user", "workstation"],
|
||||
"threshold": 1,
|
||||
"window_seconds": 300,
|
||||
"suppress_seconds": 900,
|
||||
"summary": "Privilegierte Gruppenmitgliedschaft geändert: {user} auf {host}",
|
||||
"tags": ["windows", "privilege", "account-management"],
|
||||
"mitre": ["T1098"]
|
||||
},
|
||||
{
|
||||
"id": "win-user-created",
|
||||
"title": "Benutzerkonto erstellt",
|
||||
"description": "Windows Security Event 4720.",
|
||||
"severity": "medium",
|
||||
"score": 6.0,
|
||||
"enabled": true,
|
||||
"kind": "event",
|
||||
"channels": ["Security"],
|
||||
"event_codes": [4720],
|
||||
"group_by": ["host", "user"],
|
||||
"threshold": 1,
|
||||
"window_seconds": 300,
|
||||
"suppress_seconds": 900,
|
||||
"summary": "Benutzerkonto {user} auf {host} erstellt",
|
||||
"tags": ["windows", "account-management"],
|
||||
"mitre": ["T1136.001"]
|
||||
},
|
||||
{
|
||||
"id": "win-user-enabled",
|
||||
"title": "Benutzerkonto aktiviert",
|
||||
"description": "Windows Security Event 4722.",
|
||||
"severity": "medium",
|
||||
"score": 5.5,
|
||||
"enabled": true,
|
||||
"kind": "event",
|
||||
"channels": ["Security"],
|
||||
"event_codes": [4722],
|
||||
"group_by": ["host", "user"],
|
||||
"threshold": 1,
|
||||
"window_seconds": 300,
|
||||
"suppress_seconds": 900,
|
||||
"summary": "Benutzerkonto {user} auf {host} aktiviert",
|
||||
"tags": ["windows", "account-management"],
|
||||
"mitre": []
|
||||
},
|
||||
{
|
||||
"id": "win-password-reset",
|
||||
"title": "Passwort eines Kontos zurückgesetzt",
|
||||
"description": "Windows Security Event 4724.",
|
||||
"severity": "medium",
|
||||
"score": 6.2,
|
||||
"enabled": true,
|
||||
"kind": "event",
|
||||
"channels": ["Security"],
|
||||
"event_codes": [4724],
|
||||
"group_by": ["host", "user"],
|
||||
"threshold": 1,
|
||||
"window_seconds": 300,
|
||||
"suppress_seconds": 900,
|
||||
"summary": "Passwort für {user} auf {host} zurückgesetzt",
|
||||
"tags": ["windows", "account-management", "credential"],
|
||||
"mitre": ["T1098"]
|
||||
},
|
||||
{
|
||||
"id": "win-user-deleted",
|
||||
"title": "Benutzerkonto gelöscht",
|
||||
"description": "Windows Security Event 4726.",
|
||||
"severity": "medium",
|
||||
"score": 5.8,
|
||||
"enabled": true,
|
||||
"kind": "event",
|
||||
"channels": ["Security"],
|
||||
"event_codes": [4726],
|
||||
"group_by": ["host", "user"],
|
||||
"threshold": 1,
|
||||
"window_seconds": 300,
|
||||
"suppress_seconds": 900,
|
||||
"summary": "Benutzerkonto {user} auf {host} gelöscht",
|
||||
"tags": ["windows", "account-management"],
|
||||
"mitre": []
|
||||
}
|
||||
]
|
||||
}
|
||||
102
deploy/rules/windows-authentication.json
Normal file
102
deploy/rules/windows-authentication.json
Normal file
@@ -0,0 +1,102 @@
|
||||
{
|
||||
"id": "windows-authentication",
|
||||
"name": "Windows Authentication",
|
||||
"description": "Anmelde-, Lockout-, Spray- und Kerberos/NTLM-Erkennungen.",
|
||||
"version": 1,
|
||||
"enabled": true,
|
||||
"rules": [
|
||||
{
|
||||
"id": "win-account-lockout",
|
||||
"title": "Account Lockout",
|
||||
"description": "Windows Security Event 4740.",
|
||||
"severity": "medium",
|
||||
"score": 5.5,
|
||||
"enabled": true,
|
||||
"kind": "event",
|
||||
"channels": ["Security"],
|
||||
"event_codes": [4740],
|
||||
"group_by": ["host", "user", "workstation"],
|
||||
"threshold": 1,
|
||||
"window_seconds": 600,
|
||||
"suppress_seconds": 900,
|
||||
"summary": "Account-Lockout: {user}; Caller {workstation}; DC/Host {host} ({count}×)",
|
||||
"tags": ["windows", "authentication", "lockout"],
|
||||
"mitre": []
|
||||
},
|
||||
{
|
||||
"id": "win-failed-logon-burst",
|
||||
"title": "Viele fehlgeschlagene Anmeldungen",
|
||||
"description": "Mindestens 20 Event-4625-Ereignisse für denselben Kontext in fünf Minuten.",
|
||||
"severity": "high",
|
||||
"score": 7.5,
|
||||
"enabled": true,
|
||||
"kind": "threshold",
|
||||
"channels": ["Security"],
|
||||
"event_codes": [4625],
|
||||
"group_by": ["host", "user", "source_ip"],
|
||||
"threshold": 20,
|
||||
"window_seconds": 300,
|
||||
"suppress_seconds": 900,
|
||||
"summary": "{count} fehlgeschlagene Logons für {user} auf {host} von {source_ip}",
|
||||
"tags": ["windows", "authentication", "brute-force"],
|
||||
"mitre": ["T1110"]
|
||||
},
|
||||
{
|
||||
"id": "win-password-spray",
|
||||
"title": "Password Spray",
|
||||
"description": "Eine Source-IP versucht viele unterschiedliche Konten anzumelden.",
|
||||
"severity": "high",
|
||||
"score": 8.5,
|
||||
"enabled": true,
|
||||
"kind": "distinct",
|
||||
"channels": ["Security"],
|
||||
"event_codes": [4625],
|
||||
"conditions": [{"field": "source_ip", "operator": "exists"}, {"field": "target_user", "operator": "exists"}],
|
||||
"group_by": ["source_ip"],
|
||||
"threshold": 20,
|
||||
"distinct_field": "target_user",
|
||||
"distinct_threshold": 10,
|
||||
"window_seconds": 600,
|
||||
"suppress_seconds": 1800,
|
||||
"summary": "Password-Spray von {source_ip}: {count} Versuche gegen {distinct} Benutzer",
|
||||
"tags": ["windows", "authentication", "password-spray"],
|
||||
"mitre": ["T1110.003"]
|
||||
},
|
||||
{
|
||||
"id": "win-kerberos-preauth-burst",
|
||||
"title": "Kerberos Pre-Auth Fehler-Burst",
|
||||
"description": "Viele Event-4771-Ereignisse für denselben Benutzer oder Quellkontext.",
|
||||
"severity": "high",
|
||||
"score": 7.4,
|
||||
"enabled": true,
|
||||
"kind": "threshold",
|
||||
"channels": ["Security"],
|
||||
"event_codes": [4771],
|
||||
"group_by": ["host", "user", "source_ip"],
|
||||
"threshold": 15,
|
||||
"window_seconds": 300,
|
||||
"suppress_seconds": 900,
|
||||
"summary": "{count} Kerberos Pre-Auth Fehler für {user} auf {host} von {source_ip}",
|
||||
"tags": ["windows", "kerberos", "authentication"],
|
||||
"mitre": ["T1110"]
|
||||
},
|
||||
{
|
||||
"id": "win-ntlm-auth-failure-burst",
|
||||
"title": "NTLM Authentifizierungsfehler-Burst",
|
||||
"description": "Viele Event-4776-Ereignisse im kurzen Zeitraum.",
|
||||
"severity": "high",
|
||||
"score": 7.2,
|
||||
"enabled": true,
|
||||
"kind": "threshold",
|
||||
"channels": ["Security"],
|
||||
"event_codes": [4776],
|
||||
"group_by": ["host", "user", "workstation"],
|
||||
"threshold": 15,
|
||||
"window_seconds": 300,
|
||||
"suppress_seconds": 900,
|
||||
"summary": "{count} NTLM-Authentifizierungsfehler für {user} über {workstation}",
|
||||
"tags": ["windows", "ntlm", "authentication"],
|
||||
"mitre": ["T1110"]
|
||||
}
|
||||
]
|
||||
}
|
||||
98
deploy/rules/windows-core.json
Normal file
98
deploy/rules/windows-core.json
Normal file
@@ -0,0 +1,98 @@
|
||||
{
|
||||
"id": "windows-core",
|
||||
"name": "Windows Core Security",
|
||||
"description": "Hochwertige Windows-System- und Audit-Ereignisse mit geringer Grundlautstärke.",
|
||||
"version": 1,
|
||||
"enabled": true,
|
||||
"rules": [
|
||||
{
|
||||
"id": "win-audit-log-cleared",
|
||||
"title": "Security Audit Log gelöscht",
|
||||
"description": "Windows Security Event 1102.",
|
||||
"severity": "critical",
|
||||
"score": 9.8,
|
||||
"enabled": true,
|
||||
"kind": "event",
|
||||
"channels": ["Security"],
|
||||
"event_codes": [1102],
|
||||
"group_by": ["host"],
|
||||
"threshold": 1,
|
||||
"window_seconds": 300,
|
||||
"suppress_seconds": 900,
|
||||
"summary": "Security Audit Log auf {host} wurde gelöscht",
|
||||
"tags": ["windows", "audit", "defense-evasion"],
|
||||
"mitre": ["T1070.001"]
|
||||
},
|
||||
{
|
||||
"id": "win-service-installed",
|
||||
"title": "Neuer Windows-Dienst installiert",
|
||||
"description": "Service Control Manager Event 7045.",
|
||||
"severity": "high",
|
||||
"score": 8.0,
|
||||
"enabled": true,
|
||||
"kind": "event",
|
||||
"event_codes": [7045],
|
||||
"group_by": ["host", "process_path"],
|
||||
"threshold": 1,
|
||||
"window_seconds": 300,
|
||||
"suppress_seconds": 900,
|
||||
"summary": "Neuer Dienst auf {host} installiert: {process}",
|
||||
"tags": ["windows", "persistence", "service"],
|
||||
"mitre": ["T1543.003"]
|
||||
},
|
||||
{
|
||||
"id": "win-scheduled-task-created",
|
||||
"title": "Scheduled Task erstellt",
|
||||
"description": "Windows Security Event 4698.",
|
||||
"severity": "high",
|
||||
"score": 7.8,
|
||||
"enabled": true,
|
||||
"kind": "event",
|
||||
"channels": ["Security"],
|
||||
"event_codes": [4698],
|
||||
"group_by": ["host", "user"],
|
||||
"threshold": 1,
|
||||
"window_seconds": 300,
|
||||
"suppress_seconds": 900,
|
||||
"summary": "Scheduled Task auf {host} durch {user} erstellt",
|
||||
"tags": ["windows", "persistence", "scheduled-task"],
|
||||
"mitre": ["T1053.005"]
|
||||
},
|
||||
{
|
||||
"id": "win-audit-policy-changed",
|
||||
"title": "Audit Policy geändert",
|
||||
"description": "Windows Security Event 4719.",
|
||||
"severity": "high",
|
||||
"score": 8.2,
|
||||
"enabled": true,
|
||||
"kind": "event",
|
||||
"channels": ["Security"],
|
||||
"event_codes": [4719],
|
||||
"group_by": ["host", "user"],
|
||||
"threshold": 1,
|
||||
"window_seconds": 300,
|
||||
"suppress_seconds": 900,
|
||||
"summary": "Audit Policy auf {host} durch {user} geändert",
|
||||
"tags": ["windows", "audit", "policy"],
|
||||
"mitre": ["T1562.002"]
|
||||
},
|
||||
{
|
||||
"id": "win-firewall-rule-change",
|
||||
"title": "Windows Firewall-Regel geändert",
|
||||
"description": "Firewall-Regeln hinzugefügt, geändert oder gelöscht.",
|
||||
"severity": "medium",
|
||||
"score": 5.5,
|
||||
"enabled": true,
|
||||
"kind": "threshold",
|
||||
"channels": ["Security"],
|
||||
"event_codes": [4946, 4947, 4948],
|
||||
"group_by": ["host", "user"],
|
||||
"threshold": 1,
|
||||
"window_seconds": 300,
|
||||
"suppress_seconds": 900,
|
||||
"summary": "Windows Firewall-Regel auf {host} geändert ({count} Ereignisse)",
|
||||
"tags": ["windows", "firewall", "configuration"],
|
||||
"mitre": ["T1562.004"]
|
||||
}
|
||||
]
|
||||
}
|
||||
81
deploy/rules/windows-defender-powershell.json
Normal file
81
deploy/rules/windows-defender-powershell.json
Normal file
@@ -0,0 +1,81 @@
|
||||
{
|
||||
"id": "windows-defender-powershell",
|
||||
"name": "Windows Defender & PowerShell",
|
||||
"description": "Malware-, Defender- und auffällige PowerShell-Signale.",
|
||||
"version": 1,
|
||||
"enabled": true,
|
||||
"rules": [
|
||||
{
|
||||
"id": "defender-malware-detected",
|
||||
"title": "Microsoft Defender Malware erkannt",
|
||||
"description": "Defender Operational Event 1116.",
|
||||
"severity": "high",
|
||||
"score": 8.8,
|
||||
"enabled": true,
|
||||
"kind": "event",
|
||||
"event_codes": [1116],
|
||||
"conditions": [{"field": "provider", "operator": "contains", "value": "Defender"}],
|
||||
"group_by": ["host"],
|
||||
"threshold": 1,
|
||||
"window_seconds": 300,
|
||||
"suppress_seconds": 1800,
|
||||
"summary": "Microsoft Defender meldet Malware auf {host}",
|
||||
"tags": ["windows", "defender", "malware"],
|
||||
"mitre": []
|
||||
},
|
||||
{
|
||||
"id": "defender-realtime-protection-disabled",
|
||||
"title": "Defender Echtzeitschutz deaktiviert",
|
||||
"description": "Defender Operational Event 5001.",
|
||||
"severity": "critical",
|
||||
"score": 9.0,
|
||||
"enabled": true,
|
||||
"kind": "event",
|
||||
"event_codes": [5001],
|
||||
"conditions": [{"field": "provider", "operator": "contains", "value": "Defender"}],
|
||||
"group_by": ["host"],
|
||||
"threshold": 1,
|
||||
"window_seconds": 300,
|
||||
"suppress_seconds": 1800,
|
||||
"summary": "Microsoft Defender Echtzeitschutz auf {host} deaktiviert",
|
||||
"tags": ["windows", "defender", "defense-evasion"],
|
||||
"mitre": ["T1562.001"]
|
||||
},
|
||||
{
|
||||
"id": "powershell-encoded-command",
|
||||
"title": "PowerShell EncodedCommand",
|
||||
"description": "PowerShell-Nachricht oder Kommandozeile enthält EncodedCommand.",
|
||||
"severity": "high",
|
||||
"score": 8.0,
|
||||
"enabled": true,
|
||||
"kind": "event",
|
||||
"event_codes": [4104, 4688],
|
||||
"conditions": [{"field": "message", "operator": "contains", "value": "EncodedCommand"}],
|
||||
"group_by": ["host", "user"],
|
||||
"threshold": 1,
|
||||
"window_seconds": 300,
|
||||
"suppress_seconds": 900,
|
||||
"summary": "PowerShell EncodedCommand auf {host} durch {user}",
|
||||
"tags": ["windows", "powershell", "execution"],
|
||||
"mitre": ["T1059.001", "T1027"]
|
||||
},
|
||||
{
|
||||
"id": "powershell-download-cradle",
|
||||
"title": "PowerShell Download-/Execution-Muster",
|
||||
"description": "PowerShell ScriptBlock enthält typische Download- oder In-Memory-Execution-Muster.",
|
||||
"severity": "high",
|
||||
"score": 8.4,
|
||||
"enabled": true,
|
||||
"kind": "event",
|
||||
"event_codes": [4104],
|
||||
"conditions": [{"field": "message", "operator": "regex", "value": "(?i)(DownloadString|DownloadFile|Invoke-WebRequest|FromBase64String|IEX\\s*\\()"}],
|
||||
"group_by": ["host", "user"],
|
||||
"threshold": 1,
|
||||
"window_seconds": 300,
|
||||
"suppress_seconds": 900,
|
||||
"summary": "Auffälliges PowerShell Download-/Execution-Muster auf {host} durch {user}",
|
||||
"tags": ["windows", "powershell", "execution"],
|
||||
"mitre": ["T1059.001", "T1105"]
|
||||
}
|
||||
]
|
||||
}
|
||||
Reference in New Issue
Block a user