Home
%3CP%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%26nbsp%3B%3CRULE%20grouprelation%3D%22%26quot%3Band%26quot%3B%22%3E%3C%2FRULE%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%3CIMAGE%20condition%3D%22%26quot%3Bend%22%20with%3D%22%22%3Epowershell.exe%3C%2FIMAGE%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%3CPARENTIMAGE%20condition%3D%22%26quot%3Bend%22%20with%3D%22%22%3Ecmd.exe%3C%2FPARENTIMAGE%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%26nbsp%3B%20%3C%2FP%3E%0A%3CP%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ESysmon%20PowerUsers%20may%20have%20noticed%20the%20following%20line%20is%20unusual%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%26nbsp%3B%3CCOMMANDLINE%20condition%3D%22%26quot%3Bcontains%22%20all%3D%22%22%3Enet%3Bview%3C%2FCOMMANDLINE%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThis%20brings%20me%20to%20another%20change%20for%2010.4%20which%20introduces%20the%20%22contains%20any%22%20and%20%22contains%20all%22%20conditions%20that%20can%20be%20used%20for%20local%20(field%20level)%20OR%2FAND%20conditions%20respectively.%20These%20attempt%20to%20match%20a%20'%3B'%20separated%20list%20of%20fields%20so%20in%20this%20example%20a%20match%20will%20be%20made%20for%20%22net%20view%22%20but%20not%20%22net%20use%22.%20%22contains%20any%22%20is%20a%20similar%20condition%20but%20for%20%22OR'%20operations.%26nbsp%3B%20A%20rule%20for%20browsers%20for%20example%20might%20be%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%3CIMAGE%20condition%3D%22%26quot%3Bcontains%22%20any%3D%22%22%3Efirefox.exe%3Bchrome.exe%3Biexplore.exe%3C%2FIMAGE%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3CLINGO-SUB%20id%3D%22lingo-sub-840631%22%20slang%3D%22en-US%22%3ESysmon%2010.4%20Rule%20Enhancements%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-840631%22%20slang%3D%22en-US%22%3E%3CP%3EWhen%20we%20first%20released%20the%20RuleGroup%20feature%20described%20in%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FSysinternals-Blog%2FSysmon-The-rules-about-rules%2Fm-p%2F733649%23U733649%22%20target%3D%22_blank%22%3ESysmon%20-%20The%20rules%20about%20rules%3C%2FA%3Emany%20of%20you%20contacted%20us%20to%20see%20if%20we%20might%20consider%20extending%20the%20AND%2FOR%20combiner%20to%20individual%20rules%20rather%20than%20to%20all%20rules%20for%20an%20event%20type.%26nbsp%3B%20You%20asked%20and%20we%20listened%20and%20are%20pleased%20to%20announce%20that%20from%2010.4%20onwards%20this%20is%20now%20supported.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAs%20with%20RuleGroups%2C%20these%20are%20completely%20optional%20and%20your%20existing%20configuration%20files%20should%20continue%20to%20work%20as%20they%20do%20now.%20If%20you%20do%20want%20to%20take%20advantage%20of%20the%20new%20features%20though%20you%20will%20need%20to%20increment%20the%20schema%20version%20to%204.22%20and%20you'll%20be%20ready%20to%20go..%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThe%20basic%20building%20block%20is%20the%20new%20%3CRULE%3E%20element.%20As%20with%20%3CRULEGROUP%3E%20this%20can%20optionally%20have%20name%20and%20groupRelation%20attributes%20and%20like%20RuleGroup%20the%20default%20groupRelation%20is%20%22AND%22.%20An%20example%20schema%20is%20shown%20below%3C%2FRULEGROUP%3E%3C%2FRULE%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSYSMON%20schemaversion%3D%22%26quot%3B4.22%26quot%3B%22%3E%3C%2FSYSMON%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%20%26nbsp%3B%3CEVENTFILTERING%3E%3C%2FEVENTFILTERING%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%3CRULEGROUP%20name%3D%22%26quot%3Bgroup%22%201%3D%22%22%3E%3C%2FRULEGROUP%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%3CPROCESSCREATE%20onmatch%3D%22%26quot%3Binclude%26quot%3B%22%3E%3C%2FPROCESSCREATE%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%26nbsp%3B%3CCOMMANDLINE%20condition%3D%22%26quot%3Bcontains%26quot%3B%22%3Etimeout%3C%2FCOMMANDLINE%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%26nbsp%3B%3CCOMMANDLINE%20condition%3D%22%26quot%3Bcontains%22%20all%3D%22%22%3Enet%3Bview%3C%2FCOMMANDLINE%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%26nbsp%3B%3CRULE%20grouprelation%3D%22%26quot%3Band%26quot%3B%22%20name%3D%22%26quot%3Bpinging%22%20microsoft%3D%22%22%3E%3C%2FRULE%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%20%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%3CIMAGE%20condition%3D%22%26quot%3Bcontains%26quot%3B%22%3Eping%3C%2FIMAGE%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%20%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%3CCOMMANDLINE%20condition%3D%22%26quot%3Bcontains%26quot%3B%22%3Emicrosoft%3C%2FCOMMANDLINE%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CP%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%26nbsp%3B%3CRULE%20grouprelation%3D%22%26quot%3Band%26quot%3B%22%3E%3C%2FRULE%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%3CIMAGE%20condition%3D%22%26quot%3Bend%22%20with%3D%22%22%3Epowershell.exe%3C%2FIMAGE%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%3CPARENTIMAGE%20condition%3D%22%26quot%3Bend%22%20with%3D%22%22%3Ecmd.exe%3C%2FPARENTIMAGE%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%26nbsp%3B%20%3C%2FP%3E%0A%3CP%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ESysmon%20power%20users%20may%20have%20noticed%20something%20unusual%20with%20the%20following%20line%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%26nbsp%3B%3CCOMMANDLINE%20condition%3D%22%26quot%3Bcontains%22%20all%3D%22%22%3Enet%3Bview%3C%2FCOMMANDLINE%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThis%20brings%20me%20to%20another%20change%20for%2010.4%20which%20introduces%20the%20%22contains%20any%22%20and%20%22contains%20all%22%20conditions%20that%20can%20be%20used%20for%20local%20(field%20level)%20OR%2FAND%20conditions%20respectively.%20These%20attempt%20to%20match%20a%20'%3B'%20separated%20list%20of%20fields%20so%20in%20this%20example%20a%20match%20will%20be%20made%20for%20%22net%20view%22%20but%20not%20%22net%20use%22.%20%22contains%20any%22%20is%20a%20similar%20condition%20but%20for%20%22OR'%20operations.%26nbsp%3B%20A%20rule%20for%20browsers%20for%20example%20might%20be%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%3CIMAGE%20condition%3D%22%26quot%3Bcontains%22%20any%3D%22%22%3Efirefox.exe%3Bchrome.exe%3Biexplore.exe%3C%2FIMAGE%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EHappy%20hunting%20and%20as%20always%20if%20you%20have%20any%20questions%20or%20suggestions%2C%20please%20feel%20free%20to%20contact%20us%20at%20syssite%40microsoft.com%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-840631%22%20slang%3D%22en-US%22%3E%3CP%3EDo%20you%20think%20Sysmon%20rule%20filtering%20is%20too%20inflexibile%3F%20Were%20you%20excited%20about%20RuleGroups%20but%20wished%20they%20went%20further%3F%20If%20so%20you%20may%20be%20interested%20in%20some%20changes%20that%20we%20made%20in%20Sysmon%2010.4%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-LABS%20id%3D%22lingo-labs-840631%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ERules%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Esysmon%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Microsoft

When we first released the RuleGroup feature described in Sysmon - The rules about rules many of you contacted us to see if we might consider extending the AND/OR combiner to individual rules rather than to all rules for an event type.  You asked and we listened and are pleased to announce that from 10.4 onwards this is now supported.

 

As with RuleGroups, these are completely optional and your existing configuration files should continue to work as they do now. If you do want to take advantage of the new features though you will need to increment the schema version to 4.22 and you'll be ready to go..

 

The basic building block is the new <Rule> element. As with <RuleGroup> this can optionally have name and groupRelation attributes and like RuleGroup the default groupRelation is "AND". An example schema is shown below

 

<Sysmon schemaversion="4.22">

   <EventFiltering>

      <RuleGroup name="group 1" groupRelation="or">

          <ProcessCreate onmatch="include">

              <CommandLine condition="contains">timeout</CommandLine>

              <CommandLine condition="contains all">net;view</CommandLine>

              <Rule groupRelation="and" name="pinging microsoft">

                    <Image condition="contains">ping</Image>

                    <CommandLine condition="contains">microsoft</CommandLine>

              </Rule>

              <Rule groupRelation="and">

                   <Image condition="end with">powershell.exe</Image>

                   <ParentImage condition="end with">cmd.exe</ParentImage>

            </Rule>

        </ProcessCreate>

     </RuleGroup>

   </EventFiltering>

</Sysmon>

 

 

Sysmon power users may have noticed something unusual with the following line

 

        <CommandLine condition="contains all">net;view</CommandLine>

 

This brings me to another change for 10.4 which introduces the "contains any" and "contains all" conditions that can be used for local (field level) OR/AND conditions respectively. These attempt to match a ';' separated list of fields so in this example a match will be made for "net view" but not "net use". "contains any" is a similar condition but for "OR' operations.  A rule for browsers for example might be

 

        <Image condition="contains any">firefox.exe;chrome.exe;iexplore.exe</Image>

 

 

Happy hunting and as always if you have any questions or suggestions, please feel free to contact us at syssite@microsoft.com