Skip to content

Latest commit

 

History

History
12 lines (10 loc) · 1.69 KB

r_m_unix_auditbeat_Audit_Tampering.md

File metadata and controls

12 lines (10 loc) · 1.69 KB

Vendor: Unix

Product: Auditbeat

Use-Case: Audit Tampering

Rules Models MITRE ATT&CK® TTPs Event Types Parsers
7 0 6 1 1
Event Type Rules Models
process-created T1562.006 - T1562.006
A-ETW-Trace-Disable: Event tracing has been disabled, possible logging evasion on this asset
ETW-Trace-Disable: Event tracing has been disabled, possible logging evasion
Sysmon-Driver-Unload: Possible Sysmon driver unloaded.

T1059 - Command and Scripting Interperter
A-ETW-Trace-Disable: Event tracing has been disabled, possible logging evasion on this asset
ETW-Trace-Disable: Event tracing has been disabled, possible logging evasion

T1070 - Indicator Removal on Host
A-ETW-Trace-Disable: Event tracing has been disabled, possible logging evasion on this asset
ETW-Trace-Disable: Event tracing has been disabled, possible logging evasion

T1070.001 - Indicator Removal on Host: Clear Windows Event Logs
A-EventLog-Tamper: EventLog has been tampered with on this asset
EventLog-Tamper: EventLog has been tampered with

T1546.003 - T1546.003
A-WMI-Script-Event-Consumers: Suspicious usage of WMI script event consumers on this asset.

T1562 - Impair Defenses
A-Sysmon-Driver-Unload: Possible Sysmon driver unloaded on this asset.