{"id":729,"date":"2021-07-31T09:25:09","date_gmt":"2021-07-31T14:25:09","guid":{"rendered":"https:\/\/www.searchevolution.com\/security\/?p=729"},"modified":"2022-04-27T07:44:34","modified_gmt":"2022-04-27T12:44:34","slug":"sysmon","status":"publish","type":"post","link":"https:\/\/www.searchevolution.com\/security\/2021\/07\/31\/sysmon\/","title":{"rendered":"Sysmon"},"content":{"rendered":"<p>L&#8217;utilitaire sysmon qui fait partie de sysinternals est un driver qui permet de monitorer un syst\u00e8me. Cela permet d&#8217;avoir une vue d\u00e9taill\u00e9e des \u00e9v\u00e9nements critiques qui se produisent lors d&#8217;intrusions dans une machine : cr\u00e9ation de processus, connexions r\u00e9seau et changement \u00e0 la date de cr\u00e9ation de certains fichiers. L&#8217;analyse de ces \u00e9vements avec le Event Viewer ou votre syst\u00e8me SIEM (splunk, elasticsearch, alien vault ou autres) permet de rep\u00e9rer les activit\u00e9s anormales.<\/p>\n<p>Les \u00e9v\u00e9nements de Sysmon sont enregistr\u00e9s dans <em>Applications and Services Logs\/Microsoft\/Windows\/Sysmon\/Operational<\/em><\/p>\n<p>Sysmon requiert un fichier de configuration. Je recommande le t\u00e9l\u00e9chargement de celui-ci :<br \/>\nhttps:\/\/github.com\/SwiftOnSecurity\/sysmon-config<\/p>\n<p>Ce fichier permet d&#8217;inclure ou d&#8217;exclure certains \u00e9v\u00e9nements bas\u00e9s sur des conditions. Voici une liste d\u00e9v\u00e9nements pouvant \u00eatre param\u00e9tr\u00e9s<\/p>\n<ul>\nCr\u00e9ation de processus (event ID 1)<br \/>\nDate de cr\u00e9ation de fichiers chang\u00e9s pour une date ant\u00e9rieure (event ID 2)<br \/>\nNouvelle connexion r\u00e9seau (event ID 3)<br \/>\nNouveau driver utilis\u00e9 par le noyau du syst\u00e8me d&#8217;exploitation (event ID 6)<br \/>\nDLL charg\u00e9 par un processus (ImageLoad) (event ID 7)<br \/>\nProcessus qui injecte du code dans d&#8217;autres processus (CreateRemoteThread) (event ID 8)<br \/>\nAcc\u00e8s direct \u00e0 un volume (RawAccessRead) (event ID 9)<br \/>\nINTER-PROCESS-ACCESS (ProcessAccess) (event ID 10)<br \/>\nFichiers cr\u00e9\u00e9s (event ID 11)<br \/>\nModification du registre (event ID 12,13,14)<br \/>\nData Streams cr\u00e9\u00e9 s(voir l&#8217;utilitaire streams) (event ID 15)<br \/>\nChangement de configuration de sysmon (event ID 16)<br \/>\nMonitoring des \u00e9v\u00e9nements WMI (event ID 19,20,21)<br \/>\nRequ\u00eates DNS (event ID 22)<br \/>\nEffacement de fichiers (event ID 23)\n<\/ul>\n<p>D\u00e9marrer sysmon (comme administrateur)<br \/>\n<code>Sysmon.exe -accepteula -i sysmonconfig-export.xml<\/code><\/p>\n<p>Get-WinEvent -Path <Path to Log> -FilterXPath &#8216;*\/System\/EventID=3 and *\/EventData\/Data[@Name=&#8221;DestinationPort&#8221;] and *\/EventData\/Data=4444&#8217; #fichier de logs export\u00e9s au format .evtx. Regarde pour les connexions r\u00e9seau en provenance du port 4444<br \/>\nGet-WinEvent -Path C:\\users\\germa\\Downloads\\Filtering.evtx -FilterXPath &#8216;*\/System\/EventID=3&#8217; -Oldest  -MaxEvents 10<br \/>\nGet-WinEvent -Path <Path to Log> -FilterXPath &#8216;*\/System\/EventID=10 and *\/EventData\/Data[@Name=&#8221;TargetImage&#8221;] and *\/EventData\/Data=&#8221;C:\\Windows\\system32\\lsass.exe&#8221;&#8216; | fl -property * #d\u00e9tection de mimikatz<\/p>\n","protected":false},"excerpt":{"rendered":"<p>L&#8217;utilitaire sysmon qui fait partie de sysinternals est un driver qui permet de monitorer un syst\u00e8me. Cela permet d&#8217;avoir une vue d\u00e9taill\u00e9e des \u00e9v\u00e9nements critiques qui se produisent lors d&#8217;intrusions dans une machine : cr\u00e9ation de processus, connexions r\u00e9seau et changement \u00e0 la date de cr\u00e9ation de certains fichiers. L&#8217;analyse de ces \u00e9vements avec le Event Viewer ou votre syst\u00e8me SIEM (splunk, elasticsearch, alien vault ou autres) permet de rep\u00e9rer les activit\u00e9s anormales. Les \u00e9v\u00e9nements de Sysmon sont enregistr\u00e9s dans Applications and Services Logs\/Microsoft\/Windows\/Sysmon\/Operational Sysmon requiert un fichier de configuration. Je recommande le t\u00e9l\u00e9chargement de celui-ci : https:\/\/github.com\/SwiftOnSecurity\/sysmon-config Ce fichier <\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[33,17],"tags":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v20.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Sysmon - S\u00e9curiser votre site<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.searchevolution.com\/security\/2021\/07\/31\/sysmon\/\" \/>\n<meta property=\"og:locale\" content=\"fr_CA\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Sysmon - S\u00e9curiser votre site\" \/>\n<meta property=\"og:description\" content=\"L&#8217;utilitaire sysmon qui fait partie de sysinternals est un driver qui permet de monitorer un syst\u00e8me. Cela permet d&#8217;avoir une vue d\u00e9taill\u00e9e des \u00e9v\u00e9nements critiques qui se produisent lors d&#8217;intrusions dans une machine : cr\u00e9ation de processus, connexions r\u00e9seau et changement \u00e0 la date de cr\u00e9ation de certains fichiers. L&#8217;analyse de ces \u00e9vements avec le Event Viewer ou votre syst\u00e8me SIEM (splunk, elasticsearch, alien vault ou autres) permet de rep\u00e9rer les activit\u00e9s anormales. Les \u00e9v\u00e9nements de Sysmon sont enregistr\u00e9s dans Applications and Services Logs\/Microsoft\/Windows\/Sysmon\/Operational Sysmon requiert un fichier de configuration. Je recommande le t\u00e9l\u00e9chargement de celui-ci : https:\/\/github.com\/SwiftOnSecurity\/sysmon-config Ce fichier\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.searchevolution.com\/security\/2021\/07\/31\/sysmon\/\" \/>\n<meta property=\"og:site_name\" content=\"S\u00e9curiser votre site\" \/>\n<meta property=\"article:published_time\" content=\"2021-07-31T14:25:09+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-04-27T12:44:34+00:00\" \/>\n<meta name=\"author\" content=\"Germain\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u00c9crit par\" \/>\n\t<meta name=\"twitter:data1\" content=\"Germain\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimation du temps de lecture\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.searchevolution.com\/security\/2021\/07\/31\/sysmon\/\",\"url\":\"https:\/\/www.searchevolution.com\/security\/2021\/07\/31\/sysmon\/\",\"name\":\"Sysmon - S\u00e9curiser votre site\",\"isPartOf\":{\"@id\":\"https:\/\/www.searchevolution.com\/security\/#website\"},\"datePublished\":\"2021-07-31T14:25:09+00:00\",\"dateModified\":\"2022-04-27T12:44:34+00:00\",\"author\":{\"@id\":\"https:\/\/www.searchevolution.com\/security\/#\/schema\/person\/e1318e0782dc5a7d6b03471347f881d8\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.searchevolution.com\/security\/2021\/07\/31\/sysmon\/#breadcrumb\"},\"inLanguage\":\"fr-CA\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.searchevolution.com\/security\/2021\/07\/31\/sysmon\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.searchevolution.com\/security\/2021\/07\/31\/sysmon\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\/\/www.searchevolution.com\/security\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Sysmon\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.searchevolution.com\/security\/#website\",\"url\":\"https:\/\/www.searchevolution.com\/security\/\",\"name\":\"S\u00e9curiser votre site\",\"description\":\"Conna\u00eetre son ennemi\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.searchevolution.com\/security\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"fr-CA\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.searchevolution.com\/security\/#\/schema\/person\/e1318e0782dc5a7d6b03471347f881d8\",\"name\":\"Germain\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-CA\",\"@id\":\"https:\/\/www.searchevolution.com\/security\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/6a203854efbec130dd49471ccbba1abc?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/6a203854efbec130dd49471ccbba1abc?s=96&d=mm&r=g\",\"caption\":\"Germain\"},\"sameAs\":[\"https:\/\/www.searchevolution.com\/security\"],\"url\":\"https:\/\/www.searchevolution.com\/security\/author\/germain\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Sysmon - S\u00e9curiser votre site","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.searchevolution.com\/security\/2021\/07\/31\/sysmon\/","og_locale":"fr_CA","og_type":"article","og_title":"Sysmon - S\u00e9curiser votre site","og_description":"L&#8217;utilitaire sysmon qui fait partie de sysinternals est un driver qui permet de monitorer un syst\u00e8me. Cela permet d&#8217;avoir une vue d\u00e9taill\u00e9e des \u00e9v\u00e9nements critiques qui se produisent lors d&#8217;intrusions dans une machine : cr\u00e9ation de processus, connexions r\u00e9seau et changement \u00e0 la date de cr\u00e9ation de certains fichiers. L&#8217;analyse de ces \u00e9vements avec le Event Viewer ou votre syst\u00e8me SIEM (splunk, elasticsearch, alien vault ou autres) permet de rep\u00e9rer les activit\u00e9s anormales. Les \u00e9v\u00e9nements de Sysmon sont enregistr\u00e9s dans Applications and Services Logs\/Microsoft\/Windows\/Sysmon\/Operational Sysmon requiert un fichier de configuration. Je recommande le t\u00e9l\u00e9chargement de celui-ci : https:\/\/github.com\/SwiftOnSecurity\/sysmon-config Ce fichier","og_url":"https:\/\/www.searchevolution.com\/security\/2021\/07\/31\/sysmon\/","og_site_name":"S\u00e9curiser votre site","article_published_time":"2021-07-31T14:25:09+00:00","article_modified_time":"2022-04-27T12:44:34+00:00","author":"Germain","twitter_card":"summary_large_image","twitter_misc":{"\u00c9crit par":"Germain","Estimation du temps de lecture":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.searchevolution.com\/security\/2021\/07\/31\/sysmon\/","url":"https:\/\/www.searchevolution.com\/security\/2021\/07\/31\/sysmon\/","name":"Sysmon - S\u00e9curiser votre site","isPartOf":{"@id":"https:\/\/www.searchevolution.com\/security\/#website"},"datePublished":"2021-07-31T14:25:09+00:00","dateModified":"2022-04-27T12:44:34+00:00","author":{"@id":"https:\/\/www.searchevolution.com\/security\/#\/schema\/person\/e1318e0782dc5a7d6b03471347f881d8"},"breadcrumb":{"@id":"https:\/\/www.searchevolution.com\/security\/2021\/07\/31\/sysmon\/#breadcrumb"},"inLanguage":"fr-CA","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.searchevolution.com\/security\/2021\/07\/31\/sysmon\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.searchevolution.com\/security\/2021\/07\/31\/sysmon\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/www.searchevolution.com\/security\/"},{"@type":"ListItem","position":2,"name":"Sysmon"}]},{"@type":"WebSite","@id":"https:\/\/www.searchevolution.com\/security\/#website","url":"https:\/\/www.searchevolution.com\/security\/","name":"S\u00e9curiser votre site","description":"Conna\u00eetre son ennemi","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.searchevolution.com\/security\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"fr-CA"},{"@type":"Person","@id":"https:\/\/www.searchevolution.com\/security\/#\/schema\/person\/e1318e0782dc5a7d6b03471347f881d8","name":"Germain","image":{"@type":"ImageObject","inLanguage":"fr-CA","@id":"https:\/\/www.searchevolution.com\/security\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/6a203854efbec130dd49471ccbba1abc?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/6a203854efbec130dd49471ccbba1abc?s=96&d=mm&r=g","caption":"Germain"},"sameAs":["https:\/\/www.searchevolution.com\/security"],"url":"https:\/\/www.searchevolution.com\/security\/author\/germain\/"}]}},"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/www.searchevolution.com\/security\/wp-json\/wp\/v2\/posts\/729"}],"collection":[{"href":"https:\/\/www.searchevolution.com\/security\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.searchevolution.com\/security\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.searchevolution.com\/security\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.searchevolution.com\/security\/wp-json\/wp\/v2\/comments?post=729"}],"version-history":[{"count":2,"href":"https:\/\/www.searchevolution.com\/security\/wp-json\/wp\/v2\/posts\/729\/revisions"}],"predecessor-version":[{"id":731,"href":"https:\/\/www.searchevolution.com\/security\/wp-json\/wp\/v2\/posts\/729\/revisions\/731"}],"wp:attachment":[{"href":"https:\/\/www.searchevolution.com\/security\/wp-json\/wp\/v2\/media?parent=729"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.searchevolution.com\/security\/wp-json\/wp\/v2\/categories?post=729"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.searchevolution.com\/security\/wp-json\/wp\/v2\/tags?post=729"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}