Sysmon Channel Reference Deletion
Description
Potential threat actor tampering with Sysmon manifest and eventually disabling it
Query · sigma
selection1:
EventID: 4657
ObjectName|contains:
- WINEVT\Publishers\{5770385f-c22a-43e0-bf4c-06f5698ffbd9}
- WINEVT\Channels\Microsoft-Windows-Sysmon/Operational
ObjectValueName: Enabled
NewValue: 0
selection2:
EventID: 4663
ObjectName|contains:
- WINEVT\Publishers\{5770385f-c22a-43e0-bf4c-06f5698ffbd9}
- WINEVT\Channels\Microsoft-Windows-Sysmon/Operational
AccessMask: '0x10000'
condition: 1 of selection*
Known false positives
- Unknown