Exclude Sysmon 10 noise: svchost.exe → taskhostw.exe (task host inspections).
Description
Exclude Sysmon 10 noise: svchost.exe → taskhostw.exe (task host inspections).
Query · wazuh
field win.eventdata.sourceImage="(?i)^C:\\\\WINDOWS\\\\system32\\\\svchost\.exe$" AND field win.eventdata.targetImage="(?i)^C:\\\\WINDOWS\\\\system32\\\\taskhostw\.exe$"
No license declared
socfortress/Wazuh-Rules publishes no license, and without an express grant the default is all rights reserved. The query above is synthesized from the rule rather than copied out of it, so you can see what the rule matches on; the rule as written stays upstream.
Read the full rule at Exclusion Rules/900000-exclusion_rules.xml ↗. Why this rule is treated this way.
Rule dependencies
Depends on
-
composes · Wazuh if_group
sysmon_event_10- Sysmon - Event 10: ProcessAccess by · Credential Dumping (T1003)
- Sysmon - Event 10: ProcessAccess by · Dynamic-link Library Injection (T1055.001)
- Sysmon - Event 10: ProcessAccess by · Masquerading (T1036)
- Sysmon - Event 10: ProcessAccess by · PowerShell (T1059.001)
- Sysmon - Event 10: ProcessAccess by · Process Injection (T1055)
- Sysmon - Event 10: ProcessAccess by · Modify Registry (T1112)
- Sysmon - Event 10: ProcessAccess by · LSASS Memory (T1003.004)
- Sysmon - Event 10: ProcessAccess by · Scheduled Task (T1053)
- Sysmon - Event 10: ProcessAccess by · Regsvr32 (T1218.010)
- Sysmon - Event 10: ProcessAccess by · DLL Side-Loading (T1073)
- Sysmon - Event 10: ProcessAccess by · Windows Management Instrumentation (T1047)
- Sysmon - Event 10: ProcessAccess by · Office Application Startup (T1137)
- Sysmon - Event 10: ProcessAccess by · win.eventdata.sourceImage = acad.exe
- Sysmon - Event 10
- Sysmon - Event 10: process accessed by · win.system.eventID = 10