Skip to content

Commit 32c11a6

Browse files
authored
Example of FileDeleteDetected
Example of FileDeleteDetected used in Youtube video
1 parent 593ff86 commit 32c11a6

1 file changed

Lines changed: 186 additions & 0 deletions

File tree

examples/FileDeleteDetected.xml

Lines changed: 186 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,186 @@
1+
<Sysmon schemaversion="4.60">
2+
<!-- Hashing algorithms that can be used are md5,sha1,sha256,imphash or * for all,
3+
more than once can be specified separated by using comas -->
4+
<HashAlgorithms>sha256</HashAlgorithms>
5+
<!-- Checking for signature revocation for drivers. -->
6+
<CheckRevocation/>
7+
<ArchiveDirectory>Archive</ArchiveDirectory>
8+
<EventFiltering>
9+
<RuleGroup name="" groupRelation="or">
10+
<FileDelete onmatch="include">
11+
<!-- User Writable Locations -->
12+
<Rule groupRelation="and">
13+
<TargetFilename condition="contains">\Appdata\Local\Microsoft\Windows\INetCache\Content.Outlook\</TargetFilename> <!--Microsoft Outlook Temp folder-->
14+
<TargetFilename condition="contains any">.com;.bat;.reg;.ps1;.vbs;.vba;.lnk;.doc;.xls;.hta;.bin;.7z;.xla;.cmd;.sh;.lnk;.pptm;.scr;.sct</TargetFilename>
15+
</Rule>
16+
<Rule groupRelation="and">
17+
<TargetFilename condition="contains">\Downloads\</TargetFilename> <!--User Download folder-->
18+
<TargetFilename condition="contains any">.com;.bat;.exe;.reg;.ps1;.vbs;.vba;.lnk;.doc;.xls;.hta;.bin;.dll;.xla;.cmd;.sh;.lnk;.pptm;.scr;.msi;.sct</TargetFilename>
19+
</Rule>
20+
<Rule groupRelation="and">
21+
<TargetFilename condition="contains">\Appdata\Local\Temp\</TargetFilename> <!--User Temp folder-->
22+
<TargetFilename condition="contains any">.com;.bat;.reg;.ps1;.vbs;.vba;.lnk;.doc;.xls;.hta;.bin;.xla;.cmd;.sh;.lnk;.pptm;.scr;.sct</TargetFilename>
23+
</Rule>
24+
<!-- System wide writable locations -->
25+
<Rule groupRelation="and">
26+
<TargetFilename condition="begin with">C:\ProgramData\Intel</TargetFilename>
27+
<TargetFilename condition="contains any">.com;.bat;.exe;.reg;.ps1;.vbs;.vba;.lnk;.doc;.xls;.hta;.bin;.7z;.dll;.xla;.cmd;.sh;.lnk;.pptm;.scr;.msi;.sct</TargetFilename>
28+
</Rule>
29+
<Rule groupRelation="and">
30+
<TargetFilename condition="begin with">C:\ProgramData\Mozilla</TargetFilename>
31+
<TargetFilename condition="contains any">.com;.bat;.exe;.reg;.ps1;.vbs;.vba;.lnk;.doc;.xls;.hta;.bin;.7z;.dll;.xla;.cmd;.sh;.lnk;.pptm;.scr;.msi;.sct</TargetFilename>
32+
</Rule>
33+
<Rule groupRelation="and">
34+
<TargetFilename condition="begin with">C:\ProgramData\chocolatey\logs</TargetFilename>
35+
<TargetFilename condition="contains any">.com;.bat;.exe;.reg;.ps1;.vbs;.vba;.lnk;.doc;.xls;.hta;.bin;.7z;.dll;.xla;.cmd;.sh;.lnk;.pptm;.scr;.msi;.sct</TargetFilename>
36+
</Rule>
37+
<Rule groupRelation="and">
38+
<TargetFilename condition="begin with">C:\ProgramData\Microsoft\DeviceSync</TargetFilename>
39+
<TargetFilename condition="contains any">.com;.bat;.exe;.reg;.ps1;.vbs;.vba;.lnk;.doc;.xls;.hta;.bin;.7z;.dll;.xla;.cmd;.sh;.lnk;.pptm;.scr;.msi;.sct</TargetFilename>
40+
</Rule>
41+
<Rule groupRelation="and">
42+
<TargetFilename condition="begin with">C:\ProgramData\Microsoft\PlayReady</TargetFilename>
43+
<TargetFilename condition="contains any">.com;.bat;.exe;.reg;.ps1;.vbs;.vba;.lnk;.doc;.xls;.hta;.bin;.7z;.dll;.xla;.cmd;.sh;.lnk;.pptm;.scr;.msi;.sct</TargetFilename>
44+
</Rule>
45+
<Rule groupRelation="and">
46+
<TargetFilename condition="begin with">C:\ProgramData\Microsoft\User Account Pictures</TargetFilename>
47+
<TargetFilename condition="contains any">.com;.bat;.exe;.reg;.ps1;.vbs;.vba;.lnk;.doc;.xls;.hta;.bin;.7z;.dll;.xla;.cmd;.sh;.lnk;.pptm;.scr;.msi;.sct</TargetFilename>
48+
</Rule>
49+
<Rule groupRelation="and">
50+
<TargetFilename condition="begin with">C:\ProgramData\Microsoft\Crypto\DSS\MachineKeys</TargetFilename>
51+
<TargetFilename condition="contains any">.com;.bat;.exe;.reg;.ps1;.vbs;.vba;.lnk;.doc;.xls;.hta;.bin;.7z;.dll;.xla;.cmd;.sh;.lnk;.pptm;.scr;.msi;.sct</TargetFilename>
52+
</Rule>
53+
<Rule groupRelation="and">
54+
<TargetFilename condition="begin with">C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys</TargetFilename>
55+
<TargetFilename condition="contains any">.com;.bat;.exe;.reg;.ps1;.vbs;.vba;.lnk;.doc;.xls;.hta;.bin;.7z;.dll;.xla;.cmd;.sh;.lnk;.pptm;.scr;.msi;.sct</TargetFilename>
56+
</Rule>
57+
<Rule groupRelation="and">
58+
<TargetFilename condition="begin with">C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore</TargetFilename>
59+
<TargetFilename condition="contains any">.com;.bat;.exe;.reg;.ps1;.vbs;.vba;.lnk;.doc;.xls;.hta;.bin;.7z;.dll;.xla;.cmd;.sh;.lnk;.pptm;.scr;.msi;.sct</TargetFilename>
60+
</Rule>
61+
<Rule groupRelation="and">
62+
<TargetFilename condition="begin with">C:\ProgramData\Microsoft\Office\Heartbeat</TargetFilename>
63+
<TargetFilename condition="contains any">.com;.bat;.exe;.reg;.ps1;.vbs;.vba;.lnk;.doc;.xls;.hta;.bin;.7z;.dll;.xla;.cmd;.sh;.lnk;.pptm;.scr;.msi;.sct</TargetFilename>
64+
</Rule>
65+
<Rule groupRelation="and">
66+
<TargetFilename condition="begin with">C:\ProgramData\Microsoft\Windows\WER\ReportQueue</TargetFilename>
67+
<TargetFilename condition="contains any">.com;.bat;.exe;.reg;.ps1;.vbs;.vba;.lnk;.doc;.xls;.hta;.bin;.7z;.dll;.xla;.cmd;.sh;.lnk;.pptm;.scr;.msi;.sct</TargetFilename>
68+
</Rule>
69+
<Rule groupRelation="and">
70+
<TargetFilename condition="begin with">C:\ProgramData\Microsoft\Windows\WER\Temp</TargetFilename>
71+
<TargetFilename condition="contains any">.com;.bat;.exe;.reg;.ps1;.vbs;.vba;.lnk;.doc;.xls;.hta;.bin;.7z;.dll;.xla;.cmd;.sh;.lnk;.pptm;.scr;.msi;.sct</TargetFilename>
72+
</Rule>
73+
<Rule groupRelation="and">
74+
<TargetFilename condition="begin with">C:\ProgramData\Microsoft\Windows\WER\Temp</TargetFilename>
75+
<TargetFilename condition="contains any">.com;.bat;.exe;.reg;.ps1;.vbs;.vba;.lnk;.doc;.xls;.hta;.bin;.7z;.dll;.xla;.cmd;.sh;.lnk;.pptm;.scr;.msi;.sct</TargetFilename>
76+
</Rule>
77+
<Rule groupRelation="and">
78+
<TargetFilename condition="begin with">C:\ProgramData\Microsoft\Windows\WER\Temp</TargetFilename>
79+
<TargetFilename condition="contains any">.com;.bat;.exe;.reg;.ps1;.vbs;.vba;.lnk;.doc;.xls;.hta;.bin;.7z;.dll;.xla;.cmd;.sh;.lnk;.pptm;.scr;.msi;.sct</TargetFilename>
80+
</Rule>
81+
<Rule groupRelation="and">
82+
<TargetFilename condition="begin with">C:\ProgramData\Microsoft\Windows\WER\Temp</TargetFilename>
83+
<TargetFilename condition="contains any">.com;.bat;.exe;.reg;.ps1;.vbs;.vba;.lnk;.doc;.xls;.hta;.bin;.7z;.dll;.xla;.cmd;.sh;.lnk;.pptm;.scr;.msi;.sct</TargetFilename>
84+
</Rule>
85+
<Rule groupRelation="and">
86+
<TargetFilename condition="begin with">C:\ProgramData\Microsoft\Windows\WER\Temp</TargetFilename>
87+
<TargetFilename condition="contains any">.com;.bat;.exe;.reg;.ps1;.vbs;.vba;.lnk;.doc;.xls;.hta;.bin;.7z;.dll;.xla;.cmd;.sh;.lnk;.pptm;.scr;.msi;.sct</TargetFilename>
88+
</Rule>
89+
<Rule groupRelation="and">
90+
<TargetFilename condition="begin with">C:\Users\All Users\Intel</TargetFilename>
91+
<TargetFilename condition="contains any">.com;.bat;.exe;.reg;.ps1;.vbs;.vba;.lnk;.doc;.xls;.hta;.bin;.7z;.dll;.xla;.cmd;.sh;.lnk;.pptm;.scr;.msi;.sct</TargetFilename>
92+
</Rule>
93+
<Rule groupRelation="and">
94+
<TargetFilename condition="begin with">C:\Users\All Users\Mozilla</TargetFilename>
95+
<TargetFilename condition="contains any">.com;.bat;.exe;.reg;.ps1;.vbs;.vba;.lnk;.doc;.xls;.hta;.bin;.7z;.dll;.xla;.cmd;.sh;.lnk;.pptm;.scr;.msi;.sct</TargetFilename>
96+
</Rule>
97+
<Rule groupRelation="and">
98+
<TargetFilename condition="begin with">C:\Users\All Users\chocolatey\logs</TargetFilename>
99+
<TargetFilename condition="contains any">.com;.bat;.exe;.reg;.ps1;.vbs;.vba;.lnk;.doc;.xls;.hta;.bin;.7z;.dll;.xla;.cmd;.sh;.lnk;.pptm;.scr;.msi;.sct</TargetFilename>
100+
</Rule>
101+
<Rule groupRelation="and">
102+
<TargetFilename condition="begin with">C:\Users\All Users\Microsoft\DeviceSync</TargetFilename>
103+
<TargetFilename condition="contains any">.com;.bat;.exe;.reg;.ps1;.vbs;.vba;.lnk;.doc;.xls;.hta;.bin;.7z;.dll;.xla;.cmd;.sh;.lnk;.pptm;.scr;.msi;.sct</TargetFilename>
104+
</Rule>
105+
<Rule groupRelation="and">
106+
<TargetFilename condition="begin with">C:\Users\All Users\Microsoft\PlayReady</TargetFilename>
107+
<TargetFilename condition="contains any">.com;.bat;.exe;.reg;.ps1;.vbs;.vba;.lnk;.doc;.xls;.hta;.bin;.7z;.dll;.xla;.cmd;.sh;.lnk;.pptm;.scr;.msi;.sct</TargetFilename>
108+
</Rule>
109+
<Rule groupRelation="and">
110+
<TargetFilename condition="begin with">C:\Users\All Users\Microsoft\User Account Pictures</TargetFilename>
111+
<TargetFilename condition="contains any">.com;.bat;.exe;.reg;.ps1;.vbs;.vba;.lnk;.doc;.xls;.hta;.bin;.7z;.dll;.xla;.cmd;.sh;.lnk;.pptm;.scr;.msi;.sct</TargetFilename>
112+
</Rule>
113+
<Rule groupRelation="and">
114+
<TargetFilename condition="begin with">C:\Users\All Users\Microsoft\Crypto\DSS\MachineKeys</TargetFilename>
115+
<TargetFilename condition="contains any">.com;.bat;.exe;.reg;.ps1;.vbs;.vba;.lnk;.doc;.xls;.hta;.bin;.7z;.dll;.xla;.cmd;.sh;.lnk;.pptm;.scr;.msi;.sct</TargetFilename>
116+
</Rule>
117+
<Rule groupRelation="and">
118+
<TargetFilename condition="begin with">C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys</TargetFilename>
119+
<TargetFilename condition="contains any">.com;.bat;.exe;.reg;.ps1;.vbs;.vba;.lnk;.doc;.xls;.hta;.bin;.7z;.dll;.xla;.cmd;.sh;.lnk;.pptm;.scr;.msi;.sct</TargetFilename>
120+
</Rule>
121+
<Rule groupRelation="and">
122+
<TargetFilename condition="begin with">C:\Users\All Users\Microsoft\NetFramework\BreadcrumbStore</TargetFilename>
123+
<TargetFilename condition="contains any">.com;.bat;.exe;.reg;.ps1;.vbs;.vba;.lnk;.doc;.xls;.hta;.bin;.7z;.dll;.xla;.cmd;.sh;.lnk;.pptm;.scr;.msi;.sct</TargetFilename>
124+
</Rule>
125+
<Rule groupRelation="and">
126+
<TargetFilename condition="begin with">C:\Users\All Users\Microsoft\Office\Heartbeat</TargetFilename>
127+
<TargetFilename condition="contains any">.com;.bat;.exe;.reg;.ps1;.vbs;.vba;.lnk;.doc;.xls;.hta;.bin;.7z;.dll;.xla;.cmd;.sh;.lnk;.pptm;.scr;.msi;.sct</TargetFilename>
128+
</Rule>
129+
<Rule groupRelation="and">
130+
<TargetFilename condition="begin with">C:\Users\All Users\Microsoft\Windows\WER\ReportArchive</TargetFilename>
131+
<TargetFilename condition="contains any">.com;.bat;.exe;.reg;.ps1;.vbs;.vba;.lnk;.doc;.xls;.hta;.bin;.7z;.dll;.xla;.cmd;.sh;.lnk;.pptm;.scr;.msi;.sct</TargetFilename>
132+
</Rule>
133+
<Rule groupRelation="and">
134+
<TargetFilename condition="begin with">C:\Users\All Users\Microsoft\Windows\WER\ReportQueue</TargetFilename>
135+
<TargetFilename condition="contains any">.com;.bat;.exe;.reg;.ps1;.vbs;.vba;.lnk;.doc;.xls;.hta;.bin;.7z;.dll;.xla;.cmd;.sh;.lnk;.pptm;.scr;.msi;.sct</TargetFilename>
136+
</Rule>
137+
<Rule groupRelation="and">
138+
<TargetFilename condition="begin with">C:\Users\All Users\Microsoft\Windows\WER\Temp</TargetFilename>
139+
<TargetFilename condition="contains any">.com;.bat;.exe;.reg;.ps1;.vbs;.vba;.lnk;.doc;.xls;.hta;.bin;.7z;.dll;.xla;.cmd;.sh;.lnk;.pptm;.scr;.msi;.sct</TargetFilename>
140+
</Rule>
141+
<Rule groupRelation="and">
142+
<TargetFilename condition="begin with">C:\Windows\Tasks</TargetFilename>
143+
<TargetFilename condition="contains any">.com;.bat;.exe;.reg;.ps1;.vbs;.vba;.lnk;.doc;.xls;.hta;.bin;.7z;.dll;.xla;.cmd;.sh;.lnk;.pptm;.scr;.msi;.sct</TargetFilename>
144+
</Rule>
145+
<Rule groupRelation="and">
146+
<TargetFilename condition="begin with">C:\Windows\tracing</TargetFilename>
147+
<TargetFilename condition="contains any">.com;.bat;.exe;.reg;.ps1;.vbs;.vba;.lnk;.doc;.xls;.hta;.bin;.7z;.dll;.xla;.cmd;.sh;.lnk;.pptm;.scr;.msi;.sct</TargetFilename>
148+
</Rule>
149+
<Rule groupRelation="and">
150+
<TargetFilename condition="begin with">C:\Windows\Registration\CRMLog</TargetFilename>
151+
<TargetFilename condition="contains any">.com;.bat;.exe;.reg;.ps1;.vbs;.vba;.lnk;.doc;.xls;.hta;.bin;.7z;.dll;.xla;.cmd;.sh;.lnk;.pptm;.scr;.msi;.sct</TargetFilename>
152+
</Rule>
153+
<Rule groupRelation="and">
154+
<TargetFilename condition="begin with">C:\Windows\System32\Tasks</TargetFilename>
155+
<TargetFilename condition="contains any">.com;.bat;.exe;.reg;.ps1;.vbs;.vba;.lnk;.doc;.xls;.hta;.bin;.7z;.dll;.xla;.cmd;.sh;.lnk;.pptm;.scr;.msi;.sct</TargetFilename>
156+
</Rule>
157+
<Rule groupRelation="and">
158+
<TargetFilename condition="begin with">C:\Windows\System32\Microsoft\Crypto\RSA\MachineKeys</TargetFilename>
159+
<TargetFilename condition="contains any">.com;.bat;.exe;.reg;.ps1;.vbs;.vba;.lnk;.doc;.xls;.hta;.bin;.7z;.dll;.xla;.cmd;.sh;.lnk;.pptm;.scr;.msi;.sct</TargetFilename>
160+
</Rule>
161+
<Rule groupRelation="and">
162+
<TargetFilename condition="begin with">C:\Windows\System32\spool\drivers\color</TargetFilename>
163+
<TargetFilename condition="contains any">.com;.bat;.exe;.reg;.ps1;.vbs;.vba;.lnk;.doc;.xls;.hta;.bin;.7z;.dll;.xla;.cmd;.sh;.lnk;.pptm;.scr;.msi;.sct</TargetFilename>
164+
</Rule>
165+
<Rule groupRelation="and">
166+
<TargetFilename condition="begin with">C:\Windows\SysWOW64\Tasks</TargetFilename>
167+
<TargetFilename condition="contains any">.com;.bat;.exe;.reg;.ps1;.vbs;.vba;.lnk;.doc;.xls;.hta;.bin;.7z;.dll;.xla;.cmd;.sh;.lnk;.pptm;.scr;.msi;.sct</TargetFilename>
168+
</Rule>
169+
</FileDelete>
170+
</RuleGroup>
171+
172+
<!-- Log but dont Capture deleted files -->
173+
<RuleGroup name="" groupRelation="or">
174+
<FileDeleteDetected onmatch="include">
175+
<Rule groupRelation="and">
176+
<TargetFilename condition="contains">\Downloads\</TargetFilename> <!--User Download folder-->
177+
<TargetFilename condition="contains any">.exe;dll;.msi;.7z;.zip</TargetFilename>
178+
</Rule>
179+
<Rule groupRelation="and">
180+
<TargetFilename condition="contains">\Appdata\Local\Temp\</TargetFilename> <!--User Temp folder-->
181+
<TargetFilename condition="contains any">.exe;dll;.msi;.7z;.zip</TargetFilename>
182+
</Rule>
183+
</FileDeleteDetected>
184+
</RuleGroup>
185+
</EventFiltering>
186+
</Sysmon>

0 commit comments

Comments
 (0)