Overcoming Domain Name Resolution Issue in Sysmon

Sysmon is a well known tool provided by Microsoft frequently used in the fields of threat hunting, incident response and security monitoring. One of its best features is that it allows one to log any network connection issued by the processes running on the system. We will quickly review what information is provided in those events and what is the issue we have noticed. In order to overcome the issue we will present our work around which comes in a form of a new feature called event hooks introduced in the latest version of WHIDS. more ...

Go Evtx SigNature Engine

This article introduces an engine (a.k.a Gene) we have designed to match signatures in Windows events. Our motivations were driven by some observations done during several incident we have worked on. The first observation is that Windows OS has hundreds of different event logs, which makes very difficult to remember the meaning of all of them. Some event logs can simply characterize that something is going wrong on a system whilst some others are clearly the signature of a compromise. The two previous observations make the study of the Windows very important and sometime decisive for an analysis. more ...

EVTX Flat Storage Optimization

When we try to play with several machines, Sysmon and WECs (Windows Event Collectors) we quickly see the amount of logs growing. Knowing quite good the EVTX file format we realized that no compression is builtin. In order to optimize the storage of the events collected, we decided to run basic compression tests that we are going to describe here. more ...