Skip to content

Commit 3759cea

Browse files
committed
Updated schema and attack mapping for Windows Firewall With Advanced Security events
- log_source: Microsoft-Windows-Windows Firewall With Advanced Security - issue created in OSSEM-DD: Creation of dictionaries required - OTRF/OSSEM-DD#39
1 parent a1ee4c7 commit 3759cea

15 files changed

+1084
-150
lines changed

relationships/_all_ossem_relationships.json

Lines changed: 48 additions & 44 deletions
Original file line numberDiff line numberDiff line change
@@ -1730,7 +1730,10 @@
17301730
"contributors": [
17311731
"Jose Rodriguez @Cyb3rPandaH"
17321732
],
1733-
"attack": null,
1733+
"attack": {
1734+
"data_source": "Firewall",
1735+
"data_component": "firewall rule modification"
1736+
},
17341737
"behavior": {
17351738
"source": "process",
17361739
"relationship": "removed",
@@ -1741,16 +1744,12 @@
17411744
"event_id": 2006,
17421745
"name": "A rule has been deleted in the Windows Defender Firewall exception list",
17431746
"platform": "windows",
1744-
"audit_category": null,
1745-
"audit_sub_category": null,
1746-
"log_channel": "Microsoft-Windows-Windows Firewall With Advanced Security/Firewall",
1747-
"log_provider": "Microsoft-Windows-Windows Firewall With Advanced Security"
1747+
"log_source": "Microsoft-Windows-Windows Firewall With Advanced Security",
1748+
"event_version": []
17481749
}
17491750
],
17501751
"references": null,
1751-
"notes": [
1752-
"Potential contribution for ATT&CK - Firewall / firewall rule modification"
1753-
]
1752+
"notes": null
17541753
},
17551754
{
17561755
"relationship_id": "REL-2022-0039",
@@ -3991,7 +3990,10 @@
39913990
"contributors": [
39923991
"Jose Rodriguez @Cyb3rPandaH"
39933992
],
3994-
"attack": null,
3993+
"attack": {
3994+
"data_source": "Firewall",
3995+
"data_component": "firewall rule modification"
3996+
},
39953997
"behavior": {
39963998
"source": "process",
39973999
"relationship": "added",
@@ -4002,16 +4004,12 @@
40024004
"event_id": 2004,
40034005
"name": "A rule has been added to the Windows Defender Firewall exception list",
40044006
"platform": "windows",
4005-
"audit_category": null,
4006-
"audit_sub_category": null,
4007-
"log_channel": "Microsoft-Windows-Windows Firewall With Advanced Security/Firewall",
4008-
"log_provider": "Microsoft-Windows-Windows Firewall With Advanced Security"
4007+
"log_source": "Microsoft-Windows-Windows Firewall With Advanced Security",
4008+
"event_version": []
40094009
}
40104010
],
40114011
"references": null,
4012-
"notes": [
4013-
"Potential contribution for ATT&CK - Firewall / firewall rule modification"
4014-
]
4012+
"notes": null
40154013
},
40164014
{
40174015
"relationship_id": "REL-2022-0089",
@@ -4305,7 +4303,10 @@
43054303
"contributors": [
43064304
"Jose Rodriguez @Cyb3rPandaH"
43074305
],
4308-
"attack": null,
4306+
"attack": {
4307+
"data_source": "Firewall",
4308+
"data_component": "firewall rule modification"
4309+
},
43094310
"behavior": {
43104311
"source": "process",
43114312
"relationship": "modified",
@@ -4316,16 +4317,12 @@
43164317
"event_id": 2005,
43174318
"name": "A rule has been modified in the Windows Defender Firewall exception list.",
43184319
"platform": "windows",
4319-
"audit_category": null,
4320-
"audit_sub_category": null,
4321-
"log_channel": "Microsoft-Windows-Windows Firewall With Advanced Security/Firewall",
4322-
"log_provider": "Microsoft-Windows-Windows Firewall With Advanced Security"
4320+
"log_source": "Microsoft-Windows-Windows Firewall With Advanced Security",
4321+
"event_version": []
43234322
}
43244323
],
43254324
"references": null,
4326-
"notes": [
4327-
"Potential contribution for ATT&CK - Firewall / firewall rule modification"
4328-
]
4325+
"notes": null
43294326
},
43304327
{
43314328
"relationship_id": "REL-2022-0096",
@@ -5359,7 +5356,8 @@
53595356
"event_id": 2006,
53605357
"name": "A rule has been deleted in the Windows Defender Firewall exception list",
53615358
"platform": "windows",
5362-
"log_source": "Microsoft-Windows-Windows Firewall With Advanced Security/Firewall"
5359+
"log_source": "Microsoft-Windows-Windows Firewall With Advanced Security",
5360+
"event_version": []
53635361
},
53645362
{
53655363
"event_id": "cloudtrail",
@@ -5382,7 +5380,8 @@
53825380
"event_id": 2033,
53835381
"name": "All rules have been deleted from the Windows Firewall configuration on this computer.",
53845382
"platform": "windows",
5385-
"log_source": "Microsoft-Windows-Windows Firewall With Advanced Security/Firewall"
5383+
"log_source": "Microsoft-Windows-Windows Firewall With Advanced Security",
5384+
"event_version": []
53865385
}
53875386
],
53885387
"references": null,
@@ -5802,7 +5801,8 @@
58025801
"event_id": 2009,
58035802
"name": "The Windows Firewall service failed to load Group Policy.",
58045803
"platform": "windows",
5805-
"log_source": "Microsoft-Windows-Windows Firewall With Advanced Security/Firewall"
5804+
"log_source": "Microsoft-Windows-Windows Firewall With Advanced Security",
5805+
"event_version": []
58065806
}
58075807
],
58085808
"references": null,
@@ -7039,7 +7039,10 @@
70397039
"contributors": [
70407040
"Jose Rodriguez @Cyb3rPandaH"
70417041
],
7042-
"attack": null,
7042+
"attack": {
7043+
"data_source": "Firewall",
7044+
"data_component": "firewall metadata"
7045+
},
70437046
"behavior": {
70447047
"source": "user",
70457048
"relationship": "modified",
@@ -7050,13 +7053,15 @@
70507053
"event_id": 2002,
70517054
"name": "A Windows Defender Firewall setting has changed.",
70527055
"platform": "windows",
7053-
"log_source": "Microsoft-Windows-Windows Firewall With Advanced Security/Firewall"
7056+
"log_source": "Microsoft-Windows-Windows Firewall With Advanced Security",
7057+
"event_version": []
70547058
},
70557059
{
70567060
"event_id": 2003,
70577061
"name": "A Windows Defender Firewall setting in the Private profile has changed.",
70587062
"platform": "windows",
7059-
"log_source": "Microsoft-Windows-Windows Firewall With Advanced Security/Firewall"
7063+
"log_source": "Microsoft-Windows-Windows Firewall With Advanced Security",
7064+
"event_version": []
70607065
}
70617066
],
70627067
"references": null,
@@ -7876,7 +7881,8 @@
78767881
"platform": "windows",
78777882
"audit_category": null,
78787883
"audit_sub_category": null,
7879-
"log_source": "Microsoft-Windows-Windows Firewall With Advanced Security/Firewall"
7884+
"log_source": "Microsoft-Windows-Windows Firewall With Advanced Security",
7885+
"event_version": []
78807886
},
78817887
{
78827888
"event_id": "cloudtrail",
@@ -8450,7 +8456,8 @@
84508456
"event_id": 2005,
84518457
"name": "A rule has been modified in the Windows Defender Firewall exception list.",
84528458
"platform": "windows",
8453-
"log_source": "Microsoft-Windows-Windows Firewall With Advanced Security/Firewall"
8459+
"log_source": "Microsoft-Windows-Windows Firewall With Advanced Security",
8460+
"event_version": []
84548461
},
84558462
{
84568463
"event_id": "cloudtrail",
@@ -8479,7 +8486,10 @@
84798486
"contributors": [
84808487
"Jose Rodriguez @Cyb3rPandaH"
84818488
],
8482-
"attack": null,
8489+
"attack": {
8490+
"data_source": "Firewall",
8491+
"data_component": "firewall metadata"
8492+
},
84838493
"behavior": {
84848494
"source": "process",
84858495
"relationship": "modified",
@@ -8490,25 +8500,19 @@
84908500
"event_id": 2002,
84918501
"name": "A Windows Defender Firewall setting has changed.",
84928502
"platform": "windows",
8493-
"audit_category": null,
8494-
"audit_sub_category": null,
8495-
"log_channel": "Microsoft-Windows-Windows Firewall With Advanced Security/Firewall",
8496-
"log_provider": "Microsoft-Windows-Windows Firewall With Advanced Security"
8503+
"log_source": "Microsoft-Windows-Windows Firewall With Advanced Security",
8504+
"event_version": []
84978505
},
84988506
{
84998507
"event_id": 2003,
85008508
"name": "A Windows Defender Firewall setting in the Private profile has changed.",
85018509
"platform": "windows",
8502-
"audit_category": null,
8503-
"audit_sub_category": null,
8504-
"log_channel": "Microsoft-Windows-Windows Firewall With Advanced Security/Firewall",
8505-
"log_provider": "Microsoft-Windows-Windows Firewall With Advanced Security"
8510+
"log_source": "Microsoft-Windows-Windows Firewall With Advanced Security",
8511+
"event_version": []
85068512
}
85078513
],
85088514
"references": null,
8509-
"notes": [
8510-
"Potential contribution for ATT&CK - Firewall / firewall modification (New data component and relationship)"
8511-
]
8515+
"notes": null
85128516
},
85138517
{
85148518
"relationship_id": "REL-2022-0181",

0 commit comments

Comments
 (0)