X-Git-Url: http://ftp.carnet.hr/carnet-debian/scm?p=ossec-hids.git;a=blobdiff_plain;f=src%2Fwin32%2Fossec.conf;h=e66dc14d905aa5a0f6501bfeff124ff57031d0c9;hp=6a943eacc7dc49e9e66644c6ca4c9144c0bf6cc7;hb=3f728675941dc69d4e544d3a880a56240a6e394a;hpb=927951d1c1ad45ba9e7325f07d996154a91c911b diff --git a/src/win32/ossec.conf b/src/win32/ossec.conf old mode 100755 new mode 100644 index 6a943ea..e66dc14 --- a/src/win32/ossec.conf +++ b/src/win32/ossec.conf @@ -1,24 +1,23 @@ - - - @@ -36,19 +35,22 @@ System eventlog - + + + Windows PowerShell + eventlog + ./shared/win_audit_rcl.txt ./shared/win_applications_rcl.txt ./shared/win_malware_rcl.txt - - + - + @@ -57,8 +59,7 @@ - yes - + yes %WINDIR%/win.ini @@ -66,6 +67,30 @@ C:\autoexec.bat C:\config.sys C:\boot.ini + + %WINDIR%/SysNative/at.exe + %WINDIR%/SysNative/attrib.exe + %WINDIR%/SysNative/cacls.exe + %WINDIR%/SysNative/cmd.exe + %WINDIR%/SysNative/drivers/etc + %WINDIR%/SysNative/eventcreate.exe + %WINDIR%/SysNative/ftp.exe + %WINDIR%/SysNative/lsass.exe + %WINDIR%/SysNative/net.exe + %WINDIR%/SysNative/net1.exe + %WINDIR%/SysNative/netsh.exe + %WINDIR%/SysNative/reg.exe + %WINDIR%/SysNative/regedt32.exe + %WINDIR%/SysNative/regsvr32.exe + %WINDIR%/SysNative/runas.exe + %WINDIR%/SysNative/sc.exe + %WINDIR%/SysNative/schtasks.exe + %WINDIR%/SysNative/sethc.exe + %WINDIR%/SysNative/subst.exe + %WINDIR%/SysNative/wbem/WMIC.exe + %WINDIR%/SysNative/WindowsPowerShell\v1.0\powershell.exe + %WINDIR%/SysNative/winrm.vbs + %WINDIR%/System32/CONFIG.NT %WINDIR%/System32/AUTOEXEC.NT %WINDIR%/System32/at.exe @@ -95,10 +120,13 @@ %WINDIR%/System32/tftp.exe %WINDIR%/System32/tlntsvr.exe %WINDIR%/System32/drivers/etc - C:\Documents and Settings/All Users/Start Menu/Programs/Startup - C:\Users/Public/All Users/Microsoft/Windows/Start Menu/Startup - .log$|.htm$|.jpg$|.png$|.chm$|.pnf$|.evtx$ + %WINDIR%/System32/wbem/WMIC.exe + %WINDIR%/System32/WindowsPowerShell\v1.0\powershell.exe + %WINDIR%/System32/winrm.vbs + %PROGRAMDATA%/Microsoft/Windows/Start Menu/Programs/Startup + + .log$|.htm$|.jpg$|.png$|.chm$|.pnf$|.evtx$ HKEY_LOCAL_MACHINE\Software\Classes\batfile @@ -114,7 +142,6 @@ HKEY_LOCAL_MACHINE\Security HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer - HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\KnownDLLs HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurePipeServers\winreg @@ -129,13 +156,11 @@ HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components - - HKEY_LOCAL_MACHINE\Security\Policy\Secrets HKEY_LOCAL_MACHINE\Security\SAM\Domains\Account\Users \Enum$ - + yes @@ -143,6 +168,4 @@ - -