|
1 | 1 | { |
2 | 2 | "expected": [ |
| 3 | + { |
| 4 | + "@timestamp": "2024-06-21T01:21:15.131Z", |
| 5 | + "ecs": { |
| 6 | + "version": "8.11.0" |
| 7 | + }, |
| 8 | + "event": { |
| 9 | + "action": "malware-detected", |
| 10 | + "category": [ |
| 11 | + "malware" |
| 12 | + ], |
| 13 | + "code": "1116", |
| 14 | + "kind": "event", |
| 15 | + "outcome": "success", |
| 16 | + "provider": "Microsoft-Windows-Windows Defender", |
| 17 | + "reference": "https://go.microsoft.com/fwlink/?linkid=37020&name=Virus:DOS/EICAR_Test_File&threatid=2147519003&enterprise=1", |
| 18 | + "type": [ |
| 19 | + "info" |
| 20 | + ] |
| 21 | + }, |
| 22 | + "file": { |
| 23 | + "extension": "inf.exe", |
| 24 | + "name": "autorun.inf.exe", |
| 25 | + "path": "D:\\autorun.inf\\autorun.inf.exe" |
| 26 | + }, |
| 27 | + "host": { |
| 28 | + "name": "el33t-b00k-1" |
| 29 | + }, |
| 30 | + "log": { |
| 31 | + "level": "Warning" |
| 32 | + }, |
| 33 | + "message": "Microsoft Defender Antivirus has detected malware or other potentially unwanted software.\r\n For more information please see the following:\r\nhttps://go.microsoft.com/fwlink/?linkid=37020&name=Virus:DOS/EICAR_Test_File&threatid=2147519003&enterprise=0\r\n \tName: Virus:DOS/EICAR_Test_File\r\n \tID: 2147519003\r\n \tSeverity: Severe\r\n \tCategory: Virus\r\n \tPath: file:_C:\\Users\\topsy\\OneDrive\\Desktop\\eat_more_yams.exe\r\n \tDetection Origin: Local machine\r\n \tDetection Type: Concrete\r\n \tDetection Source: Real-Time Protection\r\n \tUser: el33t-b00k-1\\topsy\r\n \tProcess Name: C:\\Users\\topsy\\AppData\\Local\\Microsoft\\OneDrive\\OneDrive.exe\r\n \tSecurity intelligence Version: AV: 1.413.419.0, AS: 1.413.419.0, NIS: 1.413.419.0\r\n \tEngine Version: AM: 1.1.24050.5, NIS: 1.1.24050.5", |
| 34 | + "user": { |
| 35 | + "domain": "NT AUTHORITY", |
| 36 | + "name": "SYSTEM" |
| 37 | + }, |
| 38 | + "windows_defender": { |
| 39 | + "evidence_paths": [ |
| 40 | + "D:\\autorun.inf\\autorun.inf.exe", |
| 41 | + "D:\\autorun.inf\\Protection for Autorun\\Protection for Autorun.exe", |
| 42 | + "D:\\test\\.exe" |
| 43 | + ] |
| 44 | + }, |
| 45 | + "winlog": { |
| 46 | + "activity_id": "5f4a9fb7-8bb9-4d46-a5af-b880cefca3c1", |
| 47 | + "channel": "Microsoft-Windows-Windows Defender/Operational", |
| 48 | + "computer_name": "el33t-b00k-1", |
| 49 | + "event_data": { |
| 50 | + "Action_ID": "9", |
| 51 | + "Action_Name": "Not Applicable", |
| 52 | + "Additional_Actions_ID": "0", |
| 53 | + "Additional_Actions_String": "No additional actions required", |
| 54 | + "Category_ID": "42", |
| 55 | + "Category_Name": "Virus", |
| 56 | + "Detection_ID": "{21A294A2-FE84-4DE0-B1D0-47D6DCD4DA9A}", |
| 57 | + "Detection_Time": "2024-09-26T16:04:49.772Z", |
| 58 | + "Detection_User": "NT AUTHORITY\\SYSTEM", |
| 59 | + "Engine_Version": "AM: 1.1.24080.9, NIS: 1.1.24080.9", |
| 60 | + "Error_Code": "0x00000000", |
| 61 | + "Error_Description": "The operation completed successfully. ", |
| 62 | + "Execution_ID": "1", |
| 63 | + "Execution_Name": "Suspended", |
| 64 | + "FWLink": "https://go.microsoft.com/fwlink/?linkid=37020&name=Virus:DOS/EICAR_Test_File&threatid=2147519003&enterprise=1", |
| 65 | + "Origin_ID": "1", |
| 66 | + "Origin_Name": "Local machine", |
| 67 | + "Path": "file:_D:\\autorun.inf\\autorun.inf.exe; file:_D:\\autorun.inf\\Protection for Autorun\\Protection for Autorun.exe; file:_D:\\test\\.exe", |
| 68 | + "Post_Clean_Status": "0", |
| 69 | + "Pre_Execution_Status": "0", |
| 70 | + "Product_Name": "Microsoft Defender Antivirus", |
| 71 | + "Product_Version": "4.18.24080.9", |
| 72 | + "Security_intelligence_Version": "AV: 1.419.183.0, AS: 1.419.183.0, NIS: 1.419.183.0", |
| 73 | + "Severity_ID": "5", |
| 74 | + "Severity_Name": "Severe", |
| 75 | + "Source_ID": "2", |
| 76 | + "Source_Name": "System", |
| 77 | + "State": "1", |
| 78 | + "Status_Code": "1", |
| 79 | + "Threat_ID": "2147519003", |
| 80 | + "Threat_Name": "Virus:DOS/EICAR_Test_File", |
| 81 | + "Type_ID": "0", |
| 82 | + "Type_Name": "Concrete" |
| 83 | + }, |
| 84 | + "event_id": "1116", |
| 85 | + "level": "Warning", |
| 86 | + "opcode": "Info", |
| 87 | + "process": { |
| 88 | + "pid": 7676, |
| 89 | + "thread": { |
| 90 | + "id": 29468 |
| 91 | + } |
| 92 | + }, |
| 93 | + "provider_guid": "11cd958a-c507-4ef3-b3f2-5fd9dfbd2c78", |
| 94 | + "provider_name": "Microsoft-Windows-Windows Defender", |
| 95 | + "record_id": "5646", |
| 96 | + "time_created": "2024-06-21T01:21:15.1310609Z", |
| 97 | + "user": { |
| 98 | + "identifier": "S-1-5-18", |
| 99 | + "name": "Topsy" |
| 100 | + }, |
| 101 | + "version": 0 |
| 102 | + } |
| 103 | + }, |
3 | 104 | { |
4 | 105 | "@timestamp": "2024-06-21T01:21:15.131Z", |
5 | 106 | "ecs": { |
|
35 | 136 | "domain": "NT AUTHORITY", |
36 | 137 | "name": "SYSTEM" |
37 | 138 | }, |
| 139 | + "windows_defender": { |
| 140 | + "evidence_paths": [ |
| 141 | + "C:\\Users\\Topsy\\Desktop\\eat_more_yams.exe" |
| 142 | + ] |
| 143 | + }, |
38 | 144 | "winlog": { |
39 | 145 | "activity_id": "5f4a9fb7-8bb9-4d46-a5af-b880cefca3c1", |
40 | 146 | "channel": "Microsoft-Windows-Windows Defender/Operational", |
|
129 | 235 | "domain": "NT AUTHORITY", |
130 | 236 | "name": "SYSTEM" |
131 | 237 | }, |
| 238 | + "windows_defender": { |
| 239 | + "evidence_paths": [ |
| 240 | + "C:\\Users\\Topsy\\Desktop\\eat_more_yams.exe", |
| 241 | + "pid: 31337" |
| 242 | + ] |
| 243 | + }, |
132 | 244 | "winlog": { |
133 | 245 | "activity_id": "5f4a9fb7-8bb9-4d46-a5af-b880cefca3c1", |
134 | 246 | "channel": "Microsoft-Windows-Windows Defender/Operational", |
|
459 | 571 | "domain": "NT AUTHORITY", |
460 | 572 | "name": "SYSTEM" |
461 | 573 | }, |
| 574 | + "windows_defender": { |
| 575 | + "evidence_paths": [ |
| 576 | + "C:\\Users\\Topsy\\Desktop\\eat_more_yams.exe" |
| 577 | + ] |
| 578 | + }, |
462 | 579 | "winlog": { |
463 | 580 | "activity_id": "", |
464 | 581 | "channel": "Microsoft-Windows-Windows Defender/Operational", |
|
554 | 671 | "domain": "NT AUTHORITY", |
555 | 672 | "name": "SYSTEM" |
556 | 673 | }, |
| 674 | + "windows_defender": { |
| 675 | + "evidence_paths": [ |
| 676 | + "C:\\Users\\Topsy\\Desktop\\eat_more_yams.exe", |
| 677 | + "pid: 1337" |
| 678 | + ] |
| 679 | + }, |
557 | 680 | "winlog": { |
558 | 681 | "activity_id": "", |
559 | 682 | "channel": "Microsoft-Windows-Windows Defender/Operational", |
|
0 commit comments