* Client event queries are targeted by label group.
* Sysmon will be installed automatically and events will be forwarded.
---
## Viewing Sysmon events relayed to the server
data:image/s3,"s3://crabby-images/892a1/892a14ebab174b739a6e9d7540e1d049a4f5d195" alt=""
---
## Turning artifacts into a detection
* We have previously looked at log enable/disable by examining registry keys.
* Can we detect when these registry keys are changing?
* The diff() plugin periodically runs a query and reports on changes.
* Install the `Windows.Events.EventLogModifications` artifact
---
## Windows.Events.EventLogModifications
data:image/s3,"s3://crabby-images/b1c4e/b1c4e0b4757295a09d80c608d59a2faa7a112859" alt=""
---
## System changes relayed to server
Good for slow changes
data:image/s3,"s3://crabby-images/81ed8/81ed86ebcadc65843a6185796b0d77c107de5e42" alt=""
---
# USN Journal monitoring
## File modification monitoring at scale.
---
## USN Journal
* We have previously seen that the USN journal is useful for
recovering evidence of file modification.
* Sadly in practice the USN journal rolls over fairly quickly (days!)
* Wouldn't it be nice to feed the events to the server continuously?
---
## Windows.Detection.USN
* Enable the Windows.Detection.USN artifact - target paths of
interest.
data:image/s3,"s3://crabby-images/daaf5/daaf5118f7075385320f568b8f8fde4f61e9940d" alt=""
---
## Inspect streaming results
* See direct evidence of execution, tasks creation etc.
data:image/s3,"s3://crabby-images/cdca4/cdca45b63b4143974e16d4d1690babd34b41c07e" alt=""