Enhanced Windows rule pack

Prev Next

The Enhanced Windows Rule Pack is focused on finding activity in Windows event logs that might represent malicious or undesired activity, and contains more than fifty rules across a range of vectors that can be targeted for attack.

Initial deployment state

The Enhanced Windows Rule Pack is disabled by default. Because many of the new Windows rules detect activity that can often be considered benign, they have been disabled by default in order to prevent unwanted or noisy alerts from being generated. We recommend that you review each of these rules individually and read their descriptions in order to determine if they are suitable for your environment, detection strategy, and risk profile before determining whether or not to enable them for your environment.

Rules in the enhanced Windows rule pack

The rules in the Enhanced Windows Rule Pack include:

Suspicious user activity

These rules are designed to detect anomalous user activity, and include:

  • New user creation

  • User password retrieval

  • Users being added to the domain admin and enterprise admin groups

While the above actions are normal in the right circumstances, they often warrant additional investigation and verification. These rules are ideal for detecting unauthorized changes related to user accounts, or for detecting the presence of an attacker who has gained a foothold on your network.

These rules can also serve as a foundation for constructing similar Customer Rules that are tailored for your environment.

Suspicious service and process activity

These rules are designed to detect anomalous activity related to services and processes, and include:

  • New service installation

  • Scheduled task creation

  • Clearing event logs

  • Application crashes

  • Registry run key access and modifications

  • Multiple failed logins via RDP

  • Multiple failed logins using admin accounts

  • Kernel driver installations and loading failures

While the above actions are normal in the right circumstances, they often warrant additional investigation and verification. These rules are ideal for detecting unauthorized activities related to services and processes, or for detecting the presence of an attacker who is attempting to gain a foothold on your network.

These rules can also serve as a foundation for constructing similar Customer Rules that are tailored for your environment.

Windows firewall modifications

As many organizations rely on the built-in Windows Firewall to protect endpoints and servers, Trellix developed 17 rules that focus on detecting of specific types of logs generated by or about the Windows Firewall. These include:

  • Firewall rule creation/modification/deletion

  • Blocked application logs

  • Firewall service modifications (manually or via group policy)

These rules are ideal for deployment in environments that contain critical servers where firewall changes or service disruptions are worthy of investigation.

EMET notification

The Microsoft Enhanced Mitigation Experience Toolkit (EMET) is a utility that helps prevent vulnerabilities in software from being successfully exploited by helping detect and block techniques that are commonly used to exploit memory corruption vulnerabilities. We have created two rules that will generate alerts when EMET Errors and Warnings are generated.

These rules are ideal for deployment in environments containing critical external facing systems where you are concerned about vulnerability exploitation.

AppLocker notifications

Microsoft AppLocker is a set of Group Policy settings that evolved from Software Restriction Policies, to restrict which applications can run on a corporate network, including the ability to restrict based on the application's version number or publisher. We have created two rules that will generate alerts when AppLocker Errors and Warnings are generated.

These rules are ideal for deployment on critical systems where you are concerned about the installation of malicious or unapproved software.

Pass-the-hash detection

The Pass-the-Hash technique is used by attackers to gain unauthorized access to Windows systems using only stolen password hashes, as opposed to full passwords. This technique allows the attacker to access these systems without cracking passwords, defeating protective controls such as complex password requirements and password rotation. We have created two rules that will detect both attempted and successful pass-the-hash attempts against local (non-domain) Windows accounts.

For these rules to work, you must manually create lists containing every valid Windows domain name in your environment. These lists should be created prior to enabling either of these rules.