Comments (4)
Sorry, I accidentally labelled it as a bug.
from lme.
Sigcheck is used to check the versions of Sysmon available and deployed.
We cannot use Sysmon to determine the hash before Sysmon is installed, also without running the centrally stored version of Sysmon we are unable to get the filehash from Sysmon so we use Sigcheck for this.
from lme.
In addition, I think we used it to check the version number of the sysmon binary (the one in the binary header). We didn’t want every machine pulling down sysmon once a day to check if it had changed, for network bandwidth and unintentional DDoS reasons. Instead, we tested and sigcheck appears to be using windows networking to just read the file version, so takes minimal bandwidth. If we see the number change, then we pull it down. We can’t do this for the config xml, so pull that down and hash but it’s about 100kb.
from lme.
Thanks for that! it makes sense to use sigcheck.
from lme.
Related Issues (20)
- [FeatureRequest] E-Mail Notification HOT 6
- Import STIX file or stream [FeatureRequest] HOT 1
- [BUG] HOT 1
- Kibana server is not ready yet HOT 6
- TLS 1.1 HOT 4
- Separate "Kibana server is not ready yet" issue HOT 19
- Kibana server not ready yet?[BUG] HOT 4
- Kibana server not ready yet then dead web console. HOT 5
- [FeatureRequest] HOT 1
- [FeatureRequest] HOT 2
- FileBeats incorporation [FeatureRequest] HOT 1
- Problem with LME .siem-signals-default HOT 3
- How can I get a friendly HTML export of a day's worth of events for 1 endpoint? HOT 2
- Kibana Container crash every few seconds HOT 6
- Update to 0.5: Unable to determine retention policy HOT 2
- 0.5 upgrade OK if fiddled with shards before? HOT 1
- Manually running a cleanup from ssh if GUI not accessible - space keeps running out HOT 1
- winlogbeat service does not start HOT 5
- [BUG] [!] LME Requires 90GB of space usable for log retention - exiting HOT 3
- [BUG] Disc space detection in deploy script has range of values it won't handle HOT 1
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from lme.