<?xml version="1.0"?>
<!--
=====================================================================
 Sysmon configuration derived from the LogMan.io Common Library ruleset
=====================================================================
 Source of requirements:
   - Detections/Sigma/windows/** : Windows Sigma detection rules
   - Correlations/Microsoft/Sysmon/* : Sysmon window correlations
   - Correlations/Advanced/* : chain correlations using Sysmon events
   - Correlations/Microsoft/Windows/Responder Machine Name Detected.yaml

 Design: EXCLUDE-based and deliberately conservative. Every event
 category the ruleset depends on stays enabled; only noise proven to
 be referenced as a false-positive filter by the ruleset itself is
 excluded. Do not add broad exclusions without checking rule
 dependencies. Most Sigma rules match on paths under C:\Windows,
 C:\Users and signed binaries.

 Install : sysmon64.exe -accepteula -i sysmon-config-lmio.xml
 Update  : sysmon64.exe -c sysmon-config-lmio.xml
 Requires Sysmon 15.x or newer (Event ID 29 FileExecutableDetected,
 schema 4.90). Event IDs 27/28 need Sysmon 14+.
 Channel forwarded to LogMan.io: Microsoft-Windows-Sysmon/Operational

 Documentation:
   https://docs.teskalabs.com/logman.io/collector/log-sources/microsoft/windows-events/sysmon/
=====================================================================
-->
<Sysmon schemaversion="4.90">

	<!-- Sigma rules match on Hashes and Imphash for EIDs 1/6/7/15.
	     All four algorithms must be present. -->
	<HashAlgorithms>md5,sha1,sha256,imphash</HashAlgorithms>

	<EventFiltering>

	<!-- ==========================================================
	EVENT ID 1: ProcessCreate. process_creation Sigma rules +
	Sysmon SP-Lang correlations.
	Fields used: CommandLine, Image, OriginalFileName, ParentImage,
	ParentCommandLine, Description, Product, Company, FileVersion,
	Hashes, Imphash, IntegrityLevel, User, CurrentDirectory, LogonId.
	No exclusions: the ruleset inspects every process, including
	signed system binaries (masquerading, LOLBin, path abuse).
	========================================================== -->
	<ProcessCreate onmatch="exclude">
		<!-- Keep empty = log all. If volume forces tuning, exclude only
		     high-frequency software that appears in no rule, measure,
		     then extend. Candidate categories (verify per environment):
		<Image condition="begin with">C:\Program Files\Google\Chrome\Application\</Image>
		<Image condition="begin with">C:\Program Files (x86)\Microsoft\Edge\Application\</Image>
		-->
	</ProcessCreate>

	<!-- ==========================================================
	EVENT ID 2: FileCreateTimeChanged. file_change rules.
	Fields: CreationUtcTime, PreviousCreationUtcTime, TargetFilename, Image.
	========================================================== -->
	<FileCreateTime onmatch="exclude">
	</FileCreateTime>

	<!-- ==========================================================
	EVENT ID 3: NetworkConnect. network_connection Sigma rules +
	Responder correlation (with EID 22 and Security 5156).
	Fields: Image, Initiated, DestinationHostname, DestinationIp,
	DestinationPort, SourceIp/Port, Protocol, CommandLine.
	Section must be present to enable connection logging (disabled by default).
	Loopback-only traffic excluded. The ruleset uses 127.0.0.1 only as a
	false-positive filter.
	========================================================== -->
	<NetworkConnect onmatch="exclude">
		<DestinationIp condition="is">127.0.0.1</DestinationIp>
		<DestinationIp condition="is">::1</DestinationIp>
		<!-- Optional noise reduction, verify first:
		<DestinationIp condition="start with">fe80:</DestinationIp>
		-->
	</NetworkConnect>

	<!-- ==========================================================
	EVENT ID 4 (service state) is not filterable and always emitted.
	Required by Sysmon configuration modification (status) rule.
	========================================================== -->

	<!-- ==========================================================
	EVENT ID 6: DriverLoad. Fields: ImageLoaded, Hashes, Imphash.
	========================================================== -->
	<DriverLoad onmatch="exclude">
	</DriverLoad>

	<!-- ==========================================================
	EVENT ID 7: ImageLoad. image_load Sigma rules +
	"Trojan Activity via File Download and Execution" correlation.
	Fields: ImageLoaded, Image, Signed, SignatureStatus, Signature,
	OriginalFileName, Hashes, Imphash.
	This category is OFF by default. The section must be present.
	VOLUME WARNING: full image-load logging is the single largest
	volume driver (can exceed process-create volume by 10-100x).
	Do not exclude signed Microsoft binaries: many rules assert
	Signed/SignatureStatus/OriginalFileName on system paths.
	========================================================== -->
	<ImageLoad onmatch="exclude">
		<!-- Keep empty = log all. Noise reduction options each cost
		     detection fidelity. Enable only after review:
		<Image condition="end with">\MsMpEng.exe</Image>
		-->
	</ImageLoad>

	<!-- ==========================================================
	EVENT ID 8: CreateRemoteThread.
	Fields: SourceImage, TargetImage, StartModule, StartFunction.
	========================================================== -->
	<CreateRemoteThread onmatch="exclude">
	</CreateRemoteThread>

	<!-- ==========================================================
	EVENT ID 9: RawAccessRead. Field: Image. Low volume; keep all.
	========================================================== -->
	<RawAccessRead onmatch="exclude">
	</RawAccessRead>

	<!-- ==========================================================
	EVENT ID 10: ProcessAccess.
	Fields: SourceImage, TargetImage, GrantedAccess, CallTrace.
	VOLUME WARNING: very high volume. Excluded sources below are
	filtered by the ruleset themselves (e.g. MsMpEng).
	========================================================== -->
	<ProcessAccess onmatch="exclude">
		<SourceImage condition="is">C:\Program Files\Windows Defender\MsMpEng.exe</SourceImage>
		<SourceImage condition="begin with">C:\ProgramData\Microsoft\Windows Defender\Platform\</SourceImage>
		<SourceImage condition="end with">\SearchIndexer.exe</SourceImage>
		<SourceImage condition="end with">\SecurityHealthService.exe</SourceImage>
		<!-- Do NOT exclude on GrantedAccess or TargetImage. Rules key on them. -->
	</ProcessAccess>

	<!-- ==========================================================
	EVENT ID 11: FileCreate. file_event Sigma rules + ransomware /
	trojan correlations.
	Fields: TargetFilename, Image, ParentImage, CommandLine.
	No exclusions: rules target temporary, download, startup, and
	service-staging paths.
	========================================================== -->
	<FileCreate onmatch="exclude">
	</FileCreate>

	<!-- ==========================================================
	EVENT ID 12/13/14: RegistryEvent. registry_set / registry_event /
	registry_add / registry_delete rules.
	Fields: TargetObject, Details, Image, EventType, NewName.
	No exclusions: persistence rules watch Run/IFEO/Service/Winlogon.
	========================================================== -->
	<RegistryEvent onmatch="exclude">
	</RegistryEvent>

	<!-- ==========================================================
	EVENT ID 15: FileCreateStreamHash. create_stream_hash rules.
	Fields: TargetFilename, Image, Contents (Zone.Identifier), Imphash.
	========================================================== -->
	<FileCreateStreamHash onmatch="exclude">
	</FileCreateStreamHash>

	<!-- ==========================================================
	EVENT ID 16: ServiceConfigurationChange. Always emitted,
	not filterable. Required by Sysmon configuration change rule.
	========================================================== -->

	<!-- ==========================================================
	EVENT ID 17/18: PipeEvent. pipe_created rules.
	Fields: PipeName, Image.
	Only Windows-internal system pipes excluded; \PSEXESVC and C2-style
	pipe names are detection targets and remain logged.
	========================================================== -->
	<PipeEvent onmatch="exclude">
		<PipeName condition="begin with">\Windows\</PipeName>
	</PipeEvent>

	<!-- ==========================================================
	EVENT ID 19/20/21: WmiEvent. wmi_event rules. Low volume.
	========================================================== -->
	<WmiEvent onmatch="exclude">
	</WmiEvent>

	<!-- ==========================================================
	EVENT ID 22: DnsQuery. dns_query rules + Responder correlation.
	Fields: QueryName, Image, QueryResults.
	========================================================== -->
	<DnsQuery onmatch="exclude">
	</DnsQuery>

	<!-- ==========================================================
	EVENT ID 23 / 26: FileDelete / FileDeleteDetected.
	file_delete rules (shadow copy, log deletion, ransomware).
	========================================================== -->
	<FileDelete onmatch="exclude">
	</FileDelete>
	<FileDeleteDetected onmatch="exclude">
	</FileDeleteDetected>

	<!-- ==========================================================
	EVENT ID 25: ProcessTampering. Fields: Image, Type.
	========================================================== -->
	<ProcessTampering onmatch="exclude">
	</ProcessTampering>

	<!-- ==========================================================
	EVENT ID 27 / 28: FileBlockExecutable / FileBlockShredding.
	PROTECTIVE features. Events appear only when protection is
	enabled, and enabling them BLOCKS matching files. Keep commented
	until you deliberately enable them. Until enabled, related Sigma
	rules stay dormant (no events to match).
	========================================================== -->
	<!--
	<FileBlockShredding onmatch="include">
		<TargetFilename condition="is">C:\Windows\Temp\*</TargetFilename>
		<TargetFilename condition="is">C:\Users\*\AppData\Local\Temp\*</TargetFilename>
	</FileBlockShredding>
	<FileBlockExecutable onmatch="include">
		<Image condition="end with">\winword.exe</Image>
		<Image condition="end with">\excel.exe</Image>
		<Image condition="end with">\powerpnt.exe</Image>
	</FileBlockExecutable>
	-->

	<!-- ==========================================================
	EVENT ID 29: FileExecutableDetected. Requires Sysmon >= 15.
	(EID 30 shares the same FileExecutableDetected config element;
	no separate configuration is needed.)
	========================================================== -->
	<FileExecutableDetected onmatch="exclude">
	</FileExecutableDetected>

	<!-- EID 5 (ProcessTerminate) and EID 24 (ClipboardChange) are not
	referenced by the LogMan.io Common Library ruleset; they stay at
	their defaults and need no configuration. -->

	</EventFiltering>
</Sysmon>
