Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 1edb002cfd
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| if (Get-WmiObject -Namespace $namespace -Class __EventFilter -Filter "Name = '$name'" -ErrorAction SilentlyContinue) { "filter:$name" } | ||
| if (Get-WmiObject -Namespace $namespace -Class CommandLineEventConsumer -Filter "Name = '$name'" -ErrorAction SilentlyContinue) { "consumer:$name" } |
There was a problem hiding this comment.
Fail cleanup when WMI verification queries error
If a final WMI query fails because the provider is unavailable, permissions changed, or the namespace cannot be queried, -ErrorAction SilentlyContinue converts that failure into an empty result, so $remaining stays empty and the script reports Clean=true even though the preceding removals may also have failed. For this persistence scenario, make the verification queries terminating or explicitly check their success before certifying cleanup.
Useful? React with 👍 / 👎.
| @@ -0,0 +1 @@ | |||
| search index=main source="WinEventLog:Microsoft-Windows-Sysmon/Operational" (_raw="*<EventID>19</EventID>*" OR _raw="*<EventID>20</EventID>*" OR _raw="*<EventID>21</EventID>*") (_raw="*<Data Name='Operation'>*Created*") AND ((_raw="*<Data Name='EventType'>*WmiFilterEvent*" OR _raw="*<Data Name='EventType'>*WmiConsumerEvent*" OR _raw="*<Data Name='EventType'>*WmiBindingEvent*")) | |||
There was a problem hiding this comment.
Bound Operation matching to its XML element
In the generated Mayuri live query, _raw="*<Data Name='Operation'>*Created*" does not require Created to be the value of Operation; it can occur in any later XML field. For example, a Sysmon Event 19 deletion whose filter name or WQL text contains Created will satisfy this clause and be reported as a creation, contrary to the Sigma rule and the negative deletion contract. Match Created before the corresponding </Data> boundary for exact-value fields.
Useful? React with 👍 / 👎.
Summary
3c64f177-28e2-49eb-a799-d767b24dd1e0on the approved Windows victimValidation
Safety and cleanup
notepad.exematches during the exact-positive windowREFERENCES OFqueries before consumers and filtersClean=trueReview