From 79b62e85290156e155dc9c77e7393b54c76ac704 Mon Sep 17 00:00:00 2001 From: rathbuna <36825567+rathbuna@users.noreply.github.com> Date: Fri, 15 Jan 2021 08:38:29 -0500 Subject: [PATCH] Create Microsoft-Windows-Ntfs-Operational_Microsoft-Windows-Ntfs_151.map --- ...Operational_Microsoft-Windows-Ntfs_151.map | 97 +++++++++++++++++++ 1 file changed, 97 insertions(+) create mode 100644 evtx/Maps/Microsoft-Windows-Ntfs-Operational_Microsoft-Windows-Ntfs_151.map diff --git a/evtx/Maps/Microsoft-Windows-Ntfs-Operational_Microsoft-Windows-Ntfs_151.map b/evtx/Maps/Microsoft-Windows-Ntfs-Operational_Microsoft-Windows-Ntfs_151.map new file mode 100644 index 00000000..bab0aba2 --- /dev/null +++ b/evtx/Maps/Microsoft-Windows-Ntfs-Operational_Microsoft-Windows-Ntfs_151.map @@ -0,0 +1,97 @@ +Author: Andrew Rathbun +Description: File deletion on an NTFS-formatted volume +EventId: 151 +Channel: "Microsoft-Windows-Ntfs/Operational" +Provider: "Microsoft-Windows-Ntfs" +Maps: + - + Property: ExecutableInfo + PropertyValue: "%ProcessName%" + Values: + - + Name: ProcessName + Value: "/Event/EventData/Data[@Name=\"ProcessName\"]" + - + Property: PayloadData1 + PropertyValue: "In the past %SecondsElapsed% seconds %TotalCountDeleteFile% files were deleted" + Values: + - + Name: SecondsElapsed + Value: "/Event/EventData/Data[@Name=\"SecondsElapsed\"]" + - + Name: TotalCountDeleteFile + Value: "/Event/EventData/Data[@Name=\"TotalCountDeleteFile\"]" + - + Property: PayloadData2 + PropertyValue: "%TotalCountDeleteFileLogged% of the deletions record their process name" + Values: + - + Name: TotalCountDeleteFileLogged + Value: "/Event/EventData/Data[@Name=\"TotalCountDeleteFileLogged\"]" + - + Property: PayloadData3 + PropertyValue: "%CountDeleteFile% files were deleted by %ProcessName%" + Values: + - + Name: CountDeleteFile + Value: "/Event/EventData/Data[@Name=\"CountDeleteFile\"]" + - + Name: ProcessName + Value: "/Event/EventData/Data[@Name=\"ProcessName\"]" + - + Property: PayloadData4 + PropertyValue: "VolumeName: %VolumeName%" + Values: + - + Name: VolumeName + Value: "/Event/EventData/Data[@Name=\"VolumeName\"]" + - + Property: PayloadData5 + PropertyValue: "IsBootVolume: %IsBootVolume%" + Values: + - + Name: IsBootVolume + Value: "/Event/EventData/Data[@Name=\"IsBootVolume\"]" + - + Property: PayloadData6 + PropertyValue: "VolumeCorrelationId: %VolumeCorrelationId%" + Values: + - + Name: VolumeCorrelationId + Value: "/Event/EventData/Data[@Name=\"VolumeCorrelationId\"]" + +# Documentation: +# https://github.com/Silv3rHorn/evtx2json/blob/master/resources/events.py#L1613 +# Appears to be only present in W10 2004+ +# +# Example Event Data: +# +# +# +# +# 151 +# 0 +# 4 +# 0 +# 0 +# 0x4000000000200000 +# +# 38 +# +# +# Microsoft-Windows-Ntfs/Operational +# HOSTNAME +# +# +# +# 5285666e-f228-11ea-9a5f-9c5c8ebbb369 +# 2 +# C: +# True +# 3601 +# 1963 +# 1963 +# MoUsoCoreWorke +# 2 +# +#