diff --git a/hayabusa/builtin/Partition_Diagnostic/PartitionDiagnostic_1006_Info_DeviceConn.yml b/hayabusa/builtin/Partition_Diagnostic/PartitionDiagnostic_1006_Info_DeviceConn.yml new file mode 100644 index 000000000..d2eed3033 --- /dev/null +++ b/hayabusa/builtin/Partition_Diagnostic/PartitionDiagnostic_1006_Info_DeviceConn.yml @@ -0,0 +1,126 @@ +author: Zach Mathis, Fukusuke Takahashi +date: 2023/11/18 +modified: 2023/11/18 + +title: 'Device Conn' +details: 'Manufacturer: %Manufacturer% ¦ Model: %Model% ¦ Revision: %Revision% ¦ SerialNumber: %SerialNumber%' +description: 'Device is connected or disconnected' + +id: a6a0d64-75d1-433a-b415-4123bab080ec +level: informational +status: test +logsource: + product: windows +detection: + selection: + Channel: 'Microsoft-Windows-Partition/Diagnostic' + EventID: 1006 + condition: selection +falsepositives: + - normal system usage +tags: +references: +ruletype: Hayabusa + +sample-evtx: | + + + + 1006 + 4 + 4 + 0 + 0 + 0x8000000000000000 + + 51 + + + Microsoft-Windows-Partition/Diagnostic + mouse + + + + 0 + 538976528 + 256 + true + 0 + 0 + 0 + 512 + 512110190592 + 17 + NVMe + KINGSTON OM8PDP3512B-A01 + EDFK0S03 + 0026_B768_5D25_0F85. + Integrated : Bus 0 : Device 14 : Function 0 : Adapter 0 + PCI\VEN_8086&DEV_467F&SUBSYS_00008086&REV_00\3&11583659&1&70 + -1 + -1 + 0 + 14 + 0 + 0 + 2 + 0 + 0 + 59899 + 4 + {f0e437b2-048f-3a1b-f313-ec03b765eef9} + {a9786d92-695a-11ee-bdc1-806e6f6e6963} + {a9786d9c-695a-11ee-bdc1-806e6f6e6963} + {00000000-0000-0000-0000-000000000000} + false + 0 + 3 + 3 + 8 + 0 + 20 + 6575692E30303236423736383544323530463835 + 2 + 2 + 2 + 1 + true + false + false + 512 + 512 + 0 + false + true + false + 0 + 0 + 0 + 0 + 0 + 0 + 0 + false + 0 + 131072 + 33 + 3 + NULL + 1 + false + 1 + 4 + 624 + 0100000004000000C27D004ABF65964993881C82C54F5A51004400000000000000DA243C770000008000000000000000010000000000000000001000000000000000401000000000010000000000000028732AC11FF8D211BA4B00A0C93EC93BA243A9B085466D4896464BF59CD3A7FF00000000000000004500460049002000730079007300740065006D00200070006100720074006900740069006F006E000000000000000000000000000000000000000000000000000000000000000000010000000000000000005010000000000000000100000000020000000000000016E3C9E35C0BB84D817DF92DF00215AEFFE4DF5EC445EF42BBE1D1DD9EC0BF8A00000000000000004D006900630072006F0073006F0066007400200072006500730065007200760065006400200070006100720074006900740069006F006E0000000000000000000000000000000000010000000000000000005011000000000000D0AA760000000300000000000000A2A0D0EBE5B9334487C068B6B72699C7A7C45513316BA14380F4E35B98D9695F00000000000000004200610073006900630020006400610074006100200070006100720074006900740069006F006E0000000000000000000000000000000000000000000000000000000000000000000100000000000000000020BC7600000000000080000000000400000000000000A4BB94DED106404DA16ABFD50179D6AC932296802442A34D8ECA8ADCD4B8613501000000000000804200610073006900630020006400610074006100200070006100720074006900740069006F006E0000000000000000005FBC9D444C1F0000EA11B033FB7F00000900000000000000 + 0 + + 0 + + 0 + + 0 + + 0 + + + \ No newline at end of file