Brand new Windows 10 LTSC machine not even patched. Agent version 7.9.2 new policy named "For_You_Ferullo" with 1 agent named TESTBOX and Endpoint enabled. Minikatz downloaded and of course Chrome hates it and flags it so you have to allow. Windows defender disabled just to avoid it steeping in.
"Artifacts.cpp:2298 Failed to download artifact endpoint-exceptionlist-windows-v1 - Failure in an external software component"
{"@timestamp":"2020-10-02T00:22:41.78407700Z","agent":{"id":"5b1ac9c4-f401-4ad6-9586-6b7c8c124b05","type":"endpoint"},"ecs":{"version":"1.5.0"},"log":{"level":"error","origin":{"file":{"line":629,"name":"SyncKernelMessageManager.cpp"}}},"message":"SyncKernelMessageManager.cpp:629 Process ID 1608: [C:\mimikatz_trunk\x64\mimikatz.exe] is allowed due to message processing failure, error code -205","process":{"pid":8188,"thread":{"id":8548}}}
{"@timestamp":"2020-10-02T00:22:41.78407700Z","agent":{"id":"5b1ac9c4-f401-4ad6-9586-6b7c8c124b05","type":"endpoint"},"ecs":{"version":"1.5.0"},"log":{"level":"error","origin":{"file":{"line":629,"name":"SyncKernelMessageManager.cpp"}}},"message":"SyncKernelMessageManager.cpp:629 Process ID 1608: [C:\mimikatz_trunk\x64\mimikatz.exe] is allowed due to message processing failure, error code -205","process":{"pid":8188,"thread":{"id":8548}}}
{"@timestamp":"2020-10-02T00:22:41.72155100Z","agent":{"id":"5b1ac9c4-f401-4ad6-9586-6b7c8c124b05","type":"endpoint"},"ecs":{"version":"1.5.0"},"log":{"level":"info","origin":{"file":{"line":746,"name":"FileScore.cpp"}}},"message":"FileScore.cpp:746 Sending alert for [C:\mimikatz_trunk\x64\mimikatz.exe]","process":{"pid":8188,"thread":{"id":9056}}}
{"@timestamp":"2020-10-02T00:22:41.72155100Z","agent":{"id":"5b1ac9c4-f401-4ad6-9586-6b7c8c124b05","type":"endpoint"},"ecs":{"version":"1.5.0"},"log":{"level":"info","origin":{"file":{"line":746,"name":"FileScore.cpp"}}},"message":"FileScore.cpp:746 Sending alert for [C:\mimikatz_trunk\x64\mimikatz.exe]","process":{"pid":8188,"thread":{"id":9056}}}
{"@timestamp":"2020-10-02T00:23:11.79709900Z","agent":{"id":"5b1ac9c4-f401-4ad6-9586-6b7c8c124b05","type":"endpoint"},"ecs":{"version":"1.5.0"},"log":{"level":"error","origin":{"file":{"line":629,"name":"SyncKernelMessageManager.cpp"}}},"message":"SyncKernelMessageManager.cpp:629 Process ID 8616: [C:\mimikatz_trunk\x64\mimidrv.sys] is allowed due to message processing failure, error code -205","process":{"pid":8188,"thread":{"id":9056}}}
{"@timestamp":"2020-10-02T00:23:11.79709900Z","agent":{"id":"5b1ac9c4-f401-4ad6-9586-6b7c8c124b05","type":"endpoint"},"ecs":{"version":"1.5.0"},"log":{"level":"warning","origin":{"file":{"line":1047,"name":"Authenticode.cpp"}}},"message":"Authenticode.cpp:1047 WinVerifyTrust returned: 800b0101, errorExpired (C:\mimikatz_trunk\x64\mimidrv.sys)","process":{"pid":8188,"thread":{"id":4028}}}
{"@timestamp":"2020-10-02T00:23:11.95328800Z","agent":{"id":"5b1ac9c4-f401-4ad6-9586-6b7c8c124b05","type":"endpoint"},"ecs":{"version":"1.5.0"},"log":{"level":"info","origin":{"file":{"line":746,"name":"FileScore.cpp"}}},"message":"FileScore.cpp:746 Sending alert for [C:\mimikatz_trunk\x64\mimidrv.sys]","process":{"pid":8188,"thread":{"id":8548}}}
{"@timestamp":"2020-10-02T00:23:48.13958800Z","agent":{"id":"5b1ac9c4-f401-4ad6-9586-6b7c8c124b05","type":"endpoint"},"ecs":{"version":"1.5.0"},"log":{"level":"error","origin":{"file":{"line":629,"name":"SyncKernelMessageManager.cpp"}}},"message":"SyncKernelMessageManager.cpp:629 Process ID 8616: [C:\mimikatz_trunk\Win32\mimikatz.exe] is allowed due to message processing failure, error code -205","process":{"pid":8188,"thread":{"id":9056}}}
{"@timestamp":"2020-10-02T00:23:48.13958800Z","agent":{"id":"5b1ac9c4-f401-4ad6-9586-6b7c8c124b05","type":"endpoint"},"ecs":{"version":"1.5.0"},"log":{"level":"error","origin":{"file":{"line":629,"name":"SyncKernelMessageManager.cpp"}}},"message":"SyncKernelMessageManager.cpp:629 Process ID 8616: [C:\mimikatz_trunk\Win32\mimikatz.exe] is allowed due to message processing failure, error code -205","process":{"pid":8188,"thread":{"id":9056}}}
{"@timestamp":"2020-10-02T00:23:48.73626800Z","agent":{"id":"5b1ac9c4-f401-4ad6-9586-6b7c8c124b05","type":"endpoint"},"ecs":{"version":"1.5.0"},"log":{"level":"info","origin":{"file":{"line":746,"name":"FileScore.cpp"}}},"message":"FileScore.cpp:746 Sending alert for [C:\mimikatz_trunk\Win32\mimikatz.exe]","process":{"pid":8188,"thread":{"id":8548}}}
{"@timestamp":"2020-10-02T00:23:48.73626800Z","agent":{"id":"5b1ac9c4-f401-4ad6-9586-6b7c8c124b05","type":"endpoint"},"ecs":{"version":"1.5.0"},"log":{"level":"info","origin":{"file":{"line":746,"name":"FileScore.cpp"}}},"message":"FileScore.cpp:746 Sending alert for [C:\mimikatz_trunk\Win32\mimikatz.exe]","process":{"pid":8188,"thread":{"id":8548}}}
Free text search for mimikatz Kibana in the logs-* ends with 0 results which is already known as I'm not the only one missing the endpoint malware logs. I did a joke search for cute cat with no results.
0 alerts are triggered but that's expected as nothing for endpoint is sent. Filebeat and Metric beat logs are received with 0 issues. What I do find interesting is mimikatz process was killed and the exe deleted. Looking over the defender logs I did not see that it was the one that stopped it. So maybe 7.9.2 did. The only reference I have in any log in the lines above. Now to fix endpoint-exceptionlist-windows-v1 and the lack of any malware notices in Elastic.