# Pre-built set of rules still using SYSMON based detection (winlogbeat- \*, event.code: 1, etc.) or using linguistic terms specific to an operating system (eg: Win 10 EN system user is SYSTEM, but Win 10 PT-BR system user is SISTEMA)

**URL:** <https://discuss.elastic.co/t/pre-built-set-of-rules-still-using-sysmon-based-detection-winlogbeat-event-code-1-etc-or-using-linguistic-terms-specific-to-an-operating-system-eg-win-10-en-system-user-is-system-but-win-10-pt-br-system-user-is-sistema/252933>\
**Category:** Endpoint Security\
**Created:** [October 22, 2020, 5:54am UTC](https://discuss.elastic.co/t/pre-built-set-of-rules-still-using-sysmon-based-detection-winlogbeat-event-code-1-etc-or-using-linguistic-terms-specific-to-an-operating-system-eg-win-10-en-system-user-is-system-but-win-10-pt-br-system-user-is-sistema/252933 "2020-10-22T05:54:20Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![skysbsb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skysbsb/32/72006_2.png) [@skysbsb](https://discuss.elastic.co/u/skysbsb)\
**Post date:** [October 22, 2020, 5:54am UTC](https://discuss.elastic.co/t/pre-built-set-of-rules-still-using-sysmon-based-detection-winlogbeat-event-code-1-etc-or-using-linguistic-terms-specific-to-an-operating-system-eg-win-10-en-system-user-is-system-but-win-10-pt-br-system-user-is-sistema/252933/1 "2020-10-22T05:54:21Z")

</div>

Pre-built set of rules still using SYSMON-based detection (winlogbeat- \*, event.code: 1, etc.) or using linguistic terms specific to an operating system (eg Win 10 EN system user is SYSTEM, but Win 10 PT-BR system user is "SISTEMA").

Attached evidence.  
With respect to using only the winlogbeat- \* index for some rules, it may make sense to review all the pre-built rules so that we can also use the Endpoint Agent index (logs-endpoint.events. \*) instead of just winlogbeat - \*.

Another thing is about rules that contain specific linguistic terms for a certain version of Windows: since Elastic has customers in several countries, it might be good to adapt the rules so that they are agnostic about the language. It may be possible to detect otherwise that a command was run with the SYSTEM user, without having to specifically compare the name of the user who ran the command. Perhaps the SID/GID would be the best option, or the token related to the process

I am using ELK 7.9.2..

.

 ![net](https://us1.discourse-cdn.com/elastic/original/3X/1/c/1c4d68e04a365e2b96b8b2b67d06445db409da7d.jpeg) ![whoami](https://us1.discourse-cdn.com/elastic/original/3X/a/3/a311f1e6dcec12414e3d5f45de545d1b3cafa731.jpeg)

---

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [November 3, 2020, 12:42am UTC](https://discuss.elastic.co/t/pre-built-set-of-rules-still-using-sysmon-based-detection-winlogbeat-event-code-1-etc-or-using-linguistic-terms-specific-to-an-operating-system-eg-win-10-en-system-user-is-system-but-win-10-pt-br-system-user-is-sistema/252933/2 "2020-11-03T00:42:25Z")

</div>

Sorry for a late reply,

I just stumbled on this and I should socialize this to a few people and see if they have seen this forum post yet or not. This looks like some valid questions and some interesting technical information and details about user based names.

So you know, the rules depot linked below is where all the feedback specific to rule content goes and they are pretty active on discussing and answering issues. You might do well creating an issue there about some of these things:

> **[elastic/detection-rules](https://github.com/elastic/detection-rules)**
>
> Rules for Elastic Security's detection engine. Contribute to elastic/detection-rules development by creating an account on GitHub.

> **[Build software better, together](https://github.com/elastic/detection-rules/issues/new/choose)**
>
> GitHub is where people build software. More than 50 million people use GitHub to discover, fork, and contribute to over 100 million projects.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 1, 2020, 12:42am UTC](https://discuss.elastic.co/t/pre-built-set-of-rules-still-using-sysmon-based-detection-winlogbeat-event-code-1-etc-or-using-linguistic-terms-specific-to-an-operating-system-eg-win-10-en-system-user-is-system-but-win-10-pt-br-system-user-is-sistema/252933/3 "2020-12-01T00:42:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
