23542300x800000000000000035789Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.local-2021-09-10 14:42:11.871{7BD73061-6E8E-613B-1107-00000000F001}4116NT AUTHORITY\SYSTEMC:\Windows\system32\msiexec.exeC:\Windows\assembly\temp\O4I2YE29AG\System.ComponentModel.Composition.ni.dll.auxMD5=694406FEC9A4D3335D220AADB0FA8797,SHA256=45E44499273F3E2F07640B16480103FEAE49022794D70F6B761C1B8A7D283CFD,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000035788Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.local-2021-09-10 14:42:11.871{7BD73061-6E8E-613B-1107-00000000F001}4116NT AUTHORITY\SYSTEMC:\Windows\system32\msiexec.exeC:\Windows\assembly\temp\O4I2YE29AG\System.ComponentModel.Composition.ni.dllMD5=0632FC2C8FE933134DC4039823BF7DDA,SHA256=65074EB6B679C8BEFA936EC373CCFDB9EAE1A71563936A3F77DDE751164D8143,IMPHASH=00000000000000000000000000000000truetrue 23542300x800000000000000035787Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.local-2021-09-10 14:42:11.824{7BD73061-6E8E-613B-1107-00000000F001}4116NT AUTHORITY\SYSTEMC:\Windows\system32\msiexec.exeC:\Windows\assembly\temp\NYU4M9NQO7\System.Drawing.ni.dll.auxMD5=AE1806558A5233CA0895E229CA9A5CDD,SHA256=BF8A1C5F9A51673F43C265FD747004440EA4B3BC1CE92378D2A9C6B197995F1D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000035786Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.local-2021-09-10 14:42:11.824{7BD73061-6E8E-613B-1107-00000000F001}4116NT AUTHORITY\SYSTEMC:\Windows\system32\msiexec.exeC:\Windows\assembly\temp\NYU4M9NQO7\System.Drawing.ni.dllMD5=FDBA63CB8F1C68D60D66AC4C25A52A2D,SHA256=9DFCA47793FC5BA5B8158ABB6E3487263E7967F0CD4533083D465AB38EA2018C,IMPHASH=00000000000000000000000000000000truetrue 23542300x800000000000000035785Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.local-2021-09-10 14:42:11.714{7BD73061-6E8E-613B-1107-00000000F001}4116NT AUTHORITY\SYSTEMC:\Windows\system32\msiexec.exeC:\Windows\assembly\temp\NVJRBVWD7A\System.Core.ni.dll.auxMD5=48FFD457B52D2283A43AAA2D8D7B2895,SHA256=529CDC113FC10D5542623FECA65BED08EF6A85D46AD9F372D32D25C91224FB54,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000035784Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.local-2021-09-10 14:42:11.714{7BD73061-6E8E-613B-1107-00000000F001}4116NT AUTHORITY\SYSTEMC:\Windows\system32\msiexec.exeC:\Windows\assembly\temp\NVJRBVWD7A\System.Core.ni.dllMD5=783B07F6DC4FEB9350CE7157E6240EA5,SHA256=A3CDC262830D14397834BF31D00E6F5179BFA6B9E570BD76C623E6033A0FF60D,IMPHASH=00000000000000000000000000000000truetrue 23542300x800000000000000035783Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.local-2021-09-10 14:42:11.371{7BD73061-6E8E-613B-1107-00000000F001}4116NT AUTHORITY\SYSTEMC:\Windows\system32\msiexec.exeC:\Windows\assembly\temp\NSCDQAJZZE\System.Data.ni.dll.auxMD5=CC9F9CB4F637C42741255EF17203B47C,SHA256=370A27D995B8AC7DEC609867B2B7BBEA89A465AB01320C77D7F8CB57793DC76B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000035782Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.local-2021-09-10 14:42:11.371{7BD73061-6E8E-613B-1107-00000000F001}4116NT AUTHORITY\SYSTEMC:\Windows\system32\msiexec.exeC:\Windows\assembly\temp\NSCDQAJZZE\System.Data.ni.dllMD5=4CE9DA541633C93EAE8D016C36CA6BF4,SHA256=08E8F1F9463152B6AABF02E6A7CB02A2DA4608AD745320837A9718B87B52AA29,IMPHASH=00000000000000000000000000000000truetrue 23542300x800000000000000035781Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.local-2021-09-10 14:42:11.339{7BD73061-665D-613B-E700-00000000F001}2764NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=99028A8592E4F9BD5383DE36046F77B2,SHA256=42776077032AA2F1591B39C47EB4B7FCD674EB28B9434080BCFF15F0EDE53F4F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000013423Microsoft-Windows-Sysmon/Operationalwin-host-166.attackrange.local-2021-09-10 14:42:11.022{625C326B-6888-613B-DB00-00000000F101}104NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E67C6429BE67F0366C3403800E6F6E15,SHA256=4C84149DA90468408BBDB771CF8997D916C9889967FE31474A62308E889F713F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000035780Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.local-2021-09-10 14:42:11.042{7BD73061-6E8E-613B-1107-00000000F001}4116NT AUTHORITY\SYSTEMC:\Windows\system32\msiexec.exeC:\Windows\assembly\temp\NO21KQA2HF\System.Configuration.Install.ni.dll.auxMD5=0CBC2C9737233F80F1C8DD57CE1AE88C,SHA256=6E18B2C2DFA32D6F4925D1BBE903FD9049472C36261FEBA8DD59628E8C6A9F30,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000035779Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.local-2021-09-10 14:42:11.042{7BD73061-6E8E-613B-1107-00000000F001}4116NT AUTHORITY\SYSTEMC:\Windows\system32\msiexec.exeC:\Windows\assembly\temp\NO21KQA2HF\System.Configuration.Install.ni.dllMD5=2582241664CA944A32E31176A66CF0C6,SHA256=B7C2F435943924E46E604D1D35C1835920CC706BF320D85179E53CA0F84354FF,IMPHASH=00000000000000000000000000000000truetrue 23542300x800000000000000035778Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.local-2021-09-10 14:42:11.027{7BD73061-6E8E-613B-1107-00000000F001}4116NT AUTHORITY\SYSTEMC:\Windows\system32\msiexec.exeC:\Windows\assembly\temp\NL4EC7YXBV\System.Data.ni.dll.auxMD5=EDB7CB075A217959013CD75CE405CCD2,SHA256=240A71F1AF20552B564ACE0F494BDFFCA2B3982D62D762D1E71E6E1535797972,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000035777Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.local-2021-09-10 14:42:11.027{7BD73061-6E8E-613B-1107-00000000F001}4116NT AUTHORITY\SYSTEMC:\Windows\system32\msiexec.exeC:\Windows\assembly\temp\NL4EC7YXBV\System.Data.ni.dllMD5=7ABB236413DDD5D4953BB3A2C663E53F,SHA256=D14A3A1F1851D9FD244CBF574F22A3B94B05FBBBC6147381E68F694AD59574E3,IMPHASH=00000000000000000000000000000000truetrue 354300x800000000000000035800Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.local-2021-09-10 14:42:10.428{7BD73061-6658-613B-DE00-00000000F001}3980C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-387.attackrange.local59190-false10.0.1.12-8000- 23542300x800000000000000035799Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.local-2021-09-10 14:42:12.761{7BD73061-665D-613B-E700-00000000F001}2764NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\ApplicationMD5=372ED2E333573FDB6830A52AF2E5A46E,SHA256=A4B4B8B22D7AE41243BD36AA1C2188E74D524F80C472165AD263B027E5FD8C03,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000035798Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.local-2021-09-10 14:42:12.730{7BD73061-6E8E-613B-1107-00000000F001}4116NT AUTHORITY\SYSTEMC:\Windows\system32\msiexec.exeC:\Windows\assembly\temp\OOS41VYSH3\System.DirectoryServices.ni.dll.auxMD5=5BE283A9E68591B32773566F147A211F,SHA256=83CFFD1BAEA158353574578F2145C054F207526C8E544F114652C4EF01713BAB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000035797Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.local-2021-09-10 14:42:12.730{7BD73061-6E8E-613B-1107-00000000F001}4116NT AUTHORITY\SYSTEMC:\Windows\system32\msiexec.exeC:\Windows\assembly\temp\OOS41VYSH3\System.DirectoryServices.ni.dllMD5=8CE05080E8212D45575DB5EC52382363,SHA256=B2960982ADB25974561E8356470B1234CDEC00F5FDBAFDC39F221B37F914433E,IMPHASH=00000000000000000000000000000000truetrue 23542300x800000000000000035796Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.local-2021-09-10 14:42:12.683{7BD73061-6E8E-613B-1107-00000000F001}4116NT AUTHORITY\SYSTEMC:\Windows\system32\msiexec.exeC:\Windows\assembly\temp\OFVXZGR1VK\System.ni.dll.auxMD5=F5E454AFEA99BF074A1D3313654C9C7C,SHA256=15FFAD8EC46C0265F01EE5C5891650A8C1D7D481080057D01EC1F0B597D009F2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000035795Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.local-2021-09-10 14:42:12.683{7BD73061-6E8E-613B-1107-00000000F001}4116NT AUTHORITY\SYSTEMC:\Windows\system32\msiexec.exeC:\Windows\assembly\temp\OFVXZGR1VK\System.ni.dllMD5=D60796FB70D97A574714D0C77F93D97D,SHA256=A1C4314F753DA4EE230B0AB995A4F9EC872F35780174F6E060A1DF56EBBBD6EF,IMPHASH=00000000000000000000000000000000truetrue 23542300x800000000000000035794Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.local-2021-09-10 14:42:12.371{7BD73061-665D-613B-E700-00000000F001}2764NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D5D1BE468C2540F497A0952C3A06EE66,SHA256=2BC681C4B5072557DBDE450BADDAF1E9274DC0F5E8A1DA2DC7627169AFEEA01E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000013424Microsoft-Windows-Sysmon/Operationalwin-host-166.attackrange.local-2021-09-10 14:42:12.038{625C326B-6888-613B-DB00-00000000F101}104NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=77964EE68C26A90DA46D80CD74C5DD92,SHA256=F019DD82BCC7DD365C96205AB7C2F955E19007DDAAF1EAF56B7D0995C37D72D6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000035793Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.local-2021-09-10 14:42:12.152{7BD73061-6E8E-613B-1107-00000000F001}4116NT AUTHORITY\SYSTEMC:\Windows\system32\msiexec.exeC:\Windows\assembly\temp\OD8WEIQHVA\System.Transactions.ni.dll.auxMD5=799D1D6903AEF7B551CD4A4C6B265AA9,SHA256=EAE828D0DC70B8C0CADC0F2FB1EB4DAB7A5E36C371C4B8A27C807DE7C0974339,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000035792Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.local-2021-09-10 14:42:12.152{7BD73061-6E8E-613B-1107-00000000F001}4116NT AUTHORITY\SYSTEMC:\Windows\system32\msiexec.exeC:\Windows\assembly\temp\OD8WEIQHVA\System.Transactions.ni.dllMD5=8D18FAAB7987602078CF848438C95F88,SHA256=AB760B68DE4E3D55C85FBC48423AC7C47C8A8C34FC3964E0473DA960D0BC3C5D,IMPHASH=00000000000000000000000000000000truetrue 23542300x800000000000000035791Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.local-2021-09-10 14:42:12.136{7BD73061-6E8E-613B-1107-00000000F001}4116NT AUTHORITY\SYSTEMC:\Windows\system32\msiexec.exeC:\Windows\assembly\temp\O8XCWSNQV8\System.Core.ni.dll.auxMD5=EB3705BF415BBFABE3EEF435BB9CAADD,SHA256=19E4BFB51F3918297F82E34403F9F1935B17BBC2A78E6C4247D6089C94C8BF15,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000035790Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.local-2021-09-10 14:42:12.136{7BD73061-6E8E-613B-1107-00000000F001}4116NT AUTHORITY\SYSTEMC:\Windows\system32\msiexec.exeC:\Windows\assembly\temp\O8XCWSNQV8\System.Core.ni.dllMD5=D34A762C6315A7E500BD3DC88FEDD43D,SHA256=80E62A15C9EB0FAB896B1D0A216D1C3AB4C103B8F957DB46C14E6DD9614D43FC,IMPHASH=00000000000000000000000000000000truetrue 23542300x800000000000000035814Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.local-2021-09-10 14:42:13.699{7BD73061-6E8E-613B-1107-00000000F001}4116NT AUTHORITY\SYSTEMC:\Windows\system32\msiexec.exeC:\Windows\assembly\temp\PC4QJUM510\System.Numerics.ni.dll.auxMD5=46C8A979AD3266DDEF725C7E593B0EC9,SHA256=44F41AE20DFD28ABE6EE0E04898C519AD9709FA50D948409B2ECD81BB20D3D37,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000035813Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.local-2021-09-10 14:42:13.683{7BD73061-6E8E-613B-1107-00000000F001}4116NT AUTHORITY\SYSTEMC:\Windows\system32\msiexec.exeC:\Windows\assembly\temp\PC4QJUM510\System.Numerics.ni.dllMD5=63A9B260BCFCC94E75F0B012DE2B32EF,SHA256=3BFD410197EBDCE1914F9CA077D5B2BE75A664A54D5D9B05169694327EC86CE3,IMPHASH=00000000000000000000000000000000truetrue 23542300x800000000000000035812Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.local-2021-09-10 14:42:13.683{7BD73061-6E8E-613B-1107-00000000F001}4116NT AUTHORITY\SYSTEMC:\Windows\system32\msiexec.exeC:\Windows\assembly\temp\P5RBFV7DTM\System.Management.ni.dll.auxMD5=9E113C3F173739443B36B19DD5C6669B,SHA256=E6D1A62EA7C191912AA011D805E8000EE89FE7281E888EF7A398F4FBA9AC4182,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000035811Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.local-2021-09-10 14:42:13.683{7BD73061-6E8E-613B-1107-00000000F001}4116NT AUTHORITY\SYSTEMC:\Windows\system32\msiexec.exeC:\Windows\assembly\temp\P5RBFV7DTM\System.Management.ni.dllMD5=545B093E8C7408982436090E8E13BA3C,SHA256=CFFD545D318D02B523B06E28AFD09A3649D013965B45986CFCAEE54A07AF0C1A,IMPHASH=00000000000000000000000000000000truetrue 23542300x800000000000000035810Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.local-2021-09-10 14:42:13.636{7BD73061-6E8E-613B-1107-00000000F001}4116NT AUTHORITY\SYSTEMC:\Windows\system32\msiexec.exeC:\Windows\assembly\temp\P3LFTWOA7M\System.Core.ni.dll.auxMD5=0B7B3547A6755335583D2C975D27717F,SHA256=CB5ECB0625E0E2D5C2A864279FFAFC96048F0E10B0A47437B6CA6D8FA2DAE6E9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000035809Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.local-2021-09-10 14:42:13.636{7BD73061-6E8E-613B-1107-00000000F001}4116NT AUTHORITY\SYSTEMC:\Windows\system32\msiexec.exeC:\Windows\assembly\temp\P3LFTWOA7M\System.Core.ni.dllMD5=90F0732AF7D2F9207DEA5BD7ECAD33B0,SHA256=C929FD867AE7413965067562351E1DFA8D05721D5A6151A3B575EB94B970F923,IMPHASH=00000000000000000000000000000000truetrue 23542300x800000000000000035808Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.local-2021-09-10 14:42:13.417{7BD73061-665D-613B-E700-00000000F001}2764NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4194144F61898BBF857C117ED3671C0E,SHA256=2DF7B9136FA8B800D7320BD3ADA1EF5081210B5D45909C1C1B2444C398F147B6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000013425Microsoft-Windows-Sysmon/Operationalwin-host-166.attackrange.local-2021-09-10 14:42:13.085{625C326B-6888-613B-DB00-00000000F101}104NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=98B13B6C3D9B809E4DA46608AE1D2DE0,SHA256=7554D079BC115C5F68652937CCCEBB7DEF9CBF680BE7DC684343CF4167ABE7C9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000035807Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.local-2021-09-10 14:42:13.261{7BD73061-6E8E-613B-1107-00000000F001}4116NT AUTHORITY\SYSTEMC:\Windows\system32\msiexec.exeC:\Windows\assembly\temp\P1WYFUDXSN\System.Security.ni.dll.auxMD5=74E5478F4A51B682700233CD6B7C05DC,SHA256=4BC93A21F6F5BE0B8E4ACFB6F96A6F3B1444A8310826E2CCC4DD8862E4D6F3E3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000035806Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.local-2021-09-10 14:42:13.261{7BD73061-6E8E-613B-1107-00000000F001}4116NT AUTHORITY\SYSTEMC:\Windows\system32\msiexec.exeC:\Windows\assembly\temp\P1WYFUDXSN\System.Security.ni.dllMD5=D518D6481A2B6037B8E61101718E6EB3,SHA256=154839515F16941BB2AB2FF9716A5CBCA5FECCD9CEAF9D0D51BA9797F3B98721,IMPHASH=00000000000000000000000000000000truetrue 23542300x800000000000000035805Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.local-2021-09-10 14:42:13.246{7BD73061-6E8E-613B-1107-00000000F001}4116NT AUTHORITY\SYSTEMC:\Windows\system32\msiexec.exeC:\Windows\assembly\temp\P0RK1OW14J\System.Configuration.ni.dll.auxMD5=F07B09293E0492E71E96C7A764BB524D,SHA256=A24285135DCD60675A12C5E36DF5B3FD7AEEEACFD305973C262A0C73053C7703,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000035804Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.local-2021-09-10 14:42:13.246{7BD73061-6E8E-613B-1107-00000000F001}4116NT AUTHORITY\SYSTEMC:\Windows\system32\msiexec.exeC:\Windows\assembly\temp\P0RK1OW14J\System.Configuration.ni.dllMD5=B0386808CBC978446F0D8638C53F9F02,SHA256=7E05166D981CF6FA3157EE088305E2B901B9721FCED6370E9D1CE7511A71AC64,IMPHASH=00000000000000000000000000000000truetrue 23542300x800000000000000035803Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.local-2021-09-10 14:42:13.167{7BD73061-6E8E-613B-1107-00000000F001}4116NT AUTHORITY\SYSTEMC:\Windows\system32\msiexec.exeC:\Windows\assembly\temp\OXYH1ETAXY\System.Core.ni.dll.auxMD5=5DCD12C73B9F94AD86DD5CCFF0961B76,SHA256=F48412CADA48829BCA494224CE73B46166853194748E6A93117C35D3A388A473,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000035802Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.local-2021-09-10 14:42:13.167{7BD73061-6E8E-613B-1107-00000000F001}4116NT AUTHORITY\SYSTEMC:\Windows\system32\msiexec.exeC:\Windows\assembly\temp\OXYH1ETAXY\System.Core.ni.dllMD5=0AA216B359BB985E91C06D6CEC347EF2,SHA256=5EDE9B67C3A3A41FCC240B0D7F27764343BD8C1BB1EAC39F441E00C6E5066C92,IMPHASH=00000000000000000000000000000000truetrue 10341000x800000000000000035801Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.local-2021-09-10 14:42:13.089{7BD73061-65B2-613B-0D00-00000000F001}8925164C:\Windows\system32\svchost.exe{7BD73061-65B2-613B-1600-00000000F001}1296C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+b4d7|c:\windows\system32\rpcss.dll+8257|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 13241300x800000000000000036425Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-fetch.exe|26836f160b2136d8\BinProductVersion2.33.0.2 13241300x800000000000000036424Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-fetch.exe|26836f160b2136d8\LinkDate08/24/2021 10:09:53 13241300x800000000000000036423Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-fetch.exe|26836f160b2136d8\Publisherthe git development community 13241300x800000000000000036422Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-fetch.exe|26836f160b2136d8\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-fetch.exe 13241300x800000000000000036421Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-fetch-pack.e|eaa13da8b960bb8f\BinProductVersion2.33.0.2 13241300x800000000000000036420Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-fetch-pack.e|eaa13da8b960bb8f\LinkDate08/24/2021 10:09:53 13241300x800000000000000036419Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-fetch-pack.e|eaa13da8b960bb8f\Publisherthe git development community 13241300x800000000000000036418Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-fetch-pack.e|eaa13da8b960bb8f\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-fetch-pack.exe 13241300x800000000000000036417Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-fast-import.|6e2bb2de2d0c9142\BinProductVersion2.33.0.2 13241300x800000000000000036416Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-fast-import.|6e2bb2de2d0c9142\LinkDate08/24/2021 10:09:53 13241300x800000000000000036415Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-fast-import.|6e2bb2de2d0c9142\Publisherthe git development community 13241300x800000000000000036414Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-fast-import.|6e2bb2de2d0c9142\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-fast-import.exe 13241300x800000000000000036413Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-fast-export.|a89216de984913cf\BinProductVersion2.33.0.2 13241300x800000000000000036412Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-fast-export.|a89216de984913cf\LinkDate08/24/2021 10:09:53 13241300x800000000000000036411Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-fast-export.|a89216de984913cf\Publisherthe git development community 13241300x800000000000000036410Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-fast-export.|a89216de984913cf\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-fast-export.exe 13241300x800000000000000036409Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-env--helper.|2c74ba6e4fc1d4ec\BinProductVersion2.33.0.2 13241300x800000000000000036408Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-env--helper.|2c74ba6e4fc1d4ec\LinkDate08/24/2021 10:09:53 13241300x800000000000000036407Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-env--helper.|2c74ba6e4fc1d4ec\Publisherthe git development community 13241300x800000000000000036406Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-env--helper.|2c74ba6e4fc1d4ec\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-env--helper.exe 13241300x800000000000000036405Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-difftool.exe|903a2ba27de6fa88\BinProductVersion2.33.0.2 13241300x800000000000000036404Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-difftool.exe|903a2ba27de6fa88\LinkDate08/24/2021 10:09:53 13241300x800000000000000036403Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-difftool.exe|903a2ba27de6fa88\Publisherthe git development community 13241300x800000000000000036402Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-difftool.exe|903a2ba27de6fa88\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-difftool.exe 13241300x800000000000000036401Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-diff.exe|fe3e1c9d29f52286\BinProductVersion2.33.0.2 13241300x800000000000000036400Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-diff.exe|fe3e1c9d29f52286\LinkDate08/24/2021 10:09:53 13241300x800000000000000036399Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-diff.exe|fe3e1c9d29f52286\Publisherthe git development community 13241300x800000000000000036398Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-diff.exe|fe3e1c9d29f52286\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-diff.exe 13241300x800000000000000036397Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-diff-tree.ex|d17f2f481ab32d12\BinProductVersion2.33.0.2 13241300x800000000000000036396Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-diff-tree.ex|d17f2f481ab32d12\LinkDate08/24/2021 10:09:53 13241300x800000000000000036395Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-diff-tree.ex|d17f2f481ab32d12\Publisherthe git development community 13241300x800000000000000036394Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-diff-tree.ex|d17f2f481ab32d12\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-diff-tree.exe 13241300x800000000000000036393Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-diff-index.e|3e5a108a9f567115\BinProductVersion2.33.0.2 13241300x800000000000000036392Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-diff-index.e|3e5a108a9f567115\LinkDate08/24/2021 10:09:53 13241300x800000000000000036391Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-diff-index.e|3e5a108a9f567115\Publisherthe git development community 13241300x800000000000000036390Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-diff-index.e|3e5a108a9f567115\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-diff-index.exe 13241300x800000000000000036389Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-diff-files.e|4b52f8fbf7fa68d0\BinProductVersion2.33.0.2 13241300x800000000000000036388Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-diff-files.e|4b52f8fbf7fa68d0\LinkDate08/24/2021 10:09:53 13241300x800000000000000036387Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-diff-files.e|4b52f8fbf7fa68d0\Publisherthe git development community 13241300x800000000000000036386Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-diff-files.e|4b52f8fbf7fa68d0\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-diff-files.exe 13241300x800000000000000036385Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-describe.exe|ca93040df5afaed5\BinProductVersion2.33.0.2 13241300x800000000000000036384Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-describe.exe|ca93040df5afaed5\LinkDate08/24/2021 10:09:53 13241300x800000000000000036383Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-describe.exe|ca93040df5afaed5\Publisherthe git development community 13241300x800000000000000036382Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-describe.exe|ca93040df5afaed5\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-describe.exe 13241300x800000000000000036381Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-daemon.exe|4df8efdd24573ae6\BinProductVersion2.33.0.2 13241300x800000000000000036380Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-daemon.exe|4df8efdd24573ae6\LinkDate08/24/2021 10:09:53 13241300x800000000000000036379Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-daemon.exe|4df8efdd24573ae6\Publisherthe git development community 13241300x800000000000000036378Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-daemon.exe|4df8efdd24573ae6\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-daemon.exe 13241300x800000000000000036377Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-credential.e|7fcfd8585219b3da\BinProductVersion2.33.0.2 13241300x800000000000000036376Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-credential.e|7fcfd8585219b3da\LinkDate08/24/2021 10:09:53 13241300x800000000000000036375Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-credential.e|7fcfd8585219b3da\Publisherthe git development community 13241300x800000000000000036374Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-credential.e|7fcfd8585219b3da\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-credential.exe 13241300x800000000000000036373Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-credential-w|dd4fe27e45e1fd6b\BinProductVersion(Empty) 13241300x800000000000000036372Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-credential-w|dd4fe27e45e1fd6b\LinkDate08/24/2021 10:09:53 13241300x800000000000000036371Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-credential-w|dd4fe27e45e1fd6b\Publisher(Empty) 13241300x800000000000000036370Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-credential-w|dd4fe27e45e1fd6b\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-credential-wincred.exe 13241300x800000000000000036369Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-credential-s|f72ca269558b1404\BinProductVersion2.33.0.2 13241300x800000000000000036368Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-credential-s|f72ca269558b1404\LinkDate08/24/2021 10:09:53 13241300x800000000000000036367Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-credential-s|f72ca269558b1404\Publisherthe git development community 13241300x800000000000000036366Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-credential-s|f72ca269558b1404\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-credential-store.exe 13241300x800000000000000036365Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-credential-m|55d73dc387b631bc\BinProductVersion1.20.0.0 13241300x800000000000000036364Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-credential-m|55d73dc387b631bc\LinkDate09/05/2019 15:02:13 13241300x800000000000000036363Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-credential-m|55d73dc387b631bc\Publishermicrosoft corporation 13241300x800000000000000036362Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-credential-m|55d73dc387b631bc\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-credential-manager.exe 13241300x800000000000000036361Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-credential-m|425ee5c501baf173\BinProductVersion2.0.498.0 13241300x800000000000000036360Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-credential-m|425ee5c501baf173\LinkDate09/05/2039 11:03:58 13241300x800000000000000036359Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-credential-m|425ee5c501baf173\Publishergit-credential-manager-core 13241300x800000000000000036358Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-credential-m|425ee5c501baf173\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-credential-manager-core.exe 13241300x800000000000000036357Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-credential-h|e6dcddb0bd298778\BinProductVersion(Empty) 13241300x800000000000000036356Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-credential-h|e6dcddb0bd298778\LinkDate01/01/1970 00:00:00 13241300x800000000000000036355Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-credential-h|e6dcddb0bd298778\Publisher(Empty) 13241300x800000000000000036354Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-credential-h|e6dcddb0bd298778\LowerCaseLongPathc:\program files\git\mingw64\bin\git-credential-helper-selector.exe 13241300x800000000000000036353Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-credential-c|2da56af252cfcd16\BinProductVersion2.33.0.2 13241300x800000000000000036352Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-credential-c|2da56af252cfcd16\LinkDate08/24/2021 10:09:53 13241300x800000000000000036351Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-credential-c|2da56af252cfcd16\Publisherthe git development community 13241300x800000000000000036350Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-credential-c|2da56af252cfcd16\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-credential-cache.exe 13241300x800000000000000036349Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-credential-c|17175c202eed73b7\BinProductVersion2.33.0.2 13241300x800000000000000036348Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-credential-c|17175c202eed73b7\LinkDate08/24/2021 10:09:53 13241300x800000000000000036347Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-credential-c|17175c202eed73b7\Publisherthe git development community 13241300x800000000000000036346Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-credential-c|17175c202eed73b7\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-credential-cache--daemon.exe 13241300x800000000000000036345Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-count-object|9f950d53a6a442ff\BinProductVersion2.33.0.2 13241300x800000000000000036344Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-count-object|9f950d53a6a442ff\LinkDate08/24/2021 10:09:53 13241300x800000000000000036343Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-count-object|9f950d53a6a442ff\Publisherthe git development community 13241300x800000000000000036342Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-count-object|9f950d53a6a442ff\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-count-objects.exe 13241300x800000000000000036341Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-config.exe|e75be4b0a6770696\BinProductVersion2.33.0.2 13241300x800000000000000036340Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-config.exe|e75be4b0a6770696\LinkDate08/24/2021 10:09:53 13241300x800000000000000036339Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-config.exe|e75be4b0a6770696\Publisherthe git development community 13241300x800000000000000036338Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-config.exe|e75be4b0a6770696\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-config.exe 13241300x800000000000000036337Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-commit.exe|6e74d5dae67b444b\BinProductVersion2.33.0.2 13241300x800000000000000036336Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-commit.exe|6e74d5dae67b444b\LinkDate08/24/2021 10:09:53 13241300x800000000000000036335Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-commit.exe|6e74d5dae67b444b\Publisherthe git development community 13241300x800000000000000036334Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-commit.exe|6e74d5dae67b444b\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-commit.exe 13241300x800000000000000036333Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-commit-tree.|e83233ce3cd9ee79\BinProductVersion2.33.0.2 13241300x800000000000000036332Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-commit-tree.|e83233ce3cd9ee79\LinkDate08/24/2021 10:09:53 13241300x800000000000000036331Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-commit-tree.|e83233ce3cd9ee79\Publisherthe git development community 13241300x800000000000000036330Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-commit-tree.|e83233ce3cd9ee79\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-commit-tree.exe 13241300x800000000000000036329Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-commit-graph|d249b2d5436de447\BinProductVersion2.33.0.2 13241300x800000000000000036328Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-commit-graph|d249b2d5436de447\LinkDate08/24/2021 10:09:53 13241300x800000000000000036327Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-commit-graph|d249b2d5436de447\Publisherthe git development community 13241300x800000000000000036326Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-commit-graph|d249b2d5436de447\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-commit-graph.exe 13241300x800000000000000036325Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-column.exe|218c406abdb7f5d8\BinProductVersion2.33.0.2 13241300x800000000000000036324Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-column.exe|218c406abdb7f5d8\LinkDate08/24/2021 10:09:53 13241300x800000000000000036323Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-column.exe|218c406abdb7f5d8\Publisherthe git development community 13241300x800000000000000036322Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-column.exe|218c406abdb7f5d8\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-column.exe 13241300x800000000000000036321Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-cmd.exe|7955156508a74f3e\BinProductVersion2.33.0.2 13241300x800000000000000036320Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-cmd.exe|7955156508a74f3e\LinkDate08/24/2021 10:09:53 13241300x800000000000000036319Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-cmd.exe|7955156508a74f3e\Publisherthe git development community 13241300x800000000000000036318Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-cmd.exe|7955156508a74f3e\LowerCaseLongPathc:\program files\git\git-cmd.exe 13241300x800000000000000036317Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-clone.exe|d02aef8e1b723e2e\BinProductVersion2.33.0.2 13241300x800000000000000036316Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-clone.exe|d02aef8e1b723e2e\LinkDate08/24/2021 10:09:53 13241300x800000000000000036315Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-clone.exe|d02aef8e1b723e2e\Publisherthe git development community 13241300x800000000000000036314Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-clone.exe|d02aef8e1b723e2e\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-clone.exe 13241300x800000000000000036313Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-clean.exe|d4eb9fccf53085a4\BinProductVersion2.33.0.2 13241300x800000000000000036312Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-clean.exe|d4eb9fccf53085a4\LinkDate08/24/2021 10:09:53 13241300x800000000000000036311Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-clean.exe|d4eb9fccf53085a4\Publisherthe git development community 13241300x800000000000000036310Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-clean.exe|d4eb9fccf53085a4\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-clean.exe 13241300x800000000000000036309Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-cherry.exe|e775100e4df4ef32\BinProductVersion2.33.0.2 13241300x800000000000000036308Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-cherry.exe|e775100e4df4ef32\LinkDate08/24/2021 10:09:53 13241300x800000000000000036307Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-cherry.exe|e775100e4df4ef32\Publisherthe git development community 13241300x800000000000000036306Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-cherry.exe|e775100e4df4ef32\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-cherry.exe 13241300x800000000000000036305Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-cherry-pick.|997eacdc80577639\BinProductVersion2.33.0.2 13241300x800000000000000036304Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-cherry-pick.|997eacdc80577639\LinkDate08/24/2021 10:09:53 13241300x800000000000000036303Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-cherry-pick.|997eacdc80577639\Publisherthe git development community 13241300x800000000000000036302Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-cherry-pick.|997eacdc80577639\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-cherry-pick.exe 13241300x800000000000000036301Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-checkout.exe|76b55428c67a380b\BinProductVersion2.33.0.2 13241300x800000000000000036300Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-checkout.exe|76b55428c67a380b\LinkDate08/24/2021 10:09:53 13241300x800000000000000036299Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-checkout.exe|76b55428c67a380b\Publisherthe git development community 13241300x800000000000000036298Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-checkout.exe|76b55428c67a380b\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-checkout.exe 13241300x800000000000000036297Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-checkout-ind|7b051b3e6750a804\BinProductVersion2.33.0.2 13241300x800000000000000036296Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-checkout-ind|7b051b3e6750a804\LinkDate08/24/2021 10:09:53 13241300x800000000000000036295Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-checkout-ind|7b051b3e6750a804\Publisherthe git development community 13241300x800000000000000036294Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-checkout-ind|7b051b3e6750a804\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-checkout-index.exe 13241300x800000000000000036293Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-checkout--wo|5e17ac3afeabc004\BinProductVersion2.33.0.2 13241300x800000000000000036292Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-checkout--wo|5e17ac3afeabc004\LinkDate08/24/2021 10:09:53 13241300x800000000000000036291Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-checkout--wo|5e17ac3afeabc004\Publisherthe git development community 13241300x800000000000000036290Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-checkout--wo|5e17ac3afeabc004\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-checkout--worker.exe 13241300x800000000000000036289Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-check-ref-fo|4c4aae0ebfb00b85\BinProductVersion2.33.0.2 13241300x800000000000000036288Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-check-ref-fo|4c4aae0ebfb00b85\LinkDate08/24/2021 10:09:53 13241300x800000000000000036287Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-check-ref-fo|4c4aae0ebfb00b85\Publisherthe git development community 13241300x800000000000000036286Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-check-ref-fo|4c4aae0ebfb00b85\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-check-ref-format.exe 13241300x800000000000000036285Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-check-mailma|ed52c712797b00dc\BinProductVersion2.33.0.2 13241300x800000000000000036284Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-check-mailma|ed52c712797b00dc\LinkDate08/24/2021 10:09:53 13241300x800000000000000036283Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-check-mailma|ed52c712797b00dc\Publisherthe git development community 13241300x800000000000000036282Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-check-mailma|ed52c712797b00dc\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-check-mailmap.exe 13241300x800000000000000036281Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-check-ignore|9bc04723247ac2dd\BinProductVersion2.33.0.2 13241300x800000000000000036280Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-check-ignore|9bc04723247ac2dd\LinkDate08/24/2021 10:09:53 13241300x800000000000000036279Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-check-ignore|9bc04723247ac2dd\Publisherthe git development community 13241300x800000000000000036278Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-check-ignore|9bc04723247ac2dd\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-check-ignore.exe 13241300x800000000000000036277Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-check-attr.e|57c1145da335bf27\BinProductVersion2.33.0.2 13241300x800000000000000036276Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-check-attr.e|57c1145da335bf27\LinkDate08/24/2021 10:09:53 13241300x800000000000000036275Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-check-attr.e|57c1145da335bf27\Publisherthe git development community 13241300x800000000000000036274Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-check-attr.e|57c1145da335bf27\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-check-attr.exe 13241300x800000000000000036273Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-cat-file.exe|d0e6669a50eba4df\BinProductVersion2.33.0.2 13241300x800000000000000036272Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-cat-file.exe|d0e6669a50eba4df\LinkDate08/24/2021 10:09:53 13241300x800000000000000036271Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-cat-file.exe|d0e6669a50eba4df\Publisherthe git development community 13241300x800000000000000036270Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.292{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-cat-file.exe|d0e6669a50eba4df\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-cat-file.exe 13241300x800000000000000036269Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-bundle.exe|fac576bd3a94d60b\BinProductVersion2.33.0.2 13241300x800000000000000036268Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-bundle.exe|fac576bd3a94d60b\LinkDate08/24/2021 10:09:53 13241300x800000000000000036267Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-bundle.exe|fac576bd3a94d60b\Publisherthe git development community 13241300x800000000000000036266Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-bundle.exe|fac576bd3a94d60b\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-bundle.exe 13241300x800000000000000036265Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-bugreport.ex|59a0df6a91883120\BinProductVersion2.33.0.2 13241300x800000000000000036264Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-bugreport.ex|59a0df6a91883120\LinkDate08/24/2021 10:09:53 13241300x800000000000000036263Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-bugreport.ex|59a0df6a91883120\Publisherthe git development community 13241300x800000000000000036262Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-bugreport.ex|59a0df6a91883120\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-bugreport.exe 13241300x800000000000000036261Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-branch.exe|60e03a3ca4e1184b\BinProductVersion2.33.0.2 13241300x800000000000000036260Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-branch.exe|60e03a3ca4e1184b\LinkDate08/24/2021 10:09:53 13241300x800000000000000036259Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-branch.exe|60e03a3ca4e1184b\Publisherthe git development community 13241300x800000000000000036258Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-branch.exe|60e03a3ca4e1184b\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-branch.exe 13241300x800000000000000036257Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-blame.exe|695e1b21d217f64a\BinProductVersion2.33.0.2 13241300x800000000000000036256Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-blame.exe|695e1b21d217f64a\LinkDate08/24/2021 10:09:53 13241300x800000000000000036255Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-blame.exe|695e1b21d217f64a\Publisherthe git development community 13241300x800000000000000036254Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-blame.exe|695e1b21d217f64a\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-blame.exe 13241300x800000000000000036253Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-bisect--help|2b85661c358f83f3\BinProductVersion2.33.0.2 13241300x800000000000000036252Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-bisect--help|2b85661c358f83f3\LinkDate08/24/2021 10:09:53 13241300x800000000000000036251Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-bisect--help|2b85661c358f83f3\Publisherthe git development community 13241300x800000000000000036250Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-bisect--help|2b85661c358f83f3\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-bisect--helper.exe 13241300x800000000000000036249Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-bash.exe|bb55e09d0018cc9\BinProductVersion2.33.0.2 13241300x800000000000000036248Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-bash.exe|bb55e09d0018cc9\LinkDate08/24/2021 10:09:53 13241300x800000000000000036247Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-bash.exe|bb55e09d0018cc9\Publisherthe git development community 13241300x800000000000000036246Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-bash.exe|bb55e09d0018cc9\LowerCaseLongPathc:\program files\git\git-bash.exe 13241300x800000000000000036245Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-askyesno.exe|307382c653791a6b\BinProductVersion(Empty) 13241300x800000000000000036244Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-askyesno.exe|307382c653791a6b\LinkDate01/01/1970 00:00:00 13241300x800000000000000036243Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-askyesno.exe|307382c653791a6b\Publisher(Empty) 13241300x800000000000000036242Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-askyesno.exe|307382c653791a6b\LowerCaseLongPathc:\program files\git\mingw64\bin\git-askyesno.exe 13241300x800000000000000036241Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-askpass.exe|e2b400b31b8b5d22\BinProductVersion(Empty) 13241300x800000000000000036240Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-askpass.exe|e2b400b31b8b5d22\LinkDate01/01/1970 00:00:00 13241300x800000000000000036239Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-askpass.exe|e2b400b31b8b5d22\Publisher(Empty) 13241300x800000000000000036238Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-askpass.exe|e2b400b31b8b5d22\LowerCaseLongPathc:\program files\git\mingw64\bin\git-askpass.exe 13241300x800000000000000036237Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-askpass.exe|ac0f34128b42387d\BinProductVersion1.20.0.0 13241300x800000000000000036236Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-askpass.exe|ac0f34128b42387d\LinkDate09/06/2019 12:59:42 13241300x800000000000000036235Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-askpass.exe|ac0f34128b42387d\Publishermicrosoft corporation 13241300x800000000000000036234Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-askpass.exe|ac0f34128b42387d\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-askpass.exe 13241300x800000000000000036233Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-archive.exe|36a80009064dc962\BinProductVersion2.33.0.2 13241300x800000000000000036232Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-archive.exe|36a80009064dc962\LinkDate08/24/2021 10:09:53 13241300x800000000000000036231Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-archive.exe|36a80009064dc962\Publisherthe git development community 13241300x800000000000000036230Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-archive.exe|36a80009064dc962\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-archive.exe 13241300x800000000000000036229Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-apply.exe|12e49d92e436268f\BinProductVersion2.33.0.2 13241300x800000000000000036228Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-apply.exe|12e49d92e436268f\LinkDate08/24/2021 10:09:53 13241300x800000000000000036227Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-apply.exe|12e49d92e436268f\Publisherthe git development community 13241300x800000000000000036226Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-apply.exe|12e49d92e436268f\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-apply.exe 13241300x800000000000000036225Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-annotate.exe|a44a56d360566d96\BinProductVersion2.33.0.2 13241300x800000000000000036224Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-annotate.exe|a44a56d360566d96\LinkDate08/24/2021 10:09:53 13241300x800000000000000036223Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-annotate.exe|a44a56d360566d96\Publisherthe git development community 13241300x800000000000000036222Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-annotate.exe|a44a56d360566d96\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-annotate.exe 13241300x800000000000000036221Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-am.exe|4f482c30f10b83a7\BinProductVersion2.33.0.2 13241300x800000000000000036220Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-am.exe|4f482c30f10b83a7\LinkDate08/24/2021 10:09:53 13241300x800000000000000036219Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-am.exe|4f482c30f10b83a7\Publisherthe git development community 13241300x800000000000000036218Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-am.exe|4f482c30f10b83a7\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-am.exe 13241300x800000000000000036217Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-add.exe|cbf55eec74d083b3\BinProductVersion2.33.0.2 13241300x800000000000000036216Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-add.exe|cbf55eec74d083b3\LinkDate08/24/2021 10:09:53 13241300x800000000000000036215Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-add.exe|cbf55eec74d083b3\Publisherthe git development community 13241300x800000000000000036214Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\git-add.exe|cbf55eec74d083b3\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-add.exe 13241300x800000000000000036213Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\gio-querymodules|c9cec5f8077b3334\BinProductVersion(Empty) 13241300x800000000000000036212Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\gio-querymodules|c9cec5f8077b3334\LinkDate01/01/1970 00:00:00 13241300x800000000000000036211Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\gio-querymodules|c9cec5f8077b3334\Publisher(Empty) 13241300x800000000000000036210Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\gio-querymodules|c9cec5f8077b3334\LowerCaseLongPathc:\program files\git\usr\bin\gio-querymodules.exe 13241300x800000000000000036209Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\gettext.exe|8596cb6c6d32afb4\BinProductVersion0.19.8.0 13241300x800000000000000036208Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\gettext.exe|8596cb6c6d32afb4\LinkDate01/01/1970 04:44:00 13241300x800000000000000036207Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\gettext.exe|8596cb6c6d32afb4\Publisherfree software foundation 13241300x800000000000000036206Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\gettext.exe|8596cb6c6d32afb4\LowerCaseLongPathc:\program files\git\usr\bin\gettext.exe 13241300x800000000000000036205Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\gettext.exe|3980488749a39656\BinProductVersion0.19.8.0 13241300x800000000000000036204Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\gettext.exe|3980488749a39656\LinkDate01/01/1970 00:00:00 13241300x800000000000000036203Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\gettext.exe|3980488749a39656\Publisherfree software foundation 13241300x800000000000000036202Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\gettext.exe|3980488749a39656\LowerCaseLongPathc:\program files\git\mingw64\bin\gettext.exe 13241300x800000000000000036201Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\getprocaddr64.ex|683e30977215239e\BinProductVersion(Empty) 13241300x800000000000000036200Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\getprocaddr64.ex|683e30977215239e\LinkDate03/26/2021 22:24:41 13241300x800000000000000036199Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\getprocaddr64.ex|683e30977215239e\Publisher(Empty) 13241300x800000000000000036198Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\getprocaddr64.ex|683e30977215239e\LowerCaseLongPathc:\program files\git\usr\libexec\getprocaddr64.exe 13241300x800000000000000036197Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\getprocaddr32.ex|11de5925d9c6baa7\BinProductVersion(Empty) 13241300x800000000000000036196Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\getprocaddr32.ex|11de5925d9c6baa7\LinkDate03/26/2021 22:24:41 13241300x800000000000000036195Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\getprocaddr32.ex|11de5925d9c6baa7\Publisher(Empty) 13241300x800000000000000036194Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\getprocaddr32.ex|11de5925d9c6baa7\LowerCaseLongPathc:\program files\git\usr\libexec\getprocaddr32.exe 13241300x800000000000000036193Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\getopt.exe|b37205341d75e599\BinProductVersion(Empty) 13241300x800000000000000036192Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\getopt.exe|b37205341d75e599\LinkDate01/01/1970 00:00:00 13241300x800000000000000036191Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\getopt.exe|b37205341d75e599\Publisher(Empty) 13241300x800000000000000036190Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\getopt.exe|b37205341d75e599\LowerCaseLongPathc:\program files\git\usr\bin\getopt.exe 13241300x800000000000000036189Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\getfacl.exe|69b0f93924f494f7\BinProductVersion(Empty) 13241300x800000000000000036188Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\getfacl.exe|69b0f93924f494f7\LinkDate03/26/2021 22:24:39 13241300x800000000000000036187Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\getfacl.exe|69b0f93924f494f7\Publisher(Empty) 13241300x800000000000000036186Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\getfacl.exe|69b0f93924f494f7\LowerCaseLongPathc:\program files\git\usr\bin\getfacl.exe 13241300x800000000000000036185Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\getconf.exe|c7f6d864684a6d19\BinProductVersion(Empty) 13241300x800000000000000036184Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\getconf.exe|c7f6d864684a6d19\LinkDate03/26/2021 22:24:39 13241300x800000000000000036183Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\getconf.exe|c7f6d864684a6d19\Publisher(Empty) 13241300x800000000000000036182Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\getconf.exe|c7f6d864684a6d19\LowerCaseLongPathc:\program files\git\usr\bin\getconf.exe 13241300x800000000000000036181Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\gencat.exe|89f29a911ad31f09\BinProductVersion(Empty) 13241300x800000000000000036180Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\gencat.exe|89f29a911ad31f09\LinkDate03/26/2021 22:24:39 13241300x800000000000000036179Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\gencat.exe|89f29a911ad31f09\Publisher(Empty) 13241300x800000000000000036178Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\gencat.exe|89f29a911ad31f09\LowerCaseLongPathc:\program files\git\usr\bin\gencat.exe 13241300x800000000000000036177Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\gdbus.exe|bf2693ac7275e90\BinProductVersion(Empty) 13241300x800000000000000036176Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\gdbus.exe|bf2693ac7275e90\LinkDate01/01/1970 00:00:00 13241300x800000000000000036175Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\gdbus.exe|bf2693ac7275e90\Publisher(Empty) 13241300x800000000000000036174Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\gdbus.exe|bf2693ac7275e90\LowerCaseLongPathc:\program files\git\usr\bin\gdbus.exe 13241300x800000000000000036173Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\gawk.exe|33613608746cae13\BinProductVersion(Empty) 13241300x800000000000000036172Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\gawk.exe|33613608746cae13\LinkDate01/01/1970 00:00:00 13241300x800000000000000036171Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\gawk.exe|33613608746cae13\Publisher(Empty) 13241300x800000000000000036170Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\gawk.exe|33613608746cae13\LowerCaseLongPathc:\program files\git\usr\bin\gawk.exe 13241300x800000000000000036169Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\gawk-5.0.0.exe|709e9d005b0b4928\BinProductVersion(Empty) 13241300x800000000000000036168Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\gawk-5.0.0.exe|709e9d005b0b4928\LinkDate01/01/1970 00:00:00 13241300x800000000000000036167Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\gawk-5.0.0.exe|709e9d005b0b4928\Publisher(Empty) 13241300x800000000000000036166Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\gawk-5.0.0.exe|709e9d005b0b4928\LowerCaseLongPathc:\program files\git\usr\bin\gawk-5.0.0.exe 13241300x800000000000000036165Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\gapplication.exe|4ee0a6aaade17793\BinProductVersion(Empty) 13241300x800000000000000036164Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\gapplication.exe|4ee0a6aaade17793\LinkDate01/01/1970 00:00:00 13241300x800000000000000036163Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\gapplication.exe|4ee0a6aaade17793\Publisher(Empty) 13241300x800000000000000036162Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\gapplication.exe|4ee0a6aaade17793\LowerCaseLongPathc:\program files\git\usr\bin\gapplication.exe 13241300x800000000000000036161Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\funzip.exe|8d9537366e67e65c\BinProductVersion(Empty) 13241300x800000000000000036160Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\funzip.exe|8d9537366e67e65c\LinkDate05/08/2031 18:06:26 13241300x800000000000000036159Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\funzip.exe|8d9537366e67e65c\Publisher(Empty) 13241300x800000000000000036158Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\funzip.exe|8d9537366e67e65c\LowerCaseLongPathc:\program files\git\usr\bin\funzip.exe 13241300x800000000000000036157Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\frcode.exe|c02ff0fb50c67deb\BinProductVersion(Empty) 13241300x800000000000000036156Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\frcode.exe|c02ff0fb50c67deb\LinkDate01/01/1970 00:00:00 13241300x800000000000000036155Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\frcode.exe|c02ff0fb50c67deb\Publisher(Empty) 13241300x800000000000000036154Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\frcode.exe|c02ff0fb50c67deb\LowerCaseLongPathc:\program files\git\usr\libexec\frcode.exe 13241300x800000000000000036153Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\fold.exe|84163f1e2201dd71\BinProductVersion(Empty) 13241300x800000000000000036152Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\fold.exe|84163f1e2201dd71\LinkDate01/01/1970 00:00:00 13241300x800000000000000036151Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\fold.exe|84163f1e2201dd71\Publisher(Empty) 13241300x800000000000000036150Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\fold.exe|84163f1e2201dd71\LowerCaseLongPathc:\program files\git\usr\bin\fold.exe 13241300x800000000000000036149Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\fmt.exe|74780154d3c66e14\BinProductVersion(Empty) 13241300x800000000000000036148Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\fmt.exe|74780154d3c66e14\LinkDate01/01/1970 00:00:00 13241300x800000000000000036147Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\fmt.exe|74780154d3c66e14\Publisher(Empty) 13241300x800000000000000036146Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\fmt.exe|74780154d3c66e14\LowerCaseLongPathc:\program files\git\usr\bin\fmt.exe 13241300x800000000000000036145Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\find.exe|d79fa77470677f17\BinProductVersion(Empty) 13241300x800000000000000036144Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\find.exe|d79fa77470677f17\LinkDate01/01/1970 00:00:00 13241300x800000000000000036143Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\find.exe|d79fa77470677f17\Publisher(Empty) 13241300x800000000000000036142Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\find.exe|d79fa77470677f17\LowerCaseLongPathc:\program files\git\usr\bin\find.exe 13241300x800000000000000036141Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\file.exe|9412a967e2d15f0f\BinProductVersion(Empty) 13241300x800000000000000036140Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\file.exe|9412a967e2d15f0f\LinkDate01/01/1970 00:00:00 13241300x800000000000000036139Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\file.exe|9412a967e2d15f0f\Publisher(Empty) 13241300x800000000000000036138Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\file.exe|9412a967e2d15f0f\LowerCaseLongPathc:\program files\git\usr\bin\file.exe 13241300x800000000000000036137Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\fido2-token.exe|a3c5680a4f7259a\BinProductVersion(Empty) 13241300x800000000000000036136Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\fido2-token.exe|a3c5680a4f7259a\LinkDate01/01/1970 00:00:00 13241300x800000000000000036135Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\fido2-token.exe|a3c5680a4f7259a\Publisher(Empty) 13241300x800000000000000036134Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\fido2-token.exe|a3c5680a4f7259a\LowerCaseLongPathc:\program files\git\usr\bin\fido2-token.exe 13241300x800000000000000036133Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\fido2-cred.exe|c2222f8371b081a5\BinProductVersion(Empty) 13241300x800000000000000036132Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\fido2-cred.exe|c2222f8371b081a5\LinkDate01/01/1970 00:00:00 13241300x800000000000000036131Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\fido2-cred.exe|c2222f8371b081a5\Publisher(Empty) 13241300x800000000000000036130Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.277{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\fido2-cred.exe|c2222f8371b081a5\LowerCaseLongPathc:\program files\git\usr\bin\fido2-cred.exe 13241300x800000000000000036129Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\fido2-assert.exe|94d2ea2ef1445ec9\BinProductVersion(Empty) 13241300x800000000000000036128Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\fido2-assert.exe|94d2ea2ef1445ec9\LinkDate01/01/1970 00:00:00 13241300x800000000000000036127Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\fido2-assert.exe|94d2ea2ef1445ec9\Publisher(Empty) 13241300x800000000000000036126Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\fido2-assert.exe|94d2ea2ef1445ec9\LowerCaseLongPathc:\program files\git\usr\bin\fido2-assert.exe 13241300x800000000000000036125Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\false.exe|8d9fec6786dfc816\BinProductVersion(Empty) 13241300x800000000000000036124Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\false.exe|8d9fec6786dfc816\LinkDate01/01/1970 00:00:00 13241300x800000000000000036123Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\false.exe|8d9fec6786dfc816\Publisher(Empty) 13241300x800000000000000036122Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\false.exe|8d9fec6786dfc816\LowerCaseLongPathc:\program files\git\usr\bin\false.exe 13241300x800000000000000036121Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\factor.exe|b56619397de59334\BinProductVersion(Empty) 13241300x800000000000000036120Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\factor.exe|b56619397de59334\LinkDate01/01/1970 00:00:00 13241300x800000000000000036119Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\factor.exe|b56619397de59334\Publisher(Empty) 13241300x800000000000000036118Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\factor.exe|b56619397de59334\LowerCaseLongPathc:\program files\git\usr\bin\factor.exe 13241300x800000000000000036117Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\expr.exe|2052e3951d88a155\BinProductVersion(Empty) 13241300x800000000000000036116Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\expr.exe|2052e3951d88a155\LinkDate01/01/1970 00:00:00 13241300x800000000000000036115Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\expr.exe|2052e3951d88a155\Publisher(Empty) 13241300x800000000000000036114Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\expr.exe|2052e3951d88a155\LowerCaseLongPathc:\program files\git\usr\bin\expr.exe 13241300x800000000000000036113Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\expand.exe|48fc5987fb05c50d\BinProductVersion(Empty) 13241300x800000000000000036112Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\expand.exe|48fc5987fb05c50d\LinkDate01/01/1970 00:00:00 13241300x800000000000000036111Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\expand.exe|48fc5987fb05c50d\Publisher(Empty) 13241300x800000000000000036110Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\expand.exe|48fc5987fb05c50d\LowerCaseLongPathc:\program files\git\usr\bin\expand.exe 13241300x800000000000000036109Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\ex.exe|a5705edbed8fc6c4\BinProductVersion(Empty) 13241300x800000000000000036108Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\ex.exe|a5705edbed8fc6c4\LinkDate01/01/1970 00:00:00 13241300x800000000000000036107Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\ex.exe|a5705edbed8fc6c4\Publisher(Empty) 13241300x800000000000000036106Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\ex.exe|a5705edbed8fc6c4\LowerCaseLongPathc:\program files\git\usr\bin\ex.exe 13241300x800000000000000036105Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\envsubst.exe|eadcd0623e89b9ae\BinProductVersion0.19.8.0 13241300x800000000000000036104Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\envsubst.exe|eadcd0623e89b9ae\LinkDate01/01/1970 00:00:00 13241300x800000000000000036103Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\envsubst.exe|eadcd0623e89b9ae\Publisherfree software foundation 13241300x800000000000000036102Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\envsubst.exe|eadcd0623e89b9ae\LowerCaseLongPathc:\program files\git\mingw64\bin\envsubst.exe 13241300x800000000000000036101Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\envsubst.exe|660c72e4fd95bfd4\BinProductVersion0.19.8.0 13241300x800000000000000036100Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\envsubst.exe|660c72e4fd95bfd4\LinkDate12/01/2031 01:05:42 13241300x800000000000000036099Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\envsubst.exe|660c72e4fd95bfd4\Publisherfree software foundation 13241300x800000000000000036098Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\envsubst.exe|660c72e4fd95bfd4\LowerCaseLongPathc:\program files\git\usr\bin\envsubst.exe 13241300x800000000000000036097Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\env.exe|7508509d7b06f998\BinProductVersion(Empty) 13241300x800000000000000036096Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\env.exe|7508509d7b06f998\LinkDate01/01/1970 00:00:00 13241300x800000000000000036095Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\env.exe|7508509d7b06f998\Publisher(Empty) 13241300x800000000000000036094Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\env.exe|7508509d7b06f998\LowerCaseLongPathc:\program files\git\usr\bin\env.exe 13241300x800000000000000036093Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\edit_test_dll.ex|2cd5024859c22e2e\BinProductVersion(Empty) 13241300x800000000000000036092Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\edit_test_dll.ex|2cd5024859c22e2e\LinkDate01/01/1970 00:00:00 13241300x800000000000000036091Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\edit_test_dll.ex|2cd5024859c22e2e\Publisher(Empty) 13241300x800000000000000036090Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\edit_test_dll.ex|2cd5024859c22e2e\LowerCaseLongPathc:\program files\git\mingw64\bin\edit_test_dll.exe 13241300x800000000000000036089Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\edit_test.exe|e47ad3e671162baa\BinProductVersion(Empty) 13241300x800000000000000036088Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\edit_test.exe|e47ad3e671162baa\LinkDate01/01/1970 00:00:00 13241300x800000000000000036087Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\edit_test.exe|e47ad3e671162baa\Publisher(Empty) 13241300x800000000000000036086Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.local-SetValue2021-09-10 14:42:14.261{7BD73061-65B2-613B-1300-00000000F001}92C:\Windows\System32\svchost.exeHKLM\System\CurrentControlSet\Services\NcbService\NCB\KapiNlmCache\7\ValueBinary Data 13241300x800000000000000036085Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\edit_test.exe|e47ad3e671162baa\LowerCaseLongPathc:\program files\git\mingw64\bin\edit_test.exe 13241300x800000000000000036084Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.local-SetValue2021-09-10 14:42:14.261{7BD73061-65B2-613B-1300-00000000F001}92C:\Windows\System32\svchost.exeHKLM\System\CurrentControlSet\Services\NcbService\NCB\KapiNlmCache\7\ValueSizeDWORD (0x00000008) 13241300x800000000000000036083Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.local-SetValue2021-09-10 14:42:14.261{7BD73061-65B2-613B-1300-00000000F001}92C:\Windows\System32\svchost.exeHKLM\System\CurrentControlSet\Services\NcbService\NCB\KapiNlmCache\7\KeySizeDWORD (0x00000000) 13241300x800000000000000036082Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.local-SetValue2021-09-10 14:42:14.261{7BD73061-65B2-613B-1300-00000000F001}92C:\Windows\System32\svchost.exeHKLM\System\CurrentControlSet\Services\NcbService\NCB\KapiNlmCache\7\TimestampQWORD (0x01d7a652-0x0b95d341) 13241300x800000000000000036081Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\edit-git-bash.ex|c4b83d4312564a9\BinProductVersion(Empty) 13241300x800000000000000036080Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\edit-git-bash.ex|c4b83d4312564a9\LinkDate08/24/2021 10:09:53 13241300x800000000000000036079Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.local-SetValue2021-09-10 14:42:14.261{7BD73061-65B2-613B-1300-00000000F001}92C:\Windows\System32\svchost.exeHKLM\System\CurrentControlSet\Services\NcbService\NCB\KapiNlmCache\7\NetworksBinary Data 13241300x800000000000000036078Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.local-SetValue2021-09-10 14:42:14.261{7BD73061-65B2-613B-1300-00000000F001}92C:\Windows\System32\svchost.exeHKLM\System\CurrentControlSet\Services\NcbService\NCB\KapiNlmCache\7\NumNetworksDWORD (0x00000001) 13241300x800000000000000036077Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\edit-git-bash.ex|c4b83d4312564a9\Publisher(Empty) 13241300x800000000000000036076Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\edit-git-bash.ex|c4b83d4312564a9\LowerCaseLongPathc:\program files\git\mingw64\share\git\edit-git-bash.exe 13241300x800000000000000036075Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\echo.exe|263446599120623a\BinProductVersion(Empty) 13241300x800000000000000036074Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\echo.exe|263446599120623a\LinkDate01/01/1970 00:00:00 13241300x800000000000000036073Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\echo.exe|263446599120623a\Publisher(Empty) 13241300x800000000000000036072Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\echo.exe|263446599120623a\LowerCaseLongPathc:\program files\git\usr\bin\echo.exe 13241300x800000000000000036071Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\dumpsexp.exe|45a2659c07e3df2c\BinProductVersion(Empty) 13241300x800000000000000036070Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\dumpsexp.exe|45a2659c07e3df2c\LinkDate01/01/1970 00:00:00 13241300x800000000000000036069Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\dumpsexp.exe|45a2659c07e3df2c\Publisher(Empty) 13241300x800000000000000036068Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\dumpsexp.exe|45a2659c07e3df2c\LowerCaseLongPathc:\program files\git\usr\bin\dumpsexp.exe 13241300x800000000000000036067Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\du.exe|2b10b32847099da7\BinProductVersion(Empty) 13241300x800000000000000036066Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\du.exe|2b10b32847099da7\LinkDate01/01/1970 00:00:00 13241300x800000000000000036065Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\du.exe|2b10b32847099da7\Publisher(Empty) 13241300x800000000000000036064Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\du.exe|2b10b32847099da7\LowerCaseLongPathc:\program files\git\usr\bin\du.exe 13241300x800000000000000036063Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\dos2unix.exe|e819f56941027f1c\BinProductVersion(Empty) 13241300x800000000000000036062Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\dos2unix.exe|e819f56941027f1c\LinkDate01/01/1970 00:00:00 13241300x800000000000000036061Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\dos2unix.exe|e819f56941027f1c\Publisher(Empty) 13241300x800000000000000036060Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\dos2unix.exe|e819f56941027f1c\LowerCaseLongPathc:\program files\git\usr\bin\dos2unix.exe 13241300x800000000000000036059Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\dirname.exe|b029038512034ced\BinProductVersion(Empty) 13241300x800000000000000036058Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\dirname.exe|b029038512034ced\LinkDate01/01/1970 00:00:00 13241300x800000000000000036057Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\dirname.exe|b029038512034ced\Publisher(Empty) 13241300x800000000000000036056Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\dirname.exe|b029038512034ced\LowerCaseLongPathc:\program files\git\usr\bin\dirname.exe 13241300x800000000000000036055Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\dirmngr.exe|fe24969724873327\BinProductVersion(Empty) 13241300x800000000000000036054Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\dirmngr.exe|fe24969724873327\LinkDate01/01/1970 00:00:00 13241300x800000000000000036053Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\dirmngr.exe|fe24969724873327\Publisher(Empty) 13241300x800000000000000036052Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\dirmngr.exe|fe24969724873327\LowerCaseLongPathc:\program files\git\usr\bin\dirmngr.exe 13241300x800000000000000036051Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\dirmngr-client.e|d59c8fc399717975\BinProductVersion(Empty) 13241300x800000000000000036050Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\dirmngr-client.e|d59c8fc399717975\LinkDate01/01/1970 00:00:00 13241300x800000000000000036049Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\dirmngr-client.e|d59c8fc399717975\Publisher(Empty) 13241300x800000000000000036048Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\dirmngr-client.e|d59c8fc399717975\LowerCaseLongPathc:\program files\git\usr\bin\dirmngr-client.exe 13241300x800000000000000036047Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\dircolors.exe|2c054bf1c4846ccd\BinProductVersion(Empty) 13241300x800000000000000036046Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\dircolors.exe|2c054bf1c4846ccd\LinkDate01/01/1970 00:00:00 13241300x800000000000000036045Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\dircolors.exe|2c054bf1c4846ccd\Publisher(Empty) 13241300x800000000000000036044Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\dircolors.exe|2c054bf1c4846ccd\LowerCaseLongPathc:\program files\git\usr\bin\dircolors.exe 13241300x800000000000000036043Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\dir.exe|100b2e6a725becca\BinProductVersion(Empty) 13241300x800000000000000036042Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\dir.exe|100b2e6a725becca\LinkDate01/01/1970 00:00:00 13241300x800000000000000036041Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\dir.exe|100b2e6a725becca\Publisher(Empty) 13241300x800000000000000036040Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\dir.exe|100b2e6a725becca\LowerCaseLongPathc:\program files\git\usr\bin\dir.exe 13241300x800000000000000036039Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\diff3.exe|db0f57bb42b2e275\BinProductVersion(Empty) 13241300x800000000000000036038Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\diff3.exe|db0f57bb42b2e275\LinkDate01/01/1970 00:00:00 13241300x800000000000000036037Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\diff3.exe|db0f57bb42b2e275\Publisher(Empty) 13241300x800000000000000036036Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\diff3.exe|db0f57bb42b2e275\LowerCaseLongPathc:\program files\git\usr\bin\diff3.exe 13241300x800000000000000036035Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\diff.exe|c7ecb5c4d9c537e1\BinProductVersion(Empty) 13241300x800000000000000036034Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\diff.exe|c7ecb5c4d9c537e1\LinkDate01/01/1970 00:00:00 13241300x800000000000000036033Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\diff.exe|c7ecb5c4d9c537e1\Publisher(Empty) 13241300x800000000000000036032Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\diff.exe|c7ecb5c4d9c537e1\LowerCaseLongPathc:\program files\git\usr\bin\diff.exe 13241300x800000000000000036031Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\df.exe|65dd80792ce5f665\BinProductVersion(Empty) 13241300x800000000000000036030Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\df.exe|65dd80792ce5f665\LinkDate01/01/1970 00:00:00 13241300x800000000000000036029Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\df.exe|65dd80792ce5f665\Publisher(Empty) 13241300x800000000000000036028Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.261{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\df.exe|65dd80792ce5f665\LowerCaseLongPathc:\program files\git\usr\bin\df.exe 13241300x800000000000000036027Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\dd.exe|d6bffb363596af3e\BinProductVersion(Empty) 13241300x800000000000000036026Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\dd.exe|d6bffb363596af3e\LinkDate01/01/1970 00:00:00 13241300x800000000000000036025Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\dd.exe|d6bffb363596af3e\Publisher(Empty) 13241300x800000000000000036024Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\dd.exe|d6bffb363596af3e\LowerCaseLongPathc:\program files\git\usr\bin\dd.exe 13241300x800000000000000036023Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\date.exe|15400b5e3ba75572\BinProductVersion(Empty) 13241300x800000000000000036022Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\date.exe|15400b5e3ba75572\LinkDate01/01/1970 00:00:00 13241300x800000000000000036021Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\date.exe|15400b5e3ba75572\Publisher(Empty) 13241300x800000000000000036020Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\date.exe|15400b5e3ba75572\LowerCaseLongPathc:\program files\git\usr\bin\date.exe 13241300x800000000000000036019Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\dash.exe|d7e7d55ce6ee5457\BinProductVersion(Empty) 13241300x800000000000000036018Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\dash.exe|d7e7d55ce6ee5457\LinkDate01/01/1970 00:00:00 13241300x800000000000000036017Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\dash.exe|d7e7d55ce6ee5457\Publisher(Empty) 13241300x800000000000000036016Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\dash.exe|d7e7d55ce6ee5457\LowerCaseLongPathc:\program files\git\usr\bin\dash.exe 13241300x800000000000000036015Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\d2u.exe|9a42254ebeca6f7a\BinProductVersion(Empty) 13241300x800000000000000036014Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\d2u.exe|9a42254ebeca6f7a\LinkDate01/01/1970 00:00:00 13241300x800000000000000036013Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\d2u.exe|9a42254ebeca6f7a\Publisher(Empty) 13241300x800000000000000036012Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\d2u.exe|9a42254ebeca6f7a\LowerCaseLongPathc:\program files\git\usr\bin\d2u.exe 13241300x800000000000000036011Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\cygwin-console-h|5323f22aa324e252\BinProductVersion(Empty) 13241300x800000000000000036010Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\cygwin-console-h|5323f22aa324e252\LinkDate03/26/2021 22:24:41 13241300x800000000000000036009Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\cygwin-console-h|5323f22aa324e252\Publisher(Empty) 13241300x800000000000000036008Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\cygwin-console-h|5323f22aa324e252\LowerCaseLongPathc:\program files\git\usr\bin\cygwin-console-helper.exe 13241300x800000000000000036007Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\cygpath.exe|89e407d49466bcd8\BinProductVersion(Empty) 13241300x800000000000000036006Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\cygpath.exe|89e407d49466bcd8\LinkDate03/26/2021 22:24:39 13241300x800000000000000036005Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\cygpath.exe|89e407d49466bcd8\Publisher(Empty) 13241300x800000000000000036004Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\cygpath.exe|89e407d49466bcd8\LowerCaseLongPathc:\program files\git\usr\bin\cygpath.exe 13241300x800000000000000036003Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\cygcheck.exe|6a2038f6387fe2d8\BinProductVersion(Empty) 13241300x800000000000000036002Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\cygcheck.exe|6a2038f6387fe2d8\LinkDate03/26/2021 22:24:41 13241300x800000000000000036001Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\cygcheck.exe|6a2038f6387fe2d8\Publisher(Empty) 13241300x800000000000000036000Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\cygcheck.exe|6a2038f6387fe2d8\LowerCaseLongPathc:\program files\git\usr\bin\cygcheck.exe 13241300x800000000000000035999Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\cut.exe|19b3f09ad648b49b\BinProductVersion(Empty) 13241300x800000000000000035998Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\cut.exe|19b3f09ad648b49b\LinkDate01/01/1970 00:00:00 13241300x800000000000000035997Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\cut.exe|19b3f09ad648b49b\Publisher(Empty) 13241300x800000000000000035996Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\cut.exe|19b3f09ad648b49b\LowerCaseLongPathc:\program files\git\usr\bin\cut.exe 13241300x800000000000000035995Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\curl.exe|34ac32e380c639e7\BinProductVersion(Empty) 13241300x800000000000000035994Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\curl.exe|34ac32e380c639e7\LinkDate08/18/2021 09:19:51 13241300x800000000000000035993Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\curl.exe|34ac32e380c639e7\Publisher(Empty) 13241300x800000000000000035992Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\curl.exe|34ac32e380c639e7\LowerCaseLongPathc:\program files\git\mingw64\bin\curl.exe 13241300x800000000000000035991Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\csplit.exe|86edd40dc8e531c1\BinProductVersion(Empty) 13241300x800000000000000035990Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\csplit.exe|86edd40dc8e531c1\LinkDate01/01/1970 00:00:00 13241300x800000000000000035989Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\csplit.exe|86edd40dc8e531c1\Publisher(Empty) 13241300x800000000000000035988Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\csplit.exe|86edd40dc8e531c1\LowerCaseLongPathc:\program files\git\usr\bin\csplit.exe 13241300x800000000000000035987Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\create-shortcut.|7be1e57c6a9b6d74\BinProductVersion(Empty) 13241300x800000000000000035986Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\create-shortcut.|7be1e57c6a9b6d74\LinkDate01/01/1970 00:00:00 13241300x800000000000000035985Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\create-shortcut.|7be1e57c6a9b6d74\Publisher(Empty) 13241300x800000000000000035984Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\create-shortcut.|7be1e57c6a9b6d74\LowerCaseLongPathc:\program files\git\mingw64\bin\create-shortcut.exe 13241300x800000000000000035983Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\cp.exe|a9aa2ba1cc55a1d1\BinProductVersion(Empty) 13241300x800000000000000035982Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\cp.exe|a9aa2ba1cc55a1d1\LinkDate01/01/1970 00:00:00 13241300x800000000000000035981Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\cp.exe|a9aa2ba1cc55a1d1\Publisher(Empty) 13241300x800000000000000035980Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\cp.exe|a9aa2ba1cc55a1d1\LowerCaseLongPathc:\program files\git\usr\bin\cp.exe 13241300x800000000000000035979Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\connect.exe|98a1b69f7698c1b1\BinProductVersion(Empty) 13241300x800000000000000035978Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\connect.exe|98a1b69f7698c1b1\LinkDate01/01/1970 00:00:00 13241300x800000000000000035977Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\connect.exe|98a1b69f7698c1b1\Publisher(Empty) 13241300x800000000000000035976Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\connect.exe|98a1b69f7698c1b1\LowerCaseLongPathc:\program files\git\mingw64\bin\connect.exe 13241300x800000000000000035975Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\compat-bash.exe|2353d7f66f7d8a47\BinProductVersion2.33.0.2 13241300x800000000000000035974Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\compat-bash.exe|2353d7f66f7d8a47\LinkDate08/24/2021 10:09:53 13241300x800000000000000035973Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\compat-bash.exe|2353d7f66f7d8a47\Publisherthe git development community 13241300x800000000000000035972Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\compat-bash.exe|2353d7f66f7d8a47\LowerCaseLongPathc:\program files\git\mingw64\share\git\compat-bash.exe 13241300x800000000000000035971Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\comm.exe|9b9df3e9f04bb630\BinProductVersion(Empty) 13241300x800000000000000035970Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\comm.exe|9b9df3e9f04bb630\LinkDate01/01/1970 00:00:00 13241300x800000000000000035969Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\comm.exe|9b9df3e9f04bb630\Publisher(Empty) 13241300x800000000000000035968Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\comm.exe|9b9df3e9f04bb630\LowerCaseLongPathc:\program files\git\usr\bin\comm.exe 13241300x800000000000000035967Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\column.exe|a0a6e93c07d1168\BinProductVersion(Empty) 13241300x800000000000000035966Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\column.exe|a0a6e93c07d1168\LinkDate01/01/1970 00:00:00 13241300x800000000000000035965Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\column.exe|a0a6e93c07d1168\Publisher(Empty) 13241300x800000000000000035964Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\column.exe|a0a6e93c07d1168\LowerCaseLongPathc:\program files\git\usr\bin\column.exe 13241300x800000000000000035963Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\cmp.exe|de6ed9764cfeeb7f\BinProductVersion(Empty) 13241300x800000000000000035962Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\cmp.exe|de6ed9764cfeeb7f\LinkDate01/01/1970 00:00:00 13241300x800000000000000035961Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\cmp.exe|de6ed9764cfeeb7f\Publisher(Empty) 13241300x800000000000000035960Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\cmp.exe|de6ed9764cfeeb7f\LowerCaseLongPathc:\program files\git\usr\bin\cmp.exe 13241300x800000000000000035959Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\clear.exe|23d1f6608a1d3194\BinProductVersion(Empty) 13241300x800000000000000035958Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\clear.exe|23d1f6608a1d3194\LinkDate01/01/1970 00:00:00 13241300x800000000000000035957Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\clear.exe|23d1f6608a1d3194\Publisher(Empty) 13241300x800000000000000035956Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\clear.exe|23d1f6608a1d3194\LowerCaseLongPathc:\program files\git\usr\bin\clear.exe 13241300x800000000000000035955Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\cldr-plurals.exe|acec4b705bc23965\BinProductVersion(Empty) 13241300x800000000000000035954Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\cldr-plurals.exe|acec4b705bc23965\LinkDate10/26/1974 18:18:40 13241300x800000000000000035953Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\cldr-plurals.exe|acec4b705bc23965\Publisher(Empty) 13241300x800000000000000035952Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\cldr-plurals.exe|acec4b705bc23965\LowerCaseLongPathc:\program files\git\usr\lib\gettext\cldr-plurals.exe 13241300x800000000000000035951Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\cksum.exe|877b1cc41ae31cae\BinProductVersion(Empty) 13241300x800000000000000035950Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\cksum.exe|877b1cc41ae31cae\LinkDate01/01/1970 00:00:00 13241300x800000000000000035949Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\cksum.exe|877b1cc41ae31cae\Publisher(Empty) 13241300x800000000000000035948Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\cksum.exe|877b1cc41ae31cae\LowerCaseLongPathc:\program files\git\usr\bin\cksum.exe 13241300x800000000000000035947Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\chroot.exe|699e7ae138a98a36\BinProductVersion(Empty) 13241300x800000000000000035946Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\chroot.exe|699e7ae138a98a36\LinkDate01/01/1970 00:00:00 13241300x800000000000000035945Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\chroot.exe|699e7ae138a98a36\Publisher(Empty) 13241300x800000000000000035944Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\chroot.exe|699e7ae138a98a36\LowerCaseLongPathc:\program files\git\usr\bin\chroot.exe 13241300x800000000000000035943Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\chown.exe|6e51d9aedefdf80f\BinProductVersion(Empty) 13241300x800000000000000035942Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\chown.exe|6e51d9aedefdf80f\LinkDate01/01/1970 00:00:00 13241300x800000000000000035941Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\chown.exe|6e51d9aedefdf80f\Publisher(Empty) 13241300x800000000000000035940Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\chown.exe|6e51d9aedefdf80f\LowerCaseLongPathc:\program files\git\usr\bin\chown.exe 13241300x800000000000000035939Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\chmod.exe|e3ddbff0fcd6c5e6\BinProductVersion(Empty) 13241300x800000000000000035938Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\chmod.exe|e3ddbff0fcd6c5e6\LinkDate01/01/1970 00:00:00 13241300x800000000000000035937Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\chmod.exe|e3ddbff0fcd6c5e6\Publisher(Empty) 13241300x800000000000000035936Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\chmod.exe|e3ddbff0fcd6c5e6\LowerCaseLongPathc:\program files\git\usr\bin\chmod.exe 13241300x800000000000000035935Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\chgrp.exe|bb039b4cd0c6f545\BinProductVersion(Empty) 13241300x800000000000000035934Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\chgrp.exe|bb039b4cd0c6f545\LinkDate01/01/1970 00:00:00 13241300x800000000000000035933Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\chgrp.exe|bb039b4cd0c6f545\Publisher(Empty) 13241300x800000000000000035932Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\chgrp.exe|bb039b4cd0c6f545\LowerCaseLongPathc:\program files\git\usr\bin\chgrp.exe 13241300x800000000000000035931Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\chcon.exe|8f0fac908d5773b6\BinProductVersion(Empty) 13241300x800000000000000035930Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\chcon.exe|8f0fac908d5773b6\LinkDate01/01/1970 00:00:00 13241300x800000000000000035929Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\chcon.exe|8f0fac908d5773b6\Publisher(Empty) 13241300x800000000000000035928Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\chcon.exe|8f0fac908d5773b6\LowerCaseLongPathc:\program files\git\usr\bin\chcon.exe 13241300x800000000000000035927Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\chattr.exe|29db3d1af543269b\BinProductVersion(Empty) 13241300x800000000000000035926Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\chattr.exe|29db3d1af543269b\LinkDate03/26/2021 22:24:39 13241300x800000000000000035925Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\chattr.exe|29db3d1af543269b\Publisher(Empty) 13241300x800000000000000035924Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\chattr.exe|29db3d1af543269b\LowerCaseLongPathc:\program files\git\usr\bin\chattr.exe 13241300x800000000000000035923Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\cat.exe|c9bdbcd78462df5e\BinProductVersion(Empty) 13241300x800000000000000035922Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\cat.exe|c9bdbcd78462df5e\LinkDate01/01/1970 00:00:00 13241300x800000000000000035921Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\cat.exe|c9bdbcd78462df5e\Publisher(Empty) 13241300x800000000000000035920Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\cat.exe|c9bdbcd78462df5e\LowerCaseLongPathc:\program files\git\usr\bin\cat.exe 13241300x800000000000000035919Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\captoinfo.exe|ae170334068304db\BinProductVersion(Empty) 13241300x800000000000000035918Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\captoinfo.exe|ae170334068304db\LinkDate01/01/1970 00:00:00 13241300x800000000000000035917Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\captoinfo.exe|ae170334068304db\Publisher(Empty) 23542300x800000000000000013426Microsoft-Windows-Sysmon/Operationalwin-host-166.attackrange.local-2021-09-10 14:42:14.100{625C326B-6888-613B-DB00-00000000F101}104NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=738D39FB07FD51EE665A02035597DF84,SHA256=BAFFC126FC4B76CC6D6238E4BCCDA3C2F6785DD64149E631E8ABD82AB33D11BF,IMPHASH=00000000000000000000000000000000falsetrue 13241300x800000000000000035916Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\captoinfo.exe|ae170334068304db\LowerCaseLongPathc:\program files\git\usr\bin\captoinfo.exe 13241300x800000000000000035915Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\bzip2recover.exe|7b4916700fd7fa54\BinProductVersion(Empty) 13241300x800000000000000035914Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\bzip2recover.exe|7b4916700fd7fa54\LinkDate01/01/1970 00:00:00 13241300x800000000000000035913Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\bzip2recover.exe|7b4916700fd7fa54\Publisher(Empty) 13241300x800000000000000035912Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\bzip2recover.exe|7b4916700fd7fa54\LowerCaseLongPathc:\program files\git\mingw64\bin\bzip2recover.exe 13241300x800000000000000035911Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\bzip2recover.exe|6fb043bab87a8c4c\BinProductVersion(Empty) 13241300x800000000000000035910Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\bzip2recover.exe|6fb043bab87a8c4c\LinkDate01/01/1970 00:00:00 13241300x800000000000000035909Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\bzip2recover.exe|6fb043bab87a8c4c\Publisher(Empty) 13241300x800000000000000035908Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\bzip2recover.exe|6fb043bab87a8c4c\LowerCaseLongPathc:\program files\git\usr\bin\bzip2recover.exe 13241300x800000000000000035907Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\bzip2.exe|cecf80293919b675\BinProductVersion(Empty) 13241300x800000000000000035906Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\bzip2.exe|cecf80293919b675\LinkDate01/01/1970 00:00:00 13241300x800000000000000035905Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\bzip2.exe|cecf80293919b675\Publisher(Empty) 13241300x800000000000000035904Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\bzip2.exe|cecf80293919b675\LowerCaseLongPathc:\program files\git\mingw64\bin\bzip2.exe 13241300x800000000000000035903Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\bzip2.exe|6e87155dac2f4c04\BinProductVersion(Empty) 13241300x800000000000000035902Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\bzip2.exe|6e87155dac2f4c04\LinkDate01/01/1970 00:00:00 13241300x800000000000000035901Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\bzip2.exe|6e87155dac2f4c04\Publisher(Empty) 13241300x800000000000000035900Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\bzip2.exe|6e87155dac2f4c04\LowerCaseLongPathc:\program files\git\usr\bin\bzip2.exe 13241300x800000000000000035899Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\bzcat.exe|5bd95ec17b3dd431\BinProductVersion(Empty) 13241300x800000000000000035898Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\bzcat.exe|5bd95ec17b3dd431\LinkDate01/01/1970 00:00:00 13241300x800000000000000035897Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\bzcat.exe|5bd95ec17b3dd431\Publisher(Empty) 13241300x800000000000000035896Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\bzcat.exe|5bd95ec17b3dd431\LowerCaseLongPathc:\program files\git\usr\bin\bzcat.exe 13241300x800000000000000035895Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\bzcat.exe|22efe6404fe377ef\BinProductVersion(Empty) 13241300x800000000000000035894Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\bzcat.exe|22efe6404fe377ef\LinkDate01/01/1970 00:00:00 13241300x800000000000000035893Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\bzcat.exe|22efe6404fe377ef\Publisher(Empty) 13241300x800000000000000035892Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\bzcat.exe|22efe6404fe377ef\LowerCaseLongPathc:\program files\git\mingw64\bin\bzcat.exe 13241300x800000000000000035891Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\bunzip2.exe|e3db3453bc608648\BinProductVersion(Empty) 13241300x800000000000000035890Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\bunzip2.exe|e3db3453bc608648\LinkDate01/01/1970 00:00:00 13241300x800000000000000035889Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\bunzip2.exe|e3db3453bc608648\Publisher(Empty) 13241300x800000000000000035888Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\bunzip2.exe|e3db3453bc608648\LowerCaseLongPathc:\program files\git\mingw64\bin\bunzip2.exe 13241300x800000000000000035887Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\bunzip2.exe|9ac74d590cb04f1a\BinProductVersion(Empty) 13241300x800000000000000035886Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\bunzip2.exe|9ac74d590cb04f1a\LinkDate01/01/1970 00:00:00 13241300x800000000000000035885Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\bunzip2.exe|9ac74d590cb04f1a\Publisher(Empty) 13241300x800000000000000035884Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\bunzip2.exe|9ac74d590cb04f1a\LowerCaseLongPathc:\program files\git\usr\bin\bunzip2.exe 13241300x800000000000000035883Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\brotli.exe|31204f639af895eb\BinProductVersion(Empty) 13241300x800000000000000035882Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\brotli.exe|31204f639af895eb\LinkDate01/01/1970 00:00:00 13241300x800000000000000035881Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\brotli.exe|31204f639af895eb\Publisher(Empty) 13241300x800000000000000035880Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\brotli.exe|31204f639af895eb\LowerCaseLongPathc:\program files\git\mingw64\bin\brotli.exe 13241300x800000000000000035879Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\blocked-file-uti|26a5d90fb1352887\BinProductVersion(Empty) 13241300x800000000000000035878Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\blocked-file-uti|26a5d90fb1352887\LinkDate01/01/1970 00:00:00 13241300x800000000000000035877Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\blocked-file-uti|26a5d90fb1352887\Publisher(Empty) 13241300x800000000000000035876Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\blocked-file-uti|26a5d90fb1352887\LowerCaseLongPathc:\program files\git\mingw64\bin\blocked-file-util.exe 13241300x800000000000000035875Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\bash.exe|82493e8a87323f44\BinProductVersion2.33.0.2 13241300x800000000000000035874Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\bash.exe|82493e8a87323f44\LinkDate08/24/2021 10:09:53 13241300x800000000000000035873Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\bash.exe|82493e8a87323f44\Publisherthe git development community 13241300x800000000000000035872Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\bash.exe|82493e8a87323f44\LowerCaseLongPathc:\program files\git\bin\bash.exe 13241300x800000000000000035871Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\bash.exe|5f326cb536e85740\BinProductVersion(Empty) 13241300x800000000000000035870Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\bash.exe|5f326cb536e85740\LinkDate12/04/2018 10:21:15 13241300x800000000000000035869Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\bash.exe|5f326cb536e85740\Publisher(Empty) 13241300x800000000000000035868Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\bash.exe|5f326cb536e85740\LowerCaseLongPathc:\program files\git\usr\bin\bash.exe 13241300x800000000000000035867Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\basenc.exe|441974f40d711257\BinProductVersion(Empty) 13241300x800000000000000035866Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\basenc.exe|441974f40d711257\LinkDate01/01/1970 00:00:00 13241300x800000000000000035865Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\basenc.exe|441974f40d711257\Publisher(Empty) 13241300x800000000000000035864Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\basenc.exe|441974f40d711257\LowerCaseLongPathc:\program files\git\usr\bin\basenc.exe 13241300x800000000000000035863Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\basename.exe|47ada093d5bb600a\BinProductVersion(Empty) 13241300x800000000000000035862Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\basename.exe|47ada093d5bb600a\LinkDate01/01/1970 00:00:00 13241300x800000000000000035861Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\basename.exe|47ada093d5bb600a\Publisher(Empty) 13241300x800000000000000035860Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\basename.exe|47ada093d5bb600a\LowerCaseLongPathc:\program files\git\usr\bin\basename.exe 13241300x800000000000000035859Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\base64.exe|962b95c6244d4b06\BinProductVersion(Empty) 13241300x800000000000000035858Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\base64.exe|962b95c6244d4b06\LinkDate01/01/1970 00:00:00 13241300x800000000000000035857Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\base64.exe|962b95c6244d4b06\Publisher(Empty) 13241300x800000000000000035856Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\base64.exe|962b95c6244d4b06\LowerCaseLongPathc:\program files\git\usr\bin\base64.exe 13241300x800000000000000035855Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\base32.exe|a314ab833a8613c9\BinProductVersion(Empty) 13241300x800000000000000035854Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\base32.exe|a314ab833a8613c9\LinkDate01/01/1970 00:00:00 13241300x800000000000000035853Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\base32.exe|a314ab833a8613c9\Publisher(Empty) 13241300x800000000000000035852Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\base32.exe|a314ab833a8613c9\LowerCaseLongPathc:\program files\git\usr\bin\base32.exe 13241300x800000000000000035851Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\b2sum.exe|29b37ad7ebd1394a\BinProductVersion(Empty) 13241300x800000000000000035850Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\b2sum.exe|29b37ad7ebd1394a\LinkDate01/01/1970 00:00:00 13241300x800000000000000035849Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.246{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\b2sum.exe|29b37ad7ebd1394a\Publisher(Empty) 13241300x800000000000000035848Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.230{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\b2sum.exe|29b37ad7ebd1394a\LowerCaseLongPathc:\program files\git\usr\bin\b2sum.exe 13241300x800000000000000035847Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.230{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\awk.exe|283395e55c831d1d\BinProductVersion(Empty) 13241300x800000000000000035846Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.230{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\awk.exe|283395e55c831d1d\LinkDate01/01/1970 00:00:00 13241300x800000000000000035845Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.230{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\awk.exe|283395e55c831d1d\Publisher(Empty) 13241300x800000000000000035844Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.230{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\awk.exe|283395e55c831d1d\LowerCaseLongPathc:\program files\git\usr\bin\awk.exe 13241300x800000000000000035843Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.230{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\atlassian.bitbuc|c03cc9e8c801d513\BinProductVersion2.0.498.0 13241300x800000000000000035842Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.230{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\atlassian.bitbuc|c03cc9e8c801d513\LinkDate01/15/2077 00:12:40 13241300x800000000000000035841Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.230{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\atlassian.bitbuc|c03cc9e8c801d513\Publisheratlassian.bitbucket.ui 13241300x800000000000000035840Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.230{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\atlassian.bitbuc|c03cc9e8c801d513\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\atlassian.bitbucket.ui.exe 13241300x800000000000000035839Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.230{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\arch.exe|6cd29c8ee920e833\BinProductVersion(Empty) 13241300x800000000000000035838Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.230{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\arch.exe|6cd29c8ee920e833\LinkDate01/01/1970 00:00:00 13241300x800000000000000035837Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.230{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\arch.exe|6cd29c8ee920e833\Publisher(Empty) 13241300x800000000000000035836Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.230{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\arch.exe|6cd29c8ee920e833\LowerCaseLongPathc:\program files\git\usr\bin\arch.exe 13241300x800000000000000035835Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.230{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\antiword.exe|f9989c5a06cca46c\BinProductVersion(Empty) 13241300x800000000000000035834Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.230{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\antiword.exe|f9989c5a06cca46c\LinkDate01/01/1970 00:00:00 13241300x800000000000000035833Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.230{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\antiword.exe|f9989c5a06cca46c\Publisher(Empty) 13241300x800000000000000035832Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.230{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\antiword.exe|f9989c5a06cca46c\LowerCaseLongPathc:\program files\git\mingw64\bin\antiword.exe 13241300x800000000000000035831Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.230{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\ahost.exe|40c7db6e62088170\BinProductVersion(Empty) 13241300x800000000000000035830Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.230{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\ahost.exe|40c7db6e62088170\LinkDate01/01/1970 00:00:00 13241300x800000000000000035829Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.230{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\ahost.exe|40c7db6e62088170\Publisher(Empty) 13241300x800000000000000035828Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.230{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\ahost.exe|40c7db6e62088170\LowerCaseLongPathc:\program files\git\mingw64\bin\ahost.exe 13241300x800000000000000035827Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.230{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\adig.exe|8c2dc2d7e3156644\BinProductVersion(Empty) 13241300x800000000000000035826Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.230{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\adig.exe|8c2dc2d7e3156644\LinkDate01/01/1970 00:00:00 13241300x800000000000000035825Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.230{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\adig.exe|8c2dc2d7e3156644\Publisher(Empty) 13241300x800000000000000035824Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.230{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\adig.exe|8c2dc2d7e3156644\LowerCaseLongPathc:\program files\git\mingw64\bin\adig.exe 13241300x800000000000000035823Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.230{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\acountry.exe|45550c852fce5231\BinProductVersion(Empty) 13241300x800000000000000035822Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.230{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\acountry.exe|45550c852fce5231\LinkDate01/01/1970 00:00:00 13241300x800000000000000035821Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.230{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\acountry.exe|45550c852fce5231\Publisher(Empty) 13241300x800000000000000035820Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.230{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\acountry.exe|45550c852fce5231\LowerCaseLongPathc:\program files\git\mingw64\bin\acountry.exe 13241300x800000000000000035819Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.230{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\[.exe|b6eac39997c90239\BinProductVersion(Empty) 13241300x800000000000000035818Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.230{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\[.exe|b6eac39997c90239\LinkDate01/01/1970 00:00:00 13241300x800000000000000035817Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.230{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\[.exe|b6eac39997c90239\Publisher(Empty) 13241300x800000000000000035816Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.230{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\[.exe|b6eac39997c90239\LowerCaseLongPathc:\program files\git\usr\bin\[.exe 13241300x800000000000000035815Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.230{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplication\0000cf6bcbd173601d5a06d08c5c197a52c40000ffff\PublisherThe Git Development Community 13241300x800000000000000037280Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\pathchk.exe|815a4f847b55a65e\Publisher(Empty) 13241300x800000000000000037279Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\pathchk.exe|815a4f847b55a65e\LowerCaseLongPathc:\program files\git\usr\bin\pathchk.exe 13241300x800000000000000037278Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\patch.exe|ec282c9a0120237a\BinProductVersion(Empty) 13241300x800000000000000037277Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\patch.exe|ec282c9a0120237a\LinkDate01/01/1970 00:00:00 13241300x800000000000000037276Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\patch.exe|ec282c9a0120237a\Publisher(Empty) 13241300x800000000000000037275Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\patch.exe|ec282c9a0120237a\LowerCaseLongPathc:\program files\git\usr\bin\patch.exe 13241300x800000000000000037274Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\paste.exe|4b6449e13df12ac2\BinProductVersion(Empty) 13241300x800000000000000037273Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\paste.exe|4b6449e13df12ac2\LinkDate01/01/1970 00:00:00 13241300x800000000000000037272Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\paste.exe|4b6449e13df12ac2\Publisher(Empty) 13241300x800000000000000037271Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\paste.exe|4b6449e13df12ac2\LowerCaseLongPathc:\program files\git\usr\bin\paste.exe 13241300x800000000000000037270Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\passwd.exe|3074fd45afd21d5a\BinProductVersion(Empty) 13241300x800000000000000037269Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\passwd.exe|3074fd45afd21d5a\LinkDate03/26/2021 22:24:40 13241300x800000000000000037268Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\passwd.exe|3074fd45afd21d5a\Publisher(Empty) 13241300x800000000000000037267Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\passwd.exe|3074fd45afd21d5a\LowerCaseLongPathc:\program files\git\usr\bin\passwd.exe 13241300x800000000000000037266Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\p11-kit.exe|8bade04a6e35b25c\BinProductVersion(Empty) 13241300x800000000000000037265Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\p11-kit.exe|8bade04a6e35b25c\LinkDate01/01/1970 00:00:00 13241300x800000000000000037264Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\p11-kit.exe|8bade04a6e35b25c\Publisher(Empty) 13241300x800000000000000037263Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\p11-kit.exe|8bade04a6e35b25c\LowerCaseLongPathc:\program files\git\usr\bin\p11-kit.exe 13241300x800000000000000037262Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\p11-kit-server.e|2949625778c73062\BinProductVersion(Empty) 13241300x800000000000000037261Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\p11-kit-server.e|2949625778c73062\LinkDate01/01/1970 00:00:00 13241300x800000000000000037260Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\p11-kit-server.e|2949625778c73062\Publisher(Empty) 13241300x800000000000000037259Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\p11-kit-server.e|2949625778c73062\LowerCaseLongPathc:\program files\git\usr\libexec\p11-kit\p11-kit-server.exe 13241300x800000000000000037258Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\p11-kit-remote.e|51a36587ed162938\BinProductVersion(Empty) 13241300x800000000000000037257Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\p11-kit-remote.e|51a36587ed162938\LinkDate01/01/1970 00:00:00 13241300x800000000000000037256Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\p11-kit-remote.e|51a36587ed162938\Publisher(Empty) 13241300x800000000000000037255Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\p11-kit-remote.e|51a36587ed162938\LowerCaseLongPathc:\program files\git\usr\libexec\p11-kit\p11-kit-remote.exe 13241300x800000000000000037254Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\openssl.exe|f1700e8a34a30f68\BinProductVersion1.1.1.11 13241300x800000000000000037253Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\openssl.exe|f1700e8a34a30f68\LinkDate03/25/2021 15:20:47 13241300x800000000000000037252Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\openssl.exe|f1700e8a34a30f68\Publisherthe openssl project, https://www.openssl.org/ 13241300x800000000000000037251Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\openssl.exe|f1700e8a34a30f68\LowerCaseLongPathc:\program files\git\mingw64\bin\openssl.exe 13241300x800000000000000037250Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\openssl.exe|171f6196cf43df96\BinProductVersion1.1.1.11 13241300x800000000000000037249Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\openssl.exe|171f6196cf43df96\LinkDate01/01/1970 00:00:00 13241300x800000000000000037248Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\openssl.exe|171f6196cf43df96\Publisherthe openssl project, https://www.openssl.org/ 13241300x800000000000000037247Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\openssl.exe|171f6196cf43df96\LowerCaseLongPathc:\program files\git\usr\bin\openssl.exe 13241300x800000000000000037246Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\odt2txt.exe|6473e7d965a98c3a\BinProductVersion(Empty) 13241300x800000000000000037245Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\odt2txt.exe|6473e7d965a98c3a\LinkDate01/01/1970 00:00:00 13241300x800000000000000037244Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\odt2txt.exe|6473e7d965a98c3a\Publisher(Empty) 13241300x800000000000000037243Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\odt2txt.exe|6473e7d965a98c3a\LowerCaseLongPathc:\program files\git\mingw64\bin\odt2txt.exe 13241300x800000000000000037242Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\od.exe|4327ce9d2e91b98c\BinProductVersion(Empty) 13241300x800000000000000037241Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\od.exe|4327ce9d2e91b98c\LinkDate01/01/1970 00:00:00 13241300x800000000000000037240Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\od.exe|4327ce9d2e91b98c\Publisher(Empty) 13241300x800000000000000037239Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\od.exe|4327ce9d2e91b98c\LowerCaseLongPathc:\program files\git\usr\bin\od.exe 13241300x800000000000000037238Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\numfmt.exe|8ee1d73a41ab2c69\BinProductVersion(Empty) 13241300x800000000000000037237Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\numfmt.exe|8ee1d73a41ab2c69\LinkDate01/01/1970 00:00:00 13241300x800000000000000037236Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\numfmt.exe|8ee1d73a41ab2c69\Publisher(Empty) 13241300x800000000000000037235Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\numfmt.exe|8ee1d73a41ab2c69\LowerCaseLongPathc:\program files\git\usr\bin\numfmt.exe 13241300x800000000000000037234Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\nproc.exe|4b998916d3f3a9c7\BinProductVersion(Empty) 13241300x800000000000000037233Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\nproc.exe|4b998916d3f3a9c7\LinkDate01/01/1970 00:00:00 13241300x800000000000000037232Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\nproc.exe|4b998916d3f3a9c7\Publisher(Empty) 13241300x800000000000000037231Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\nproc.exe|4b998916d3f3a9c7\LowerCaseLongPathc:\program files\git\usr\bin\nproc.exe 13241300x800000000000000037230Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\nohup.exe|b6d740d02d8e649a\BinProductVersion(Empty) 13241300x800000000000000037229Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\nohup.exe|b6d740d02d8e649a\LinkDate01/01/1970 00:00:00 13241300x800000000000000037228Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\nohup.exe|b6d740d02d8e649a\Publisher(Empty) 13241300x800000000000000037227Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\nohup.exe|b6d740d02d8e649a\LowerCaseLongPathc:\program files\git\usr\bin\nohup.exe 13241300x800000000000000037226Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\nl.exe|a11f2aa66e5f8174\BinProductVersion(Empty) 13241300x800000000000000037225Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\nl.exe|a11f2aa66e5f8174\LinkDate01/01/1970 00:00:00 13241300x800000000000000037224Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\nl.exe|a11f2aa66e5f8174\Publisher(Empty) 13241300x800000000000000037223Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\nl.exe|a11f2aa66e5f8174\LowerCaseLongPathc:\program files\git\usr\bin\nl.exe 13241300x800000000000000037222Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\nice.exe|d195556bd0ad811f\BinProductVersion(Empty) 13241300x800000000000000037221Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\nice.exe|d195556bd0ad811f\LinkDate01/01/1970 00:00:00 13241300x800000000000000037220Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\nice.exe|d195556bd0ad811f\Publisher(Empty) 13241300x800000000000000037219Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\nice.exe|d195556bd0ad811f\LowerCaseLongPathc:\program files\git\usr\bin\nice.exe 13241300x800000000000000037218Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\ngettext.exe|b3b7f8b500cfd995\BinProductVersion0.19.8.0 13241300x800000000000000037217Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\ngettext.exe|b3b7f8b500cfd995\LinkDate01/01/1970 00:00:02 13241300x800000000000000037216Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\ngettext.exe|b3b7f8b500cfd995\Publisherfree software foundation 13241300x800000000000000037215Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\ngettext.exe|b3b7f8b500cfd995\LowerCaseLongPathc:\program files\git\usr\bin\ngettext.exe 13241300x800000000000000037214Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\nettle-pbkdf2.ex|97ba977fde0c62d6\BinProductVersion(Empty) 13241300x800000000000000037213Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\nettle-pbkdf2.ex|97ba977fde0c62d6\LinkDate01/01/1970 00:00:00 13241300x800000000000000037212Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\nettle-pbkdf2.ex|97ba977fde0c62d6\Publisher(Empty) 13241300x800000000000000037211Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\nettle-pbkdf2.ex|97ba977fde0c62d6\LowerCaseLongPathc:\program files\git\usr\bin\nettle-pbkdf2.exe 13241300x800000000000000037210Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\nettle-lfib-stre|884dcfac9ef75867\BinProductVersion(Empty) 13241300x800000000000000037209Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\nettle-lfib-stre|884dcfac9ef75867\LinkDate01/01/1970 00:00:00 13241300x800000000000000037208Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\nettle-lfib-stre|884dcfac9ef75867\Publisher(Empty) 13241300x800000000000000037207Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\nettle-lfib-stre|884dcfac9ef75867\LowerCaseLongPathc:\program files\git\usr\bin\nettle-lfib-stream.exe 13241300x800000000000000037206Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\nettle-hash.exe|b53503615f207ffa\BinProductVersion(Empty) 13241300x800000000000000037205Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\nettle-hash.exe|b53503615f207ffa\LinkDate01/01/1970 00:00:00 13241300x800000000000000037204Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\nettle-hash.exe|b53503615f207ffa\Publisher(Empty) 13241300x800000000000000037203Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\nettle-hash.exe|b53503615f207ffa\LowerCaseLongPathc:\program files\git\usr\bin\nettle-hash.exe 13241300x800000000000000037202Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\nano.exe|b50a21634bf0fc7\BinProductVersion(Empty) 13241300x800000000000000037201Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\nano.exe|b50a21634bf0fc7\LinkDate01/01/1970 00:00:00 13241300x800000000000000037200Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\nano.exe|b50a21634bf0fc7\Publisher(Empty) 13241300x800000000000000037199Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.402{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\nano.exe|b50a21634bf0fc7\LowerCaseLongPathc:\program files\git\usr\bin\nano.exe 13241300x800000000000000037198Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\mv.exe|929878a0fb05584e\BinProductVersion(Empty) 13241300x800000000000000037197Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\mv.exe|929878a0fb05584e\LinkDate01/01/1970 00:00:00 13241300x800000000000000037196Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\mv.exe|929878a0fb05584e\Publisher(Empty) 13241300x800000000000000037195Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\mv.exe|929878a0fb05584e\LowerCaseLongPathc:\program files\git\usr\bin\mv.exe 13241300x800000000000000037194Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msguniq.exe|630e939fcdce570c\BinProductVersion(Empty) 13241300x800000000000000037193Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msguniq.exe|630e939fcdce570c\LinkDate01/01/1970 00:00:01 13241300x800000000000000037192Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msguniq.exe|630e939fcdce570c\Publisher(Empty) 13241300x800000000000000037191Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msguniq.exe|630e939fcdce570c\LowerCaseLongPathc:\program files\git\usr\bin\msguniq.exe 13241300x800000000000000037190Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msgunfmt.exe|e224c743b2bfe999\BinProductVersion(Empty) 13241300x800000000000000037189Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msgunfmt.exe|e224c743b2bfe999\LinkDate06/19/2025 15:30:53 13241300x800000000000000037188Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msgunfmt.exe|e224c743b2bfe999\Publisher(Empty) 13241300x800000000000000037187Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msgunfmt.exe|e224c743b2bfe999\LowerCaseLongPathc:\program files\git\usr\bin\msgunfmt.exe 13241300x800000000000000037186Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msgmerge.exe|70a7277cc4533b58\BinProductVersion(Empty) 13241300x800000000000000037185Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msgmerge.exe|70a7277cc4533b58\LinkDate06/19/2025 15:30:53 13241300x800000000000000037184Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msgmerge.exe|70a7277cc4533b58\Publisher(Empty) 13241300x800000000000000037183Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msgmerge.exe|70a7277cc4533b58\LowerCaseLongPathc:\program files\git\usr\bin\msgmerge.exe 13241300x800000000000000037182Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msginit.exe|5aa0cd7045e63438\BinProductVersion(Empty) 13241300x800000000000000037181Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msginit.exe|5aa0cd7045e63438\LinkDate01/18/2021 06:51:50 13241300x800000000000000037180Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msginit.exe|5aa0cd7045e63438\Publisher(Empty) 13241300x800000000000000037179Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msginit.exe|5aa0cd7045e63438\LowerCaseLongPathc:\program files\git\usr\bin\msginit.exe 13241300x800000000000000037178Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msggrep.exe|983cdb3b51d722e3\BinProductVersion(Empty) 13241300x800000000000000037177Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msggrep.exe|983cdb3b51d722e3\LinkDate01/01/1970 00:00:00 13241300x800000000000000037176Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msggrep.exe|983cdb3b51d722e3\Publisher(Empty) 13241300x800000000000000037175Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msggrep.exe|983cdb3b51d722e3\LowerCaseLongPathc:\program files\git\usr\bin\msggrep.exe 13241300x800000000000000037174Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msgfmt.exe|b876ce85e126a312\BinProductVersion(Empty) 13241300x800000000000000037173Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msgfmt.exe|b876ce85e126a312\LinkDate06/19/2025 15:30:53 13241300x800000000000000037172Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msgfmt.exe|b876ce85e126a312\Publisher(Empty) 13241300x800000000000000037171Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msgfmt.exe|b876ce85e126a312\LowerCaseLongPathc:\program files\git\usr\bin\msgfmt.exe 13241300x800000000000000037170Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msgfilter.exe|aaac2b93f137f1ae\BinProductVersion(Empty) 13241300x800000000000000037169Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msgfilter.exe|aaac2b93f137f1ae\LinkDate01/01/1970 00:00:00 13241300x800000000000000037168Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msgfilter.exe|aaac2b93f137f1ae\Publisher(Empty) 13241300x800000000000000037167Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msgfilter.exe|aaac2b93f137f1ae\LowerCaseLongPathc:\program files\git\usr\bin\msgfilter.exe 13241300x800000000000000037166Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msgexec.exe|9c976ab4ff6e1c54\BinProductVersion(Empty) 13241300x800000000000000037165Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msgexec.exe|9c976ab4ff6e1c54\LinkDate01/01/1970 00:00:01 13241300x800000000000000037164Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msgexec.exe|9c976ab4ff6e1c54\Publisher(Empty) 13241300x800000000000000037163Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msgexec.exe|9c976ab4ff6e1c54\LowerCaseLongPathc:\program files\git\usr\bin\msgexec.exe 13241300x800000000000000037162Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msgen.exe|da6af5ac56e9716\BinProductVersion(Empty) 13241300x800000000000000037161Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msgen.exe|da6af5ac56e9716\LinkDate06/19/2025 15:30:53 13241300x800000000000000037160Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msgen.exe|da6af5ac56e9716\Publisher(Empty) 13241300x800000000000000037159Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msgen.exe|da6af5ac56e9716\LowerCaseLongPathc:\program files\git\usr\bin\msgen.exe 13241300x800000000000000037158Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msgconv.exe|be24512a01e4ec35\BinProductVersion(Empty) 13241300x800000000000000037157Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msgconv.exe|be24512a01e4ec35\LinkDate06/19/2025 15:30:53 13241300x800000000000000037156Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msgconv.exe|be24512a01e4ec35\Publisher(Empty) 13241300x800000000000000037155Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msgconv.exe|be24512a01e4ec35\LowerCaseLongPathc:\program files\git\usr\bin\msgconv.exe 13241300x800000000000000037154Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msgcomm.exe|6ef471fb1825a1cd\BinProductVersion(Empty) 13241300x800000000000000037153Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msgcomm.exe|6ef471fb1825a1cd\LinkDate06/19/2025 15:30:53 13241300x800000000000000037152Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msgcomm.exe|6ef471fb1825a1cd\Publisher(Empty) 13241300x800000000000000037151Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msgcomm.exe|6ef471fb1825a1cd\LowerCaseLongPathc:\program files\git\usr\bin\msgcomm.exe 13241300x800000000000000037150Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msgcmp.exe|7c2e229e6e1c68a8\BinProductVersion(Empty) 13241300x800000000000000037149Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msgcmp.exe|7c2e229e6e1c68a8\LinkDate05/08/2031 18:06:26 13241300x800000000000000037148Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msgcmp.exe|7c2e229e6e1c68a8\Publisher(Empty) 13241300x800000000000000037147Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msgcmp.exe|7c2e229e6e1c68a8\LowerCaseLongPathc:\program files\git\usr\bin\msgcmp.exe 13241300x800000000000000037146Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msgcat.exe|5596b37e57e3e044\BinProductVersion(Empty) 13241300x800000000000000037145Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msgcat.exe|5596b37e57e3e044\LinkDate01/01/1970 00:00:01 13241300x800000000000000037144Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msgcat.exe|5596b37e57e3e044\Publisher(Empty) 13241300x800000000000000037143Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msgcat.exe|5596b37e57e3e044\LowerCaseLongPathc:\program files\git\usr\bin\msgcat.exe 13241300x800000000000000037142Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msgattrib.exe|ef0e87f6c6fba86f\BinProductVersion(Empty) 13241300x800000000000000037141Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msgattrib.exe|ef0e87f6c6fba86f\LinkDate01/01/1970 00:00:01 13241300x800000000000000037140Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msgattrib.exe|ef0e87f6c6fba86f\Publisher(Empty) 13241300x800000000000000037139Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\msgattrib.exe|ef0e87f6c6fba86f\LowerCaseLongPathc:\program files\git\usr\bin\msgattrib.exe 13241300x800000000000000037138Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\mpicalc.exe|f96ca699905a957b\BinProductVersion(Empty) 13241300x800000000000000037137Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\mpicalc.exe|f96ca699905a957b\LinkDate01/01/1970 00:00:00 13241300x800000000000000037136Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\mpicalc.exe|f96ca699905a957b\Publisher(Empty) 13241300x800000000000000037135Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\mpicalc.exe|f96ca699905a957b\LowerCaseLongPathc:\program files\git\usr\bin\mpicalc.exe 13241300x800000000000000037134Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\mount.exe|9be5c50fa3ad3871\BinProductVersion(Empty) 13241300x800000000000000037133Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\mount.exe|9be5c50fa3ad3871\LinkDate03/26/2021 22:24:40 13241300x800000000000000037132Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\mount.exe|9be5c50fa3ad3871\Publisher(Empty) 13241300x800000000000000037131Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\mount.exe|9be5c50fa3ad3871\LowerCaseLongPathc:\program files\git\usr\bin\mount.exe 13241300x800000000000000037130Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\mktemp.exe|f571057b3b322073\BinProductVersion(Empty) 13241300x800000000000000037129Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\mktemp.exe|f571057b3b322073\LinkDate01/01/1970 00:00:00 13241300x800000000000000037128Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\mktemp.exe|f571057b3b322073\Publisher(Empty) 13241300x800000000000000037127Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\mktemp.exe|f571057b3b322073\LowerCaseLongPathc:\program files\git\usr\bin\mktemp.exe 13241300x800000000000000037126Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\mkpasswd.exe|73ea587603f838db\BinProductVersion(Empty) 13241300x800000000000000037125Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\mkpasswd.exe|73ea587603f838db\LinkDate03/26/2021 22:24:40 13241300x800000000000000037124Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\mkpasswd.exe|73ea587603f838db\Publisher(Empty) 13241300x800000000000000037123Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\mkpasswd.exe|73ea587603f838db\LowerCaseLongPathc:\program files\git\usr\bin\mkpasswd.exe 13241300x800000000000000037122Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\mknod.exe|1c9cc79f3ba29852\BinProductVersion(Empty) 13241300x800000000000000037121Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\mknod.exe|1c9cc79f3ba29852\LinkDate01/01/1970 00:00:00 13241300x800000000000000037120Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\mknod.exe|1c9cc79f3ba29852\Publisher(Empty) 13241300x800000000000000037119Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\mknod.exe|1c9cc79f3ba29852\LowerCaseLongPathc:\program files\git\usr\bin\mknod.exe 13241300x800000000000000037118Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\mkgroup.exe|b0fed08db39d16e4\BinProductVersion(Empty) 13241300x800000000000000037117Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\mkgroup.exe|b0fed08db39d16e4\LinkDate03/26/2021 22:24:40 13241300x800000000000000037116Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\mkgroup.exe|b0fed08db39d16e4\Publisher(Empty) 13241300x800000000000000037115Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\mkgroup.exe|b0fed08db39d16e4\LowerCaseLongPathc:\program files\git\usr\bin\mkgroup.exe 13241300x800000000000000037114Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\mkfifo.exe|1676140672f1cfe0\BinProductVersion(Empty) 13241300x800000000000000037113Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\mkfifo.exe|1676140672f1cfe0\LinkDate01/01/1970 00:00:00 13241300x800000000000000037112Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\mkfifo.exe|1676140672f1cfe0\Publisher(Empty) 13241300x800000000000000037111Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\mkfifo.exe|1676140672f1cfe0\LowerCaseLongPathc:\program files\git\usr\bin\mkfifo.exe 13241300x800000000000000037110Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\mkdir.exe|d166f5452ec8d3f1\BinProductVersion(Empty) 13241300x800000000000000037109Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\mkdir.exe|d166f5452ec8d3f1\LinkDate01/01/1970 00:00:00 13241300x800000000000000037108Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\mkdir.exe|d166f5452ec8d3f1\Publisher(Empty) 13241300x800000000000000037107Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\mkdir.exe|d166f5452ec8d3f1\LowerCaseLongPathc:\program files\git\usr\bin\mkdir.exe 13241300x800000000000000037106Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\mintty.exe|49e751352c5fb46d\BinProductVersion0.0.0.0 13241300x800000000000000037105Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\mintty.exe|49e751352c5fb46d\LinkDate01/01/1970 00:00:00 13241300x800000000000000037104Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\mintty.exe|49e751352c5fb46d\Publisherandy koppe / thomas wolff 13241300x800000000000000037103Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\mintty.exe|49e751352c5fb46d\LowerCaseLongPathc:\program files\git\usr\bin\mintty.exe 13241300x800000000000000037102Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\minidumper.exe|54796dc6e15198fd\BinProductVersion(Empty) 13241300x800000000000000037101Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\minidumper.exe|54796dc6e15198fd\LinkDate03/26/2021 22:24:40 13241300x800000000000000037100Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\minidumper.exe|54796dc6e15198fd\Publisher(Empty) 13241300x800000000000000037099Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\minidumper.exe|54796dc6e15198fd\LowerCaseLongPathc:\program files\git\usr\bin\minidumper.exe 13241300x800000000000000037098Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\md5sum.exe|24d7cfd4f0a567ad\BinProductVersion(Empty) 13241300x800000000000000037097Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\md5sum.exe|24d7cfd4f0a567ad\LinkDate01/01/1970 00:00:00 13241300x800000000000000037096Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\md5sum.exe|24d7cfd4f0a567ad\Publisher(Empty) 13241300x800000000000000037095Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\md5sum.exe|24d7cfd4f0a567ad\LowerCaseLongPathc:\program files\git\usr\bin\md5sum.exe 13241300x800000000000000037094Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\mac2unix.exe|fa8c232fc2ace248\BinProductVersion(Empty) 13241300x800000000000000037093Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\mac2unix.exe|fa8c232fc2ace248\LinkDate01/01/1970 00:00:00 13241300x800000000000000037092Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\mac2unix.exe|fa8c232fc2ace248\Publisher(Empty) 13241300x800000000000000037091Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\mac2unix.exe|fa8c232fc2ace248\LowerCaseLongPathc:\program files\git\usr\bin\mac2unix.exe 13241300x800000000000000037090Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\lzmainfo.exe|3070267691718925\BinProductVersion5.2.5.0 13241300x800000000000000037089Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\lzmainfo.exe|3070267691718925\LinkDate01/01/1970 00:00:00 13241300x800000000000000037088Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\lzmainfo.exe|3070267691718925\Publisherthe tukaani project <https://tukaani.org/> 13241300x800000000000000037087Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\lzmainfo.exe|3070267691718925\LowerCaseLongPathc:\program files\git\mingw64\bin\lzmainfo.exe 13241300x800000000000000037086Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\lzmadec.exe|d4a4f5d09de2ad9f\BinProductVersion5.2.5.0 13241300x800000000000000037085Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\lzmadec.exe|d4a4f5d09de2ad9f\LinkDate01/01/1970 00:00:00 13241300x800000000000000037084Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\lzmadec.exe|d4a4f5d09de2ad9f\Publisherthe tukaani project <https://tukaani.org/> 13241300x800000000000000037083Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\lzmadec.exe|d4a4f5d09de2ad9f\LowerCaseLongPathc:\program files\git\mingw64\bin\lzmadec.exe 13241300x800000000000000037082Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\lsattr.exe|e9598ad07d9f1abe\BinProductVersion(Empty) 13241300x800000000000000037081Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\lsattr.exe|e9598ad07d9f1abe\LinkDate03/26/2021 22:24:39 13241300x800000000000000037080Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\lsattr.exe|e9598ad07d9f1abe\Publisher(Empty) 13241300x800000000000000037079Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\lsattr.exe|e9598ad07d9f1abe\LowerCaseLongPathc:\program files\git\usr\bin\lsattr.exe 13241300x800000000000000037078Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\ls.exe|dfaab3a81c3b31c6\BinProductVersion(Empty) 13241300x800000000000000037077Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\ls.exe|dfaab3a81c3b31c6\LinkDate01/01/1970 00:00:00 13241300x800000000000000037076Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\ls.exe|dfaab3a81c3b31c6\Publisher(Empty) 13241300x800000000000000037075Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\ls.exe|dfaab3a81c3b31c6\LowerCaseLongPathc:\program files\git\usr\bin\ls.exe 13241300x800000000000000037074Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\logname.exe|12359a62b40825c8\BinProductVersion(Empty) 13241300x800000000000000037073Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\logname.exe|12359a62b40825c8\LinkDate01/01/1970 00:00:00 13241300x800000000000000037072Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\logname.exe|12359a62b40825c8\Publisher(Empty) 13241300x800000000000000037071Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\logname.exe|12359a62b40825c8\LowerCaseLongPathc:\program files\git\usr\bin\logname.exe 13241300x800000000000000037070Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\locate.exe|62a0c84839d4a077\BinProductVersion(Empty) 13241300x800000000000000037069Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\locate.exe|62a0c84839d4a077\LinkDate01/01/1970 00:00:00 13241300x800000000000000037068Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\locate.exe|62a0c84839d4a077\Publisher(Empty) 13241300x800000000000000037067Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\locate.exe|62a0c84839d4a077\LowerCaseLongPathc:\program files\git\usr\bin\locate.exe 13241300x800000000000000037066Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\locale.exe|5d75359b8fae4864\BinProductVersion(Empty) 13241300x800000000000000037065Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\locale.exe|5d75359b8fae4864\LinkDate03/26/2021 22:24:39 13241300x800000000000000037064Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\locale.exe|5d75359b8fae4864\Publisher(Empty) 13241300x800000000000000037063Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\locale.exe|5d75359b8fae4864\LowerCaseLongPathc:\program files\git\usr\bin\locale.exe 13241300x800000000000000037062Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\ln.exe|79dda9f517ff22bc\BinProductVersion(Empty) 13241300x800000000000000037061Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\ln.exe|79dda9f517ff22bc\LinkDate01/01/1970 00:00:00 13241300x800000000000000037060Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\ln.exe|79dda9f517ff22bc\Publisher(Empty) 13241300x800000000000000037059Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\ln.exe|79dda9f517ff22bc\LowerCaseLongPathc:\program files\git\usr\bin\ln.exe 13241300x800000000000000037058Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\link.exe|293c50e422886ac8\BinProductVersion(Empty) 13241300x800000000000000037057Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\link.exe|293c50e422886ac8\LinkDate01/01/1970 00:00:00 13241300x800000000000000037056Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\link.exe|293c50e422886ac8\Publisher(Empty) 13241300x800000000000000037055Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\link.exe|293c50e422886ac8\LowerCaseLongPathc:\program files\git\usr\bin\link.exe 13241300x800000000000000037054Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\lesskey.exe|6d817558b9a5216\BinProductVersion(Empty) 13241300x800000000000000037053Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\lesskey.exe|6d817558b9a5216\LinkDate01/01/1970 00:00:00 13241300x800000000000000037052Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\lesskey.exe|6d817558b9a5216\Publisher(Empty) 13241300x800000000000000037051Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\lesskey.exe|6d817558b9a5216\LowerCaseLongPathc:\program files\git\usr\bin\lesskey.exe 13241300x800000000000000037050Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\lessecho.exe|3b7a4aa7df4af94e\BinProductVersion(Empty) 13241300x800000000000000037049Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\lessecho.exe|3b7a4aa7df4af94e\LinkDate01/01/1970 00:00:00 13241300x800000000000000037048Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\lessecho.exe|3b7a4aa7df4af94e\Publisher(Empty) 13241300x800000000000000037047Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\lessecho.exe|3b7a4aa7df4af94e\LowerCaseLongPathc:\program files\git\usr\bin\lessecho.exe 13241300x800000000000000037046Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\less.exe|a02ef69e95f97e25\BinProductVersion(Empty) 13241300x800000000000000037045Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\less.exe|a02ef69e95f97e25\LinkDate01/01/1970 00:00:00 13241300x800000000000000037044Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\less.exe|a02ef69e95f97e25\Publisher(Empty) 13241300x800000000000000037043Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\less.exe|a02ef69e95f97e25\LowerCaseLongPathc:\program files\git\usr\bin\less.exe 13241300x800000000000000037042Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\ldh.exe|da4d63a2fca071c0\BinProductVersion(Empty) 13241300x800000000000000037041Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.386{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\ldh.exe|da4d63a2fca071c0\LinkDate03/26/2021 22:24:41 13241300x800000000000000037040Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.371{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\ldh.exe|da4d63a2fca071c0\Publisher(Empty) 13241300x800000000000000037039Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.371{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\ldh.exe|da4d63a2fca071c0\LowerCaseLongPathc:\program files\git\usr\bin\ldh.exe 13241300x800000000000000037038Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.371{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\ldd.exe|15068ec08ef3ecfc\BinProductVersion(Empty) 13241300x800000000000000037037Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.371{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\ldd.exe|15068ec08ef3ecfc\LinkDate03/26/2021 22:24:39 13241300x800000000000000037036Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.371{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\ldd.exe|15068ec08ef3ecfc\Publisher(Empty) 13241300x800000000000000037035Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.371{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\ldd.exe|15068ec08ef3ecfc\LowerCaseLongPathc:\program files\git\usr\bin\ldd.exe 13241300x800000000000000037034Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.371{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\kill.exe|4bade27621c021e4\BinProductVersion(Empty) 13241300x800000000000000037033Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.371{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\kill.exe|4bade27621c021e4\LinkDate03/26/2021 22:24:39 13241300x800000000000000037032Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.371{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\kill.exe|4bade27621c021e4\Publisher(Empty) 13241300x800000000000000037031Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.371{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\kill.exe|4bade27621c021e4\LowerCaseLongPathc:\program files\git\usr\bin\kill.exe 13241300x800000000000000037030Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.371{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\kbxutil.exe|1308e71e0c8d3207\BinProductVersion(Empty) 13241300x800000000000000037029Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.371{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\kbxutil.exe|1308e71e0c8d3207\LinkDate01/01/1970 00:00:00 13241300x800000000000000037028Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.371{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\kbxutil.exe|1308e71e0c8d3207\Publisher(Empty) 13241300x800000000000000037027Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.371{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\kbxutil.exe|1308e71e0c8d3207\LowerCaseLongPathc:\program files\git\usr\bin\kbxutil.exe 13241300x800000000000000037026Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.371{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\join.exe|dc913e518f010b9e\BinProductVersion(Empty) 13241300x800000000000000037025Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.371{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\join.exe|dc913e518f010b9e\LinkDate01/01/1970 00:00:00 13241300x800000000000000037024Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.371{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\join.exe|dc913e518f010b9e\Publisher(Empty) 13241300x800000000000000037023Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.371{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\join.exe|dc913e518f010b9e\LowerCaseLongPathc:\program files\git\usr\bin\join.exe 13241300x800000000000000037022Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.371{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\install.exe|6fbae492ae887311\BinProductVersion(Empty) 13241300x800000000000000037021Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.371{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\install.exe|6fbae492ae887311\LinkDate01/01/1970 00:00:00 13241300x800000000000000037020Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.371{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\install.exe|6fbae492ae887311\Publisher(Empty) 13241300x800000000000000037019Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.371{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\install.exe|6fbae492ae887311\LowerCaseLongPathc:\program files\git\usr\bin\install.exe 13241300x800000000000000037018Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.371{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\infotocap.exe|b30daf4370dfb24c\BinProductVersion(Empty) 13241300x800000000000000037017Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.371{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\infotocap.exe|b30daf4370dfb24c\LinkDate01/01/1970 00:00:00 13241300x800000000000000037016Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.371{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\infotocap.exe|b30daf4370dfb24c\Publisher(Empty) 13241300x800000000000000037015Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.371{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\infotocap.exe|b30daf4370dfb24c\LowerCaseLongPathc:\program files\git\usr\bin\infotocap.exe 13241300x800000000000000037014Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.371{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\infocmp.exe|bf56519423b7f5b4\BinProductVersion(Empty) 13241300x800000000000000037013Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.371{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\infocmp.exe|bf56519423b7f5b4\LinkDate01/01/1970 00:00:00 13241300x800000000000000037012Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PubSetValue2021-09-10 14:42:14.371{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\infocmp.exe|bf56519423b7f5b4\Publisher(Empty) 13241300x800000000000000037011Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-PathSetValue2021-09-10 14:42:14.371{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\infocmp.exe|bf56519423b7f5b4\LowerCaseLongPathc:\program files\git\usr\bin\infocmp.exe 13241300x800000000000000037010Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-VerSetValue2021-09-10 14:42:14.371{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\id.exe|58d5aeed1760e581\BinProductVersion(Empty) 13241300x800000000000000037009Microsoft-Windows-Sysmon/Operationalwin-dc-387.attackrange.localInvDB-CompileTimeClaimSetValue2021-09-10 14:42:14.371{7BD73061-6EB6-613B-1907-00000000F001}6620C:\Windows\system32\compattelrunner.exe\REGISTRY\A\{1a038503-3218-d821-aac7-04bc27d90010}\Root\InventoryApplicationFile\id.exe|58d5aeed1760e581\LinkDate01/01/1970 00:00:00