Update win_susp_local_anon_logon_created.yml

This commit is contained in:
Jonhnathan 2020-10-27 22:00:42 -03:00 committed by GitHub
parent 3eea825898
commit 61ccdc598d
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -18,7 +18,9 @@ logsource:
detection:
selection:
EventID: 4720
SAMAccountName|contains: 'ANONYMOUS*LOGON'
SAMAccountName|contains|all:
- 'ANONYMOUS'
- 'LOGON'
condition: selection
falsepositives:
- Unknown