mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-06 17:35:19 +00:00
Further improved Windows user creation rule
* Decreased level * Fixed field names * Added false positive possibility
This commit is contained in:
parent
80f45349ed
commit
765fe9dcd9
@ -16,10 +16,11 @@ detection:
|
||||
condition: selection
|
||||
fields:
|
||||
- EventCode
|
||||
- Account_Name
|
||||
- Account_Domain
|
||||
- AccountName
|
||||
- AccountDomain
|
||||
falsepositives:
|
||||
- Domain Controller Logs
|
||||
level: high
|
||||
- Local accounts managed by privileged account management tools
|
||||
level: low
|
||||
|
||||
|
||||
|
Loading…
Reference in New Issue
Block a user