fix invalid case SamAccountName

This commit is contained in:
frack113 2021-07-06 15:43:07 +02:00
parent bcf2bf2e4d
commit 9cf1d3d5f3

View File

@ -6,7 +6,7 @@ references:
- https://twitter.com/SBousseaden/status/1189469425482829824
author: James Pemberton / @4A616D6573
date: 2019/10/31
modified: 2020/08/23
modified: 2021/07/06
tags:
- attack.persistence
- attack.t1136 # an old one
@ -18,7 +18,7 @@ logsource:
detection:
selection:
EventID: 4720
SAMAccountName|contains|all:
SamAccountName|contains|all:
- 'ANONYMOUS'
- 'LOGON'
condition: selection