mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 01:45:21 +00:00
Update win_account_discovery.yml
This commit is contained in:
parent
eda5298457
commit
edb98f2781
@ -3,7 +3,7 @@ description: Detect priv users or groups recon based on 4661 eventid and known p
|
||||
references:
|
||||
- https://blog.menasec.net/2019/02/threat-hunting-5-detecting-enumeration.html
|
||||
tags:
|
||||
- attack.account_discovery
|
||||
- attack.discovery
|
||||
- attack.t1087
|
||||
status: experimental
|
||||
author: Samir Bousseaden
|
||||
|
Loading…
Reference in New Issue
Block a user