SigmaHQ/wazuh/rules/sigma_win_scm_database_handle_failure.yml
joker2013 50379800f2 123
2020-12-03 01:43:30 +03:00

16 lines
423 B
YAML

alert:
- debug
description: Detects non-system users failing to get a handle of the SCM database.
filter:
- query:
query_string:
query: (data.win.system.eventID:"4656" AND object_type:"SC_MANAGER\ OBJECT" AND object_name:"servicesactive" AND Keywords:"Audit\ Failure" AND SubjectLogonId:"0x3e4")
index: wazuh-alerts-3.x-*
name: 13addce7-47b2-4ca0-a98f-1de964d1d669_0
priority: 1
realert:
minutes: 0
type: any