Rule fixes
This commit is contained in:
@@ -12,7 +12,7 @@ logsource:
|
||||
detection:
|
||||
selection1:
|
||||
EventID: 4738
|
||||
AllowedToDelegateTo: '*'
|
||||
AllowedToDelegateTo: (any)
|
||||
selection2:
|
||||
EventID: 5136
|
||||
AttributeLDAPDisplayName: 'msDS-AllowedToDelegateTo'
|
||||
|
||||
@@ -27,4 +27,4 @@ fields:
|
||||
- ParentCommandLine
|
||||
falsepositives:
|
||||
- Will need to be tuned. If using Splunk, I recommend | stats count by Computer,CommandLine following the search for easy hunting by computer/CommandLine.
|
||||
level: medium
|
||||
level: low
|
||||
|
||||
Reference in New Issue
Block a user