Merge pull request #1110 from vburov/patch-11
Update win_disable_event_logging.yml
This commit is contained in:
@@ -16,7 +16,9 @@ logsource:
|
||||
detection:
|
||||
selection:
|
||||
EventID: 4719
|
||||
AuditPolicyChanges: 'removed'
|
||||
AuditPolicyChanges|contains:
|
||||
- '%%8448' # This is "Success removed"
|
||||
- '%%8450' # This is "Failure removed"
|
||||
condition: selection
|
||||
falsepositives:
|
||||
- Unknown
|
||||
|
||||
Reference in New Issue
Block a user