Merge pull request #1900 from ZikyHD/add_fields
Add fields to event log cleared
This commit is contained in:
@@ -18,6 +18,9 @@ detection:
|
||||
EventID: 1102
|
||||
condition: selection
|
||||
fields:
|
||||
- fields in the log source that are important to investigate further
|
||||
- SubjectLogonId
|
||||
- SubjectUserName
|
||||
- SubjectUserSid
|
||||
- SubjectDomainName
|
||||
falsepositives:
|
||||
- Legitimate administrative activity
|
||||
|
||||
Reference in New Issue
Block a user