Rule: Access to ADMIN$ share

This commit is contained in:
Florian Roth
2017-03-14 14:53:03 +01:00
parent 3eae1f2710
commit dd558e941c
@@ -0,0 +1,17 @@
title: Access to ADMIN$ Share
description:
status: experimental
author: Florian Roth
logsource:
product: windows
service: security
detection:
selection:
EventID: 4732
GroupName: Administrators
filter:
SubjectAccountName: '*$'
condition: selection and not filter
falsepositives:
- Legitimate administrative activity
level: low