Rule: Access to ADMIN$ share
This commit is contained in:
@@ -0,0 +1,17 @@
|
||||
title: Access to ADMIN$ Share
|
||||
description:
|
||||
status: experimental
|
||||
author: Florian Roth
|
||||
logsource:
|
||||
product: windows
|
||||
service: security
|
||||
detection:
|
||||
selection:
|
||||
EventID: 4732
|
||||
GroupName: Administrators
|
||||
filter:
|
||||
SubjectAccountName: '*$'
|
||||
condition: selection and not filter
|
||||
falsepositives:
|
||||
- Legitimate administrative activity
|
||||
level: low
|
||||
Reference in New Issue
Block a user