From dd558e941caa4afa071fe983cbdb66c75dbc3afc Mon Sep 17 00:00:00 2001 From: Florian Roth Date: Tue, 14 Mar 2017 14:53:03 +0100 Subject: [PATCH] Rule: Access to ADMIN$ share --- .../windows/builtin/win_admin_share_access.yml | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) create mode 100644 rules/windows/builtin/win_admin_share_access.yml diff --git a/rules/windows/builtin/win_admin_share_access.yml b/rules/windows/builtin/win_admin_share_access.yml new file mode 100644 index 000000000..8c1ec3dc9 --- /dev/null +++ b/rules/windows/builtin/win_admin_share_access.yml @@ -0,0 +1,17 @@ +title: Access to ADMIN$ Share +description: +status: experimental +author: Florian Roth +logsource: + product: windows + service: security +detection: + selection: + EventID: 4732 + GroupName: Administrators + filter: + SubjectAccountName: '*$' + condition: selection and not filter +falsepositives: + - Legitimate administrative activity +level: low