Update win_account_discovery.yml
This commit is contained in:
@@ -33,7 +33,7 @@ detection:
|
||||
- '-555'
|
||||
- ObjectName|contains: 'admin'
|
||||
filter:
|
||||
- SubjectUserName|endswith: '$'
|
||||
SubjectUserName|endswith: '$'
|
||||
condition: selection and selection_object and not filter
|
||||
falsepositives:
|
||||
- If source account name is not an admin then its super suspicious
|
||||
|
||||
Reference in New Issue
Block a user