Files
blue-team-tools/rules
Florian Roth f80cf52982 Expired happens too often
Back then when we created this rule, we noticed that "logon attempt with expired account" happens pretty often, so we decided to not include it. All event codes in this rule did not appear in a 30 day time period and therefore the rule's "level" was set to "high".
2019-03-02 07:20:59 +01:00
..
2019-02-24 14:04:44 +01:00
2018-08-08 15:58:19 +02:00
2019-02-12 10:33:33 +01:00
2019-01-22 08:49:10 +01:00
2019-03-02 07:20:59 +01:00