From 190b4ea67e5d796ca47e6f407f5861d2fdf20b19 Mon Sep 17 00:00:00 2001 From: Brent Murphy <56412096+bm11100@users.noreply.github.com> Date: Wed, 10 Feb 2021 16:41:49 -0500 Subject: [PATCH] [Rule Tuning] User Added to Privileged Group in Active Directory (#941) * Update persistence_user_account_added_to_privileged_group_ad.toml * updated date --- ...persistence_user_account_added_to_privileged_group_ad.toml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/rules/windows/persistence_user_account_added_to_privileged_group_ad.toml b/rules/windows/persistence_user_account_added_to_privileged_group_ad.toml index c0fbfae13..12011b76b 100644 --- a/rules/windows/persistence_user_account_added_to_privileged_group_ad.toml +++ b/rules/windows/persistence_user_account_added_to_privileged_group_ad.toml @@ -1,10 +1,10 @@ [metadata] creation_date = "2021/01/09" maturity = "production" -updated_date = "2021/01/09" +updated_date = "2021/02/10" [rule] -author = ["Skoetting"] +author = ["Elastic", "Skoetting"] description = """ Identifies a user being added to a privileged group in Active Directory. Privileged accounts and groups in Active Directory are those to which powerful rights, privileges, and permissions are granted that allow them to perform nearly