Files
sigma-rules/rules/windows
Simon 250bb4cc27 Add Rule to Detect User creation via Eventlog (#794)
* Add Rule to Detect User creation via Eventlog

* Apply suggestions from code review

Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com>

* Update persistence_user_account_creation_event_logs.toml

* update with fp info

* Update persistence_user_account_creation_event_logs.toml

* Update rules/windows/persistence_user_account_creation_event_logs.toml

Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com>
Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com>
2021-02-10 15:48:33 -05:00
..