Detection rules › By event
Microsoft-Windows-Security-Auditing Event ID 4624
Sigma (29)
- Active Directory honeypot used for lateral movement
- Admin User Remote Logon
- Administrator login impersonation with forged Golden ticket
- Anonymous access performed to multiple targets
- Anonymous login (RottenPotatoNG)
- Azure Windows virtual machine login via serial console
- Detection of default a Windows host name in login attempts
- DiagTrackEoP Default Login Username
- Exchange server impersonation via PrivExchange relay attack
- External Remote RDP Logon from Public IP
- External Remote SMB Logon from Public IP
- Hacktool Ruler
- Metasploit SMB Authentication
- Mimikatz Pass-the-hash login
- NetSYnc attack
- Network login performed to multiple targets
- Outgoing Logon with New Credentials
- Pass the Hash Activity 2
- Potential Access Token Abuse
- Potential Privilege Escalation via Local Kerberos Relay over LDAP
- Potential Remote WMI ActiveScriptEventConsumers Activity
- Privilege escalation via runas (command)
- RDP Login from Localhost
- RottenPotato Like Attack Pattern
- Success login attempt on a Windows OpenSSH server
- Successful Account Login Via WMI
- Successful Overpass the Hash Attempt
- Suspicious anonymous login (domain specified)
- User password change without previous password known - SetNTLM (Mimikatz)
Elastic (11)
- Account Password Reset Remotely
- Multiple Logon Failure Followed by Logon Success
- Potential Account Takeover - Logon from New Source IP
- Potential Account Takeover - Mixed Logon Types
- Potential Computer Account NTLM Relay Activity
- Potential Kerberos Relay Attack against a Computer Account
- Potential NTLM Relay Attack against a Computer Account
- Potential Pass-the-Hash (PtH) Attempt
- Process Creation via Secondary Logon
- Remote Windows Service Installed
- Service Creation via Local Kerberos Authentication
Splunk (20)
- Detect Password Spray Attack Behavior From Source
- Detect Password Spray Attack Behavior On User
- Multiple Host logons (Windows Event Log)
- Pass-the-Hash (Windows Event Log)
- Potential EternalBlue via Metasploit (Windows Event Log)
- Potential Exposed SMB_RDP Port - Windows (Windows Event Log)
- Potential SMB Activity from External IP - Windows (Windows Event Log)
- SecretsDump Credential Harvest (Windows Event Log)
- Suspicious Spool Authentication (Windows Event Log)
- Unusual Number of Remote Endpoint Authentication Events
- Windows AD Domain Controller Promotion
- Windows AD Replication Request Initiated by User Account
- Windows AD Replication Request Initiated from Unsanctioned Location
- Windows AD Short Lived Domain Controller SPN Attribute
- Windows AD Suspicious Attribute Modification
- Windows Identify PowerShell Web Access IIS Pool
- Windows Kerberos Local Successful Logon
- Windows Local Administrator Credential Stuffing
- Windows Rapid Authentication On Multiple Hosts
- Windows RDP Login Session Was Established
Kusto (24)
- Brute force attack against user credentials (Uses Authentication Normalization)
- Detect service account login on new device
- EatonForeseer - Unauthorized Logins
- Failed AzureAD logons but success logon to host
- Gain Code Execution on ADFS Server via Remote WMI Execution
- Gain Code Execution on ADFS Server via SMB + Remote Service or Scheduled Task
- Multiple RDP connections from Single System
- Non Domain Controller Active Directory Replication
- NTLM Relay Attack
- Password Spray
- Password Spraying
- Potential NTLM Relay Attack to Domain Controller
- Potential Password Spray Attack (Uses Authentication Normalization)
- Potential Remote Desktop Tunneling
- Potentially Relayed NTLM Authentication - Microsoft Defender for Endpoint
- Potentially Relayed NTLM Authentication - Microsoft Sentinel
- Potentially Relayed NTLM Authentication - Microsoft Sentinel
- Rare RDP Connections
- RDP Nesting
- SecurityEvent - Multiple authentication failures followed by a success
- Service Accounts Performing Remote PS
- Sign-ins from IPs that attempt sign-ins to disabled accounts (Uses Authentication Normalization)
- Starting or Stopping HealthService to Avoid Detection
- User login from different countries within 3 hours (Uses Authentication Normalization)
YARA-L (12)
- ADFS DKM Key Access
- GCP_Uunauthorized_GKE_Pod_Token_Endpoint_Usage
- GeoIP User Login From Multiple States Or Countries
- Logins From Terminated Employees
- MITRE ATT&CK T1110.001 Windows Repeated Authentication Failures Before Successful One
- MITRE ATT&CK T1110.001 Windows Repeated Authentication Failures Before Successful One With User Entity
- MITRE ATT&CK T1110.003 RW Windows Password Spray
- Okta Multiple Failed Requests To Access Applications
- sap break glass account login
- sap impossible travel
- sap multi terminal logon
- Windows Short Term Account Use