Detection rules › By event

Microsoft-Windows-Security-Auditing Event ID 4656

39 detection rules reference this event. View event page.

Sigma (18)

Elastic (1)

Splunk (15)

Kusto (4)

YARA-L (1)