Detection rules › By event

Microsoft-Windows-Security-Auditing Event ID 4657

46 detection rules reference this event. View event page.

Sigma (5)

Splunk (14)

Kusto (12)

YARA-L (15)