Detection rules › By event

Microsoft-Windows-Security-Auditing Event ID 4697

35 detection rules reference this event. View event page.

Sigma (27)

Elastic (4)

Splunk (2)

Kusto (1)

YARA-L (1)