Anvilogic high experimental spl
Account set to active via Net.exe [splunk-winevent]
Adversaries may obtain and abuse credentials of a default or disabled account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. -- Threat Actor Association: Unfading Sea Haze - Software Association: RansomHub -- Atomics T1078.001 Test#1 Atomics T1078.001 Test#2 Atomics T1564 Test#2
Detection Logic
`get_endpoint_data` `get_endpoint_data_winevent` (TERM(EventCode=4688)
OR "EventID>4688<") ("/active:yes"
OR "/active:y")
| table _time, host, user, signature_id, process, process_*, parent_process_*, src_ip, dest_ip, dest_port `group_events("host", 1)` Field Validations
Loading…
Comments (0)
Loading comments...