Google Chronicle unknown experimental yara-l

group_modification_logging

Configure systems to issue a log entry and alert when an account is added to or removed from any group assigned administrative privileges. Sigma detects Event ID 4728 indicates a ‘Member is added to a Security Group’. Event ID 4729 indicates a ‘Member is removed from a Security enabled-group’. Event ID 4730 indicates a‘Security Group is deleted’. The case is not applicable for Unix OS. Supported OS - Windows 2008 R2 and 7, Windows 2012 R2 and 8.1, Windows 2016 and 10 Windows Server 2019, Windows Server 2000, Windows 2003 and XP. License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.

View Source

Detection Logic

rule group_modification_logging {
 meta:
    author = "Alexandr Yampolskyi"
    description = "Configure systems to issue a log entry and alert when an account is added to or removed from any group assigned administrative privileges. Sigma detects Event ID 4728 indicates a ‘Member is added to a Security Group’. Event ID 4729 indicates a ‘Member is removed from a Security enabled-group’. Event ID 4730 indicates a‘Security Group is deleted’. The case is not applicable for Unix OS. Supported OS - Windows 2008 R2 and 7, Windows 2012 R2 and 8.1, Windows 2016 and 10 Windows Server 2019, Windows Server 2000, Windows 2003 and XP.  License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md."
    reference = "https://tdm.socprime.com/tdm/info/OdYpGwZmuXva"
    version = "0.01"
    created = "2021-03-09"
    product = "windows"
    service = "security"
    mitre = "CSC4, CSC4.8, GDPR Art 32.1, GDPR Art 32.2, NIST CSF 1.1 PR.AC-4, NIST CSF 1.1 PR.AT-2, NIST CSF 1.1 PR.MA-2, NIST CSF 1.1 PR.PT-3, ISO 27002-2013 A.9.1.1, ISO 27002-2013 A.9.2.2, ISO 27002-2013 A.9.2.3, ISO 27002-2013 A.9.2.4, ISO 27002-2013 A.9.2.5, ISO 27002-2013 A.9.2.6, ISO 27002-2013 A.9.3.1, ISO 27002-2013 A.9.4.1, ISO 27002-2013 A.9.4.2, ISO 27002-2013 A.9.4.3, ISO 27002-2013 A.9.4.4, PCI DSS 3.2 2.1, PCI DSS 3.2 7.1, PCI DSS 3.2 7.2, PCI DSS 3.2 7.3, PCI DSS 3.2 8.1, PCI DSS 3.2 8.2, PCI DSS 3.2 8.3, PCI DSS 3.2 8.7"

  events:
($selection.metadata.product_event_type = "4728" or $selection.metadata.product_event_type = "4729" or $selection.metadata.product_event_type = "4730" or $selection.metadata.product_event_type = "633" or $selection.metadata.product_event_type = "632" or $selection.metadata.product_event_type = "634")

  condition:
    $selection
}

Field Validations

Loading…

Comments (0)

Loading comments...