Elastic high stable kql
Sensitive Privilege SeEnableDelegationPrivilege assigned to a Principal
Identifies the assignment of the SeEnableDelegationPrivilege sensitive "user right" to a security principal. This right enables computer and user accounts to be trusted for delegation. Attackers can abuse it to compromise Active Directory accounts and elevate their privileges.
Detection Logic
event.code:4704 and host.os.type:"windows" and winlog.event_data.PrivilegeList:"SeEnableDelegationPrivilege" Field Validations
Loading…
Comments (0)
Loading comments...