Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Tuning] DCSync Rules - 4662 event.action #3410

Merged
merged 2 commits into from
Jan 30, 2024
Merged

[Tuning] DCSync Rules - 4662 event.action #3410

merged 2 commits into from
Jan 30, 2024

Conversation

Samirbous
Copy link
Contributor

@Samirbous Samirbous commented Jan 29, 2024

add new event action for 4662 object-operation-performed. https://elasticstack.slack.com/archives/C018PDGK6JU/p1706360190882899

@Samirbous Samirbous added Rule: Tuning tweaking or tuning an existing rule OS: Windows windows related rules labels Jan 29, 2024
@Samirbous Samirbous self-assigned this Jan 29, 2024
@Samirbous Samirbous merged commit d7f4d79 into main Jan 30, 2024
13 checks passed
@Samirbous Samirbous deleted the Samirbous-patch-1 branch January 30, 2024 11:43
protectionsmachine pushed a commit that referenced this pull request Jan 30, 2024
* Update credential_access_dcsync_newterm_subjectuser.toml

* Update credential_access_dcsync_replication_rights.toml

Removed changes from:
- rules/windows/credential_access_dcsync_newterm_subjectuser.toml

(selectively cherry picked from commit d7f4d79)
protectionsmachine pushed a commit that referenced this pull request Jan 30, 2024
* Update credential_access_dcsync_newterm_subjectuser.toml

* Update credential_access_dcsync_replication_rights.toml

(cherry picked from commit d7f4d79)
protectionsmachine pushed a commit that referenced this pull request Jan 30, 2024
* Update credential_access_dcsync_newterm_subjectuser.toml

* Update credential_access_dcsync_replication_rights.toml

(cherry picked from commit d7f4d79)
protectionsmachine pushed a commit that referenced this pull request Jan 30, 2024
* Update credential_access_dcsync_newterm_subjectuser.toml

* Update credential_access_dcsync_replication_rights.toml

(cherry picked from commit d7f4d79)
protectionsmachine pushed a commit that referenced this pull request Jan 30, 2024
* Update credential_access_dcsync_newterm_subjectuser.toml

* Update credential_access_dcsync_replication_rights.toml

(cherry picked from commit d7f4d79)
protectionsmachine pushed a commit that referenced this pull request Jan 30, 2024
* Update credential_access_dcsync_newterm_subjectuser.toml

* Update credential_access_dcsync_replication_rights.toml

(cherry picked from commit d7f4d79)
protectionsmachine pushed a commit that referenced this pull request Jan 30, 2024
* Update credential_access_dcsync_newterm_subjectuser.toml

* Update credential_access_dcsync_replication_rights.toml

(cherry picked from commit d7f4d79)
protectionsmachine pushed a commit that referenced this pull request Jan 30, 2024
* Update credential_access_dcsync_newterm_subjectuser.toml

* Update credential_access_dcsync_replication_rights.toml

(cherry picked from commit d7f4d79)
protectionsmachine pushed a commit that referenced this pull request Jan 30, 2024
* Update credential_access_dcsync_newterm_subjectuser.toml

* Update credential_access_dcsync_replication_rights.toml

(cherry picked from commit d7f4d79)
protectionsmachine pushed a commit that referenced this pull request Jan 30, 2024
* Update credential_access_dcsync_newterm_subjectuser.toml

* Update credential_access_dcsync_replication_rights.toml

(cherry picked from commit d7f4d79)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
backport: auto Domain: Endpoint OS: Windows windows related rules Rule: Tuning tweaking or tuning an existing rule
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants