Skip to content

Commit 2f9fc76

Browse files
committed
feat(rules/windows): update adfs, certificate services, sid history and smbv1 rules
1 parent aab1b44 commit 2f9fc76

4 files changed

Lines changed: 4 additions & 4 deletions

File tree

‎rules/windows/adfs_authentication_anomalies.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ description: |
2424
5. Consider implementing IP-based blocking if malicious activity is confirmed
2525
6. Review ADFS configuration for security hardening opportunities
2626
7. Correlate with other authentication events across the domain
27-
where: equals("log.providerName", "AD FS") && (equals("log.eventId", "411") || equals("log.eventId", "342") || equals("log.eventId", "516")) && contains("log.message", "token validation failed")
27+
where: equals("log.providerName", "AD FS") && (equals("log.eventCode", "342") || equals("log.eventCode", "516")) && contains("log.message", "token validation failed")
2828
afterEvents:
2929
- indexPattern: v11-log-wineventlog-*
3030
with:

‎rules/windows/certificate_services_abuse.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ description: |
2424
5. Examine the requesting host for signs of compromise
2525
6. Consider revoking any suspicious certificates issued
2626
7. Validate Certificate Authority security configurations and access controls
27-
where: (equals("log.eventId", "4886") || equals("log.eventId", "4887")) && equals("log.providerName", "Microsoft-Windows-Security-Auditing") && (contains("log.eventDataSubjectUserName", "$") || equals("log.eventDataSubjectUserName", "ANONYMOUS LOGON"))
27+
where: (equals("log.eventCode", "4886") || equals("log.eventCode", "4887")) && equals("log.providerName", "Microsoft-Windows-Security-Auditing") && (contains("log.eventDataSubjectUserName", "$") || equals("log.eventDataSubjectUserName", "ANONYMOUS LOGON"))
2828
groupBy:
2929
- lastEvent.log.eventDataSubjectUserName
3030
- origin.host

‎rules/windows/sid_history_injection.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,7 @@ description: |
2727
6. Consider resetting the target account password and removing unauthorized SID History entries
2828
7. Review domain administrator accounts and privileged group memberships for anomalies
2929
where: |
30-
oneOf("log.eventId", ["4765", "4766"]) &&
30+
oneOf("log.eventCode", ["4765", "4766"]) &&
3131
equals("log.channel", "Security")
3232
groupBy:
3333
- origin.host

‎rules/windows/smbv1_usage_detection.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ description: |
2424
5. Plan migration to SMBv2/SMBv3 and disable SMBv1 on all systems where possible
2525
6. Monitor for any lateral movement patterns that may indicate ongoing compromise
2626
7. Consider implementing network segmentation to limit exposure if SMBv1 cannot be immediately disabled
27-
where: equals("log.eventId", "3000") && equals("log.providerName", "Microsoft-Windows-SMBServer") && contains("log.message", "SMB1")
27+
where: equals("log.eventCode", "3000") && equals("log.providerName", "Microsoft-Windows-SMBServer") && contains("log.message", "SMB1")
2828
groupBy:
2929
- origin.host
3030
- origin.ip

0 commit comments

Comments
 (0)