OTRF / ThreatHunter-Playbook

A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.
MIT License
3.97k stars 803 forks source link

Added new events and observations to remote_desktop_logon #29

Closed Cyb3rSn0rlax closed 2 years ago

Cyb3rSn0rlax commented 5 years ago

Added some new events and observations to remote_desktop_logon :

And some observation : | WinEvent | 4624 | LogonType | 12 | hilo21 | | WinEvent | 4624 | LogonType | 7 | hilo21 | | WinEvent | 21, 22 | Source Network Address | is NOT 'LOCAL' | hilo21 | | WinEvent | 4656 | Object Name | C:\Windows\Prefetch\RDPCLIP.EXE-[RANDOM].pf | hilo21 |

Cyb3rWard0g commented 2 years ago

Hello @H1L021 ! It has been a while, but better late than never ;) . I will create an issue to create a similar analytic but in the current format of the project. I appreciate your hard work and contribution 🙏🏾