palantir / windows-event-forwarding

A repository for using windows event forwarding for incident detection and response
Other
1.22k stars 268 forks source link

Add ID 6041 - CVE-2018-0886 #41

Closed mdecrevoisier closed 2 years ago

mdecrevoisier commented 4 years ago

Allow to catch incorrect RDP authentication from non protected or attacked hosts https://support.microsoft.com/en-us/help/4093492/credssp-updates-for-cve-2018-0886-march-13-2018