quadrantsec / sagan-rules

GNU General Public License v2.0
28 stars 28 forks source link

Azure AD rules created and windows-sysmon lsass.exe credential dump rule updated #356

Closed GeekCharmiing closed 6 months ago

GeekCharmiing commented 6 months ago

msapi-azuread.rules Created rules for detected when a Global Administrator, Security Administrator, Security Operator or a User Administrator is created

azure-eventhub-ad.rules Created rules for detected when a Global Administrator, Security Administrator, Security Operator or a User Administrator is created

windows-sysmon.rules Updated rule 5014601 to only look for instances of lsass.exe in an effort to prevent false positives

.last_used_sid Updated sid