Enabled User Right in AD to Control User Objects
Last updated on:
In this page
About the rule
Rule Type
Standard
Rule Description
Detects scenario where if a user is assigned the SeEnableDelegationPrivilege right in Active Directory it would allow control of other AD user objects.
Severity
Trouble
Rule Requirement
Criteria
Action1: actionname = "User Right Assigned" AND ACCESSRIGHT contains "SeEnableDelegationPrivilege" select Action1.HOSTNAME,Action1.MESSAGE,Action1.TARGETUSER,Action1.USERNAME,Action1.DOMAIN
Detection
Execution Mode
realtime
Log Sources
Active Directory
Author
@neu5ron


