Standard User In High Privileged Group
Last updated on:
In this page
About the rule
Rule Type
Standard
Rule Description
Detect standard users login that are part of high privileged groups such as the Administrator group
Severity
Trouble
Rule Requirement
Criteria
Action1: actionname = "LSA Server Operation" AND (SECURITYID startswith "S-1-5-21-" AND SIDHISTORY contains "S-1-5-32-544,-500},-518},-519}") AND SECURITYID notendswith "-500,-518,-519" select Action1.HOSTNAME,Action1.MESSAGE,Action1.SIDHISTORY,Action1.USERNAME
Detection
Execution Mode
realtime
Log Sources
Active Directory
Author
frack113


