mirror of
https://github.com/Yamato-Security/WELA.git
synced 2025-12-06 17:22:50 +01:00
Automated update
This commit is contained in:
@@ -105,8 +105,8 @@
|
|||||||
"id": "60d768ca-33e8-4f34-b967-14fd7aa18a22",
|
"id": "60d768ca-33e8-4f34-b967-14fd7aa18a22",
|
||||||
"level": "informational",
|
"level": "informational",
|
||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
"0CCE9227-69AE-11D9-BED3-505054503030",
|
"0CCE9226-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE9226-69AE-11D9-BED3-505054503030"
|
"0CCE9227-69AE-11D9-BED3-505054503030"
|
||||||
],
|
],
|
||||||
"title": "Task Created"
|
"title": "Task Created"
|
||||||
},
|
},
|
||||||
@@ -118,8 +118,8 @@
|
|||||||
"id": "de5ed02e-e7b5-47a0-a35c-06a907c988e4",
|
"id": "de5ed02e-e7b5-47a0-a35c-06a907c988e4",
|
||||||
"level": "informational",
|
"level": "informational",
|
||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
"0CCE9227-69AE-11D9-BED3-505054503030",
|
"0CCE9226-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE9226-69AE-11D9-BED3-505054503030"
|
"0CCE9227-69AE-11D9-BED3-505054503030"
|
||||||
],
|
],
|
||||||
"title": "Task Deleted"
|
"title": "Task Deleted"
|
||||||
},
|
},
|
||||||
@@ -441,8 +441,8 @@
|
|||||||
"id": "4574194d-e7ca-4356-a95c-21b753a1787e",
|
"id": "4574194d-e7ca-4356-a95c-21b753a1787e",
|
||||||
"level": "medium",
|
"level": "medium",
|
||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
"0CCE9215-69AE-11D9-BED3-505054503030",
|
"0CCE9217-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE9217-69AE-11D9-BED3-505054503030"
|
"0CCE9215-69AE-11D9-BED3-505054503030"
|
||||||
],
|
],
|
||||||
"title": "User Guessing"
|
"title": "User Guessing"
|
||||||
},
|
},
|
||||||
@@ -589,8 +589,8 @@
|
|||||||
"id": "8afa97ce-a217-4f7c-aced-3e320a57756d",
|
"id": "8afa97ce-a217-4f7c-aced-3e320a57756d",
|
||||||
"level": "low",
|
"level": "low",
|
||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
"0CCE9215-69AE-11D9-BED3-505054503030",
|
"0CCE9217-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE9217-69AE-11D9-BED3-505054503030"
|
"0CCE9215-69AE-11D9-BED3-505054503030"
|
||||||
],
|
],
|
||||||
"title": "Logon Failure (User Does Not Exist)"
|
"title": "Logon Failure (User Does Not Exist)"
|
||||||
},
|
},
|
||||||
@@ -650,8 +650,8 @@
|
|||||||
"id": "e87bd730-df45-4ae9-85de-6c75369c5d29",
|
"id": "e87bd730-df45-4ae9-85de-6c75369c5d29",
|
||||||
"level": "low",
|
"level": "low",
|
||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
"0CCE9215-69AE-11D9-BED3-505054503030",
|
"0CCE9217-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE9217-69AE-11D9-BED3-505054503030"
|
"0CCE9215-69AE-11D9-BED3-505054503030"
|
||||||
],
|
],
|
||||||
"title": "Logon Failure (Wrong Password)"
|
"title": "Logon Failure (Wrong Password)"
|
||||||
},
|
},
|
||||||
@@ -1043,8 +1043,8 @@
|
|||||||
"id": "e4c7a334-7ecb-ef93-85dd-49185891fb7a",
|
"id": "e4c7a334-7ecb-ef93-85dd-49185891fb7a",
|
||||||
"level": "medium",
|
"level": "medium",
|
||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
"0CCE9227-69AE-11D9-BED3-505054503030",
|
"0CCE9226-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE9226-69AE-11D9-BED3-505054503030"
|
"0CCE9227-69AE-11D9-BED3-505054503030"
|
||||||
],
|
],
|
||||||
"title": "Defrag Deactivation - Security"
|
"title": "Defrag Deactivation - Security"
|
||||||
},
|
},
|
||||||
@@ -1117,10 +1117,10 @@
|
|||||||
"id": "82b185f4-cdcb-ba23-9fdb-dbc1a732e1a7",
|
"id": "82b185f4-cdcb-ba23-9fdb-dbc1a732e1a7",
|
||||||
"level": "medium",
|
"level": "medium",
|
||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
"0CCE9245-69AE-11D9-BED3-505054503030",
|
|
||||||
"0CCE921E-69AE-11D9-BED3-505054503030",
|
"0CCE921E-69AE-11D9-BED3-505054503030",
|
||||||
|
"0CCE921F-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE921D-69AE-11D9-BED3-505054503030",
|
"0CCE921D-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE921F-69AE-11D9-BED3-505054503030"
|
"0CCE9245-69AE-11D9-BED3-505054503030"
|
||||||
],
|
],
|
||||||
"title": "ScreenConnect User Database Modification - Security"
|
"title": "ScreenConnect User Database Modification - Security"
|
||||||
},
|
},
|
||||||
@@ -1132,23 +1132,23 @@
|
|||||||
"id": "74d067bc-3f42-3855-c13d-771d589cf11c",
|
"id": "74d067bc-3f42-3855-c13d-771d589cf11c",
|
||||||
"level": "critical",
|
"level": "critical",
|
||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
|
"0CCE921E-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE9245-69AE-11D9-BED3-505054503030",
|
"0CCE9245-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE921D-69AE-11D9-BED3-505054503030",
|
|
||||||
"0CCE921F-69AE-11D9-BED3-505054503030",
|
"0CCE921F-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE921E-69AE-11D9-BED3-505054503030"
|
"0CCE921D-69AE-11D9-BED3-505054503030"
|
||||||
],
|
],
|
||||||
"title": "CVE-2024-1708 - ScreenConnect Path Traversal Exploitation - Security"
|
"title": "CVE-2024-1708 - ScreenConnect Path Traversal Exploitation - Security"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"channel": "sec",
|
"channel": "sec",
|
||||||
"event_ids": [
|
"event_ids": [
|
||||||
"4727",
|
|
||||||
"4737",
|
|
||||||
"4754",
|
|
||||||
"4728",
|
|
||||||
"4755",
|
|
||||||
"4756",
|
"4756",
|
||||||
"4731"
|
"4731",
|
||||||
|
"4754",
|
||||||
|
"4737",
|
||||||
|
"4755",
|
||||||
|
"4727",
|
||||||
|
"4728"
|
||||||
],
|
],
|
||||||
"id": "2a451b93-9890-5cfe-38aa-1dc4f8f0fe0a",
|
"id": "2a451b93-9890-5cfe-38aa-1dc4f8f0fe0a",
|
||||||
"level": "high",
|
"level": "high",
|
||||||
@@ -1768,9 +1768,9 @@
|
|||||||
"level": "critical",
|
"level": "critical",
|
||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
"0CCE921F-69AE-11D9-BED3-505054503030",
|
"0CCE921F-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE921D-69AE-11D9-BED3-505054503030",
|
|
||||||
"0CCE9245-69AE-11D9-BED3-505054503030",
|
"0CCE9245-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE921E-69AE-11D9-BED3-505054503030"
|
"0CCE921E-69AE-11D9-BED3-505054503030",
|
||||||
|
"0CCE921D-69AE-11D9-BED3-505054503030"
|
||||||
],
|
],
|
||||||
"title": "CVE-2023-23397 Exploitation Attempt"
|
"title": "CVE-2023-23397 Exploitation Attempt"
|
||||||
},
|
},
|
||||||
@@ -1886,8 +1886,8 @@
|
|||||||
"id": "05731ce3-cfda-dbba-3792-c17794a22cf7",
|
"id": "05731ce3-cfda-dbba-3792-c17794a22cf7",
|
||||||
"level": "critical",
|
"level": "critical",
|
||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
"0CCE9226-69AE-11D9-BED3-505054503030",
|
"0CCE9227-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE9227-69AE-11D9-BED3-505054503030"
|
"0CCE9226-69AE-11D9-BED3-505054503030"
|
||||||
],
|
],
|
||||||
"title": "Diamond Sleet APT Scheduled Task Creation"
|
"title": "Diamond Sleet APT Scheduled Task Creation"
|
||||||
},
|
},
|
||||||
@@ -1954,15 +1954,15 @@
|
|||||||
{
|
{
|
||||||
"channel": "sec",
|
"channel": "sec",
|
||||||
"event_ids": [
|
"event_ids": [
|
||||||
"4698",
|
"4702",
|
||||||
"4699",
|
"4699",
|
||||||
"4702"
|
"4698"
|
||||||
],
|
],
|
||||||
"id": "ae16af08-e56e-414a-ceba-cb62e9f3a2ef",
|
"id": "ae16af08-e56e-414a-ceba-cb62e9f3a2ef",
|
||||||
"level": "high",
|
"level": "high",
|
||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
"0CCE9226-69AE-11D9-BED3-505054503030",
|
"0CCE9227-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE9227-69AE-11D9-BED3-505054503030"
|
"0CCE9226-69AE-11D9-BED3-505054503030"
|
||||||
],
|
],
|
||||||
"title": "Scheduled Tasks Names Used By SVR For GraphicalProton Backdoor"
|
"title": "Scheduled Tasks Names Used By SVR For GraphicalProton Backdoor"
|
||||||
},
|
},
|
||||||
@@ -2769,18 +2769,18 @@
|
|||||||
{
|
{
|
||||||
"channel": "sec",
|
"channel": "sec",
|
||||||
"event_ids": [
|
"event_ids": [
|
||||||
"4663",
|
|
||||||
"5145",
|
"5145",
|
||||||
|
"4663",
|
||||||
"4656"
|
"4656"
|
||||||
],
|
],
|
||||||
"id": "21ead34c-d2d4-2799-6318-2ff9e4aa9222",
|
"id": "21ead34c-d2d4-2799-6318-2ff9e4aa9222",
|
||||||
"level": "high",
|
"level": "high",
|
||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
"0CCE921E-69AE-11D9-BED3-505054503030",
|
|
||||||
"0CCE921D-69AE-11D9-BED3-505054503030",
|
"0CCE921D-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE921F-69AE-11D9-BED3-505054503030",
|
"0CCE9244-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE9245-69AE-11D9-BED3-505054503030",
|
"0CCE9245-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE9244-69AE-11D9-BED3-505054503030"
|
"0CCE921E-69AE-11D9-BED3-505054503030",
|
||||||
|
"0CCE921F-69AE-11D9-BED3-505054503030"
|
||||||
],
|
],
|
||||||
"title": "BlueSky Ransomware Artefacts"
|
"title": "BlueSky Ransomware Artefacts"
|
||||||
},
|
},
|
||||||
@@ -3161,8 +3161,8 @@
|
|||||||
"id": "35890fd4-9ed3-b244-0eff-91fe61e52f8b",
|
"id": "35890fd4-9ed3-b244-0eff-91fe61e52f8b",
|
||||||
"level": "medium",
|
"level": "medium",
|
||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
"0CCE9217-69AE-11D9-BED3-505054503030",
|
"0CCE9215-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE9215-69AE-11D9-BED3-505054503030"
|
"0CCE9217-69AE-11D9-BED3-505054503030"
|
||||||
],
|
],
|
||||||
"title": "Potential Pass the Hash Activity"
|
"title": "Potential Pass the Hash Activity"
|
||||||
},
|
},
|
||||||
@@ -3181,8 +3181,8 @@
|
|||||||
{
|
{
|
||||||
"channel": "sec",
|
"channel": "sec",
|
||||||
"event_ids": [
|
"event_ids": [
|
||||||
"4964",
|
"4672",
|
||||||
"4672"
|
"4964"
|
||||||
],
|
],
|
||||||
"id": "b3d10465-f171-0ef7-d28e-8ef2f9409cf1",
|
"id": "b3d10465-f171-0ef7-d28e-8ef2f9409cf1",
|
||||||
"level": "low",
|
"level": "low",
|
||||||
@@ -3202,8 +3202,8 @@
|
|||||||
"id": "7298c707-7564-3229-7c76-ec514847d8c2",
|
"id": "7298c707-7564-3229-7c76-ec514847d8c2",
|
||||||
"level": "medium",
|
"level": "medium",
|
||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
"0CCE9215-69AE-11D9-BED3-505054503030",
|
"0CCE9217-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE9217-69AE-11D9-BED3-505054503030"
|
"0CCE9215-69AE-11D9-BED3-505054503030"
|
||||||
],
|
],
|
||||||
"title": "Interactive Logon to Server Systems"
|
"title": "Interactive Logon to Server Systems"
|
||||||
},
|
},
|
||||||
@@ -16355,8 +16355,8 @@
|
|||||||
"id": "68d6fb03-e325-2ed1-a429-abac7adf7ba3",
|
"id": "68d6fb03-e325-2ed1-a429-abac7adf7ba3",
|
||||||
"level": "low",
|
"level": "low",
|
||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
"0CCE9226-69AE-11D9-BED3-505054503030",
|
"0CCE9227-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE9227-69AE-11D9-BED3-505054503030"
|
"0CCE9226-69AE-11D9-BED3-505054503030"
|
||||||
],
|
],
|
||||||
"title": "Scheduled Task Deletion"
|
"title": "Scheduled Task Deletion"
|
||||||
},
|
},
|
||||||
@@ -16368,10 +16368,10 @@
|
|||||||
"id": "7619b716-8052-6323-d9c7-87923ef591e6",
|
"id": "7619b716-8052-6323-d9c7-87923ef591e6",
|
||||||
"level": "low",
|
"level": "low",
|
||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
"0CCE921E-69AE-11D9-BED3-505054503030",
|
|
||||||
"0CCE9245-69AE-11D9-BED3-505054503030",
|
"0CCE9245-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE921D-69AE-11D9-BED3-505054503030",
|
"0CCE921D-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE921F-69AE-11D9-BED3-505054503030"
|
"0CCE921F-69AE-11D9-BED3-505054503030",
|
||||||
|
"0CCE921E-69AE-11D9-BED3-505054503030"
|
||||||
],
|
],
|
||||||
"title": "Access To Browser Credential Files By Uncommon Applications - Security"
|
"title": "Access To Browser Credential Files By Uncommon Applications - Security"
|
||||||
},
|
},
|
||||||
@@ -18651,10 +18651,10 @@
|
|||||||
"id": "4faa08cb-e57e-bb07-cfc2-2153a97a99bf",
|
"id": "4faa08cb-e57e-bb07-cfc2-2153a97a99bf",
|
||||||
"level": "medium",
|
"level": "medium",
|
||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
"0CCE921F-69AE-11D9-BED3-505054503030",
|
"0CCE921E-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE9245-69AE-11D9-BED3-505054503030",
|
|
||||||
"0CCE921D-69AE-11D9-BED3-505054503030",
|
"0CCE921D-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE921E-69AE-11D9-BED3-505054503030"
|
"0CCE921F-69AE-11D9-BED3-505054503030",
|
||||||
|
"0CCE9245-69AE-11D9-BED3-505054503030"
|
||||||
],
|
],
|
||||||
"title": "ISO Image Mounted"
|
"title": "ISO Image Mounted"
|
||||||
},
|
},
|
||||||
@@ -18666,8 +18666,8 @@
|
|||||||
"id": "cd7d9f05-3bf6-21f6-6686-e602ab6d72ba",
|
"id": "cd7d9f05-3bf6-21f6-6686-e602ab6d72ba",
|
||||||
"level": "high",
|
"level": "high",
|
||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
"0CCE9226-69AE-11D9-BED3-505054503030",
|
"0CCE9227-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE9227-69AE-11D9-BED3-505054503030"
|
"0CCE9226-69AE-11D9-BED3-505054503030"
|
||||||
],
|
],
|
||||||
"title": "Suspicious Scheduled Task Creation"
|
"title": "Suspicious Scheduled Task Creation"
|
||||||
},
|
},
|
||||||
@@ -18691,17 +18691,17 @@
|
|||||||
"id": "1085e6d3-6691-5713-42ba-ba8933a6b2d0",
|
"id": "1085e6d3-6691-5713-42ba-ba8933a6b2d0",
|
||||||
"level": "low",
|
"level": "low",
|
||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
"69979849-797A-11D9-BED3-505054503030",
|
"0CCE9210-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE9210-69AE-11D9-BED3-505054503030"
|
"69979849-797A-11D9-BED3-505054503030"
|
||||||
],
|
],
|
||||||
"title": "Unauthorized System Time Modification"
|
"title": "Unauthorized System Time Modification"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"channel": "sec",
|
"channel": "sec",
|
||||||
"event_ids": [
|
"event_ids": [
|
||||||
|
"4738",
|
||||||
"4765",
|
"4765",
|
||||||
"4766",
|
"4766"
|
||||||
"4738"
|
|
||||||
],
|
],
|
||||||
"id": "5335aea0-f1b4-e120-08b6-c80fe4bf99ad",
|
"id": "5335aea0-f1b4-e120-08b6-c80fe4bf99ad",
|
||||||
"level": "medium",
|
"level": "medium",
|
||||||
@@ -18761,15 +18761,15 @@
|
|||||||
"channel": "sec",
|
"channel": "sec",
|
||||||
"event_ids": [
|
"event_ids": [
|
||||||
"4768",
|
"4768",
|
||||||
"4771",
|
"4769",
|
||||||
"675",
|
"675",
|
||||||
"4769"
|
"4771"
|
||||||
],
|
],
|
||||||
"id": "978525c2-97aa-f0e4-8c11-3cf81ea3379b",
|
"id": "978525c2-97aa-f0e4-8c11-3cf81ea3379b",
|
||||||
"level": "high",
|
"level": "high",
|
||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
"0CCE9240-69AE-11D9-BED3-505054503030",
|
"0CCE9242-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE9242-69AE-11D9-BED3-505054503030"
|
"0CCE9240-69AE-11D9-BED3-505054503030"
|
||||||
],
|
],
|
||||||
"title": "Kerberos Manipulation"
|
"title": "Kerberos Manipulation"
|
||||||
},
|
},
|
||||||
@@ -18788,8 +18788,8 @@
|
|||||||
{
|
{
|
||||||
"channel": "sec",
|
"channel": "sec",
|
||||||
"event_ids": [
|
"event_ids": [
|
||||||
"6281",
|
"5038",
|
||||||
"5038"
|
"6281"
|
||||||
],
|
],
|
||||||
"id": "4f738466-2a14-5842-1eb3-481614770a49",
|
"id": "4f738466-2a14-5842-1eb3-481614770a49",
|
||||||
"level": "informational",
|
"level": "informational",
|
||||||
@@ -18886,8 +18886,8 @@
|
|||||||
{
|
{
|
||||||
"channel": "sec",
|
"channel": "sec",
|
||||||
"event_ids": [
|
"event_ids": [
|
||||||
"4742",
|
"5136",
|
||||||
"5136"
|
"4742"
|
||||||
],
|
],
|
||||||
"id": "c800ccd5-5818-b0f5-1a12-f9c8bc24a433",
|
"id": "c800ccd5-5818-b0f5-1a12-f9c8bc24a433",
|
||||||
"level": "medium",
|
"level": "medium",
|
||||||
@@ -18906,10 +18906,10 @@
|
|||||||
"id": "c7f94c63-6fb7-9686-e2c2-2298c9f56ca9",
|
"id": "c7f94c63-6fb7-9686-e2c2-2298c9f56ca9",
|
||||||
"level": "medium",
|
"level": "medium",
|
||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
"0CCE921E-69AE-11D9-BED3-505054503030",
|
"0CCE921F-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE9245-69AE-11D9-BED3-505054503030",
|
"0CCE9245-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE921D-69AE-11D9-BED3-505054503030",
|
"0CCE921E-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE921F-69AE-11D9-BED3-505054503030"
|
"0CCE921D-69AE-11D9-BED3-505054503030"
|
||||||
],
|
],
|
||||||
"title": "Potentially Suspicious AccessMask Requested From LSASS"
|
"title": "Potentially Suspicious AccessMask Requested From LSASS"
|
||||||
},
|
},
|
||||||
@@ -18928,16 +18928,16 @@
|
|||||||
{
|
{
|
||||||
"channel": "sec",
|
"channel": "sec",
|
||||||
"event_ids": [
|
"event_ids": [
|
||||||
"4656",
|
"4663",
|
||||||
"4663"
|
"4656"
|
||||||
],
|
],
|
||||||
"id": "321196fe-fb10-6b13-c611-3dfe40baa1af",
|
"id": "321196fe-fb10-6b13-c611-3dfe40baa1af",
|
||||||
"level": "medium",
|
"level": "medium",
|
||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
"0CCE9245-69AE-11D9-BED3-505054503030",
|
|
||||||
"0CCE921F-69AE-11D9-BED3-505054503030",
|
"0CCE921F-69AE-11D9-BED3-505054503030",
|
||||||
|
"0CCE921E-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE921D-69AE-11D9-BED3-505054503030",
|
"0CCE921D-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE921E-69AE-11D9-BED3-505054503030"
|
"0CCE9245-69AE-11D9-BED3-505054503030"
|
||||||
],
|
],
|
||||||
"title": "Azure AD Health Monitoring Agent Registry Keys Access"
|
"title": "Azure AD Health Monitoring Agent Registry Keys Access"
|
||||||
},
|
},
|
||||||
@@ -19088,64 +19088,64 @@
|
|||||||
{
|
{
|
||||||
"channel": "sec",
|
"channel": "sec",
|
||||||
"event_ids": [
|
"event_ids": [
|
||||||
"4776",
|
"4625",
|
||||||
"4625"
|
"4776"
|
||||||
],
|
],
|
||||||
"id": "655eb351-553b-501f-186e-aa9af13ecf43",
|
"id": "655eb351-553b-501f-186e-aa9af13ecf43",
|
||||||
"level": "medium",
|
"level": "medium",
|
||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
"0CCE923F-69AE-11D9-BED3-505054503030",
|
|
||||||
"0CCE9215-69AE-11D9-BED3-505054503030",
|
"0CCE9215-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE9217-69AE-11D9-BED3-505054503030"
|
"0CCE9217-69AE-11D9-BED3-505054503030",
|
||||||
|
"0CCE923F-69AE-11D9-BED3-505054503030"
|
||||||
],
|
],
|
||||||
"title": "Account Tampering - Suspicious Failed Logon Reasons"
|
"title": "Account Tampering - Suspicious Failed Logon Reasons"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"channel": "sec",
|
"channel": "sec",
|
||||||
"event_ids": [
|
"event_ids": [
|
||||||
"4663",
|
"4657",
|
||||||
"4657"
|
"4663"
|
||||||
],
|
],
|
||||||
"id": "249d836c-8857-1b98-5d7b-050c2d34e275",
|
"id": "249d836c-8857-1b98-5d7b-050c2d34e275",
|
||||||
"level": "high",
|
"level": "high",
|
||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
"0CCE921D-69AE-11D9-BED3-505054503030",
|
"0CCE921D-69AE-11D9-BED3-505054503030",
|
||||||
|
"0CCE9245-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE921F-69AE-11D9-BED3-505054503030",
|
"0CCE921F-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE921E-69AE-11D9-BED3-505054503030",
|
"0CCE921E-69AE-11D9-BED3-505054503030"
|
||||||
"0CCE9245-69AE-11D9-BED3-505054503030"
|
|
||||||
],
|
],
|
||||||
"title": "Sysmon Channel Reference Deletion"
|
"title": "Sysmon Channel Reference Deletion"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"channel": "sec",
|
"channel": "sec",
|
||||||
"event_ids": [
|
"event_ids": [
|
||||||
"4657",
|
|
||||||
"4656",
|
"4656",
|
||||||
"4663"
|
"4663",
|
||||||
|
"4657"
|
||||||
],
|
],
|
||||||
"id": "32337bc9-8e75-bdaf-eaf4-d3b19ee08a67",
|
"id": "32337bc9-8e75-bdaf-eaf4-d3b19ee08a67",
|
||||||
"level": "medium",
|
"level": "medium",
|
||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
"0CCE9245-69AE-11D9-BED3-505054503030",
|
|
||||||
"0CCE921F-69AE-11D9-BED3-505054503030",
|
|
||||||
"0CCE921D-69AE-11D9-BED3-505054503030",
|
"0CCE921D-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE921E-69AE-11D9-BED3-505054503030"
|
"0CCE921F-69AE-11D9-BED3-505054503030",
|
||||||
|
"0CCE921E-69AE-11D9-BED3-505054503030",
|
||||||
|
"0CCE9245-69AE-11D9-BED3-505054503030"
|
||||||
],
|
],
|
||||||
"title": "Processes Accessing the Microphone and Webcam"
|
"title": "Processes Accessing the Microphone and Webcam"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"channel": "sec",
|
"channel": "sec",
|
||||||
"event_ids": [
|
"event_ids": [
|
||||||
"4656",
|
"4663",
|
||||||
"4663"
|
"4656"
|
||||||
],
|
],
|
||||||
"id": "63308dbe-54a4-9c70-cc90-6d15e10f3505",
|
"id": "63308dbe-54a4-9c70-cc90-6d15e10f3505",
|
||||||
"level": "high",
|
"level": "high",
|
||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
"0CCE921E-69AE-11D9-BED3-505054503030",
|
|
||||||
"0CCE921F-69AE-11D9-BED3-505054503030",
|
|
||||||
"0CCE921D-69AE-11D9-BED3-505054503030",
|
"0CCE921D-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE9245-69AE-11D9-BED3-505054503030"
|
"0CCE9245-69AE-11D9-BED3-505054503030",
|
||||||
|
"0CCE921E-69AE-11D9-BED3-505054503030",
|
||||||
|
"0CCE921F-69AE-11D9-BED3-505054503030"
|
||||||
],
|
],
|
||||||
"title": "SysKey Registry Keys Access"
|
"title": "SysKey Registry Keys Access"
|
||||||
},
|
},
|
||||||
@@ -19181,8 +19181,8 @@
|
|||||||
"id": "6bcac9cb-eeee-9f45-c5c1-0daaf023ac12",
|
"id": "6bcac9cb-eeee-9f45-c5c1-0daaf023ac12",
|
||||||
"level": "medium",
|
"level": "medium",
|
||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
"0CCE9215-69AE-11D9-BED3-505054503030",
|
"0CCE9217-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE9217-69AE-11D9-BED3-505054503030"
|
"0CCE9215-69AE-11D9-BED3-505054503030"
|
||||||
],
|
],
|
||||||
"title": "Failed Logon From Public IP"
|
"title": "Failed Logon From Public IP"
|
||||||
},
|
},
|
||||||
@@ -19214,8 +19214,8 @@
|
|||||||
{
|
{
|
||||||
"channel": "sec",
|
"channel": "sec",
|
||||||
"event_ids": [
|
"event_ids": [
|
||||||
"633",
|
"4729",
|
||||||
"4729"
|
"633"
|
||||||
],
|
],
|
||||||
"id": "6e0f860b-3678-7396-a4a3-7cf55f7bb01c",
|
"id": "6e0f860b-3678-7396-a4a3-7cf55f7bb01c",
|
||||||
"level": "low",
|
"level": "low",
|
||||||
@@ -19323,8 +19323,8 @@
|
|||||||
{
|
{
|
||||||
"channel": "sec",
|
"channel": "sec",
|
||||||
"event_ids": [
|
"event_ids": [
|
||||||
"4730",
|
"634",
|
||||||
"634"
|
"4730"
|
||||||
],
|
],
|
||||||
"id": "ae7d8d1c-f75b-d952-e84e-a7981b861590",
|
"id": "ae7d8d1c-f75b-d952-e84e-a7981b861590",
|
||||||
"level": "low",
|
"level": "low",
|
||||||
@@ -19361,16 +19361,16 @@
|
|||||||
{
|
{
|
||||||
"channel": "sec",
|
"channel": "sec",
|
||||||
"event_ids": [
|
"event_ids": [
|
||||||
"4663",
|
"4656",
|
||||||
"4656"
|
"4663"
|
||||||
],
|
],
|
||||||
"id": "de10da38-ee60-f6a4-7d70-4d308558158b",
|
"id": "de10da38-ee60-f6a4-7d70-4d308558158b",
|
||||||
"level": "critical",
|
"level": "critical",
|
||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
"0CCE9245-69AE-11D9-BED3-505054503030",
|
"0CCE9245-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE921F-69AE-11D9-BED3-505054503030",
|
|
||||||
"0CCE921D-69AE-11D9-BED3-505054503030",
|
"0CCE921D-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE921E-69AE-11D9-BED3-505054503030"
|
"0CCE921E-69AE-11D9-BED3-505054503030",
|
||||||
|
"0CCE921F-69AE-11D9-BED3-505054503030"
|
||||||
],
|
],
|
||||||
"title": "WCE wceaux.dll Access"
|
"title": "WCE wceaux.dll Access"
|
||||||
},
|
},
|
||||||
@@ -19396,8 +19396,8 @@
|
|||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
"0CCE921D-69AE-11D9-BED3-505054503030",
|
"0CCE921D-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE921E-69AE-11D9-BED3-505054503030",
|
"0CCE921E-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE921F-69AE-11D9-BED3-505054503030",
|
"0CCE9245-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE9245-69AE-11D9-BED3-505054503030"
|
"0CCE921F-69AE-11D9-BED3-505054503030"
|
||||||
],
|
],
|
||||||
"title": "Suspicious Teams Application Related ObjectAcess Event"
|
"title": "Suspicious Teams Application Related ObjectAcess Event"
|
||||||
},
|
},
|
||||||
@@ -19441,8 +19441,8 @@
|
|||||||
{
|
{
|
||||||
"channel": "sec",
|
"channel": "sec",
|
||||||
"event_ids": [
|
"event_ids": [
|
||||||
"4647",
|
"4634",
|
||||||
"4634"
|
"4647"
|
||||||
],
|
],
|
||||||
"id": "73f64ce7-a76d-0208-ea75-dd26a09d719b",
|
"id": "73f64ce7-a76d-0208-ea75-dd26a09d719b",
|
||||||
"level": "informational",
|
"level": "informational",
|
||||||
@@ -19585,16 +19585,16 @@
|
|||||||
"channel": "sec",
|
"channel": "sec",
|
||||||
"event_ids": [
|
"event_ids": [
|
||||||
"4658",
|
"4658",
|
||||||
"4656",
|
"4663",
|
||||||
"4663"
|
"4656"
|
||||||
],
|
],
|
||||||
"id": "70c3269a-a7f2-49bd-1e28-a0921f353db7",
|
"id": "70c3269a-a7f2-49bd-1e28-a0921f353db7",
|
||||||
"level": "medium",
|
"level": "medium",
|
||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
|
"0CCE921E-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE921F-69AE-11D9-BED3-505054503030",
|
"0CCE921F-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE9223-69AE-11D9-BED3-505054503030",
|
"0CCE9223-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE9245-69AE-11D9-BED3-505054503030",
|
"0CCE9245-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE921E-69AE-11D9-BED3-505054503030",
|
|
||||||
"0CCE921D-69AE-11D9-BED3-505054503030"
|
"0CCE921D-69AE-11D9-BED3-505054503030"
|
||||||
],
|
],
|
||||||
"title": "Potential Secure Deletion with SDelete"
|
"title": "Potential Secure Deletion with SDelete"
|
||||||
@@ -19631,18 +19631,18 @@
|
|||||||
"id": "d7742b08-730d-3624-df95-cc3c6eaa3a39",
|
"id": "d7742b08-730d-3624-df95-cc3c6eaa3a39",
|
||||||
"level": "high",
|
"level": "high",
|
||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
"0CCE921F-69AE-11D9-BED3-505054503030",
|
|
||||||
"0CCE921D-69AE-11D9-BED3-505054503030",
|
|
||||||
"0CCE921E-69AE-11D9-BED3-505054503030",
|
"0CCE921E-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE9245-69AE-11D9-BED3-505054503030"
|
"0CCE921D-69AE-11D9-BED3-505054503030",
|
||||||
|
"0CCE9245-69AE-11D9-BED3-505054503030",
|
||||||
|
"0CCE921F-69AE-11D9-BED3-505054503030"
|
||||||
],
|
],
|
||||||
"title": "SAM Registry Hive Handle Request"
|
"title": "SAM Registry Hive Handle Request"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"channel": "sec",
|
"channel": "sec",
|
||||||
"event_ids": [
|
"event_ids": [
|
||||||
"5136",
|
"5145",
|
||||||
"5145"
|
"5136"
|
||||||
],
|
],
|
||||||
"id": "bc613d09-5a80-cad3-6f65-c5020f960511",
|
"id": "bc613d09-5a80-cad3-6f65-c5020f960511",
|
||||||
"level": "medium",
|
"level": "medium",
|
||||||
@@ -19705,8 +19705,8 @@
|
|||||||
{
|
{
|
||||||
"channel": "sec",
|
"channel": "sec",
|
||||||
"event_ids": [
|
"event_ids": [
|
||||||
"5447",
|
"5441",
|
||||||
"5441"
|
"5447"
|
||||||
],
|
],
|
||||||
"id": "4d56e133-40b5-5b28-07b5-bab0913fc338",
|
"id": "4d56e133-40b5-5b28-07b5-bab0913fc338",
|
||||||
"level": "high",
|
"level": "high",
|
||||||
@@ -19736,8 +19736,8 @@
|
|||||||
"id": "9bcf333e-fc4c-5912-eeba-8a0cefe21be4",
|
"id": "9bcf333e-fc4c-5912-eeba-8a0cefe21be4",
|
||||||
"level": "medium",
|
"level": "medium",
|
||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
"0CCE9220-69AE-11D9-BED3-505054503030",
|
"0CCE923B-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE923B-69AE-11D9-BED3-505054503030"
|
"0CCE9220-69AE-11D9-BED3-505054503030"
|
||||||
],
|
],
|
||||||
"title": "Password Policy Enumerated"
|
"title": "Password Policy Enumerated"
|
||||||
},
|
},
|
||||||
@@ -19888,9 +19888,9 @@
|
|||||||
{
|
{
|
||||||
"channel": "sec",
|
"channel": "sec",
|
||||||
"event_ids": [
|
"event_ids": [
|
||||||
|
"4624",
|
||||||
"4776",
|
"4776",
|
||||||
"4625",
|
"4625"
|
||||||
"4624"
|
|
||||||
],
|
],
|
||||||
"id": "827aa6c1-1507-3f0a-385a-ade5251bfd71",
|
"id": "827aa6c1-1507-3f0a-385a-ade5251bfd71",
|
||||||
"level": "high",
|
"level": "high",
|
||||||
@@ -20020,8 +20020,8 @@
|
|||||||
"level": "medium",
|
"level": "medium",
|
||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
"0CCE921D-69AE-11D9-BED3-505054503030",
|
"0CCE921D-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE921E-69AE-11D9-BED3-505054503030",
|
|
||||||
"0CCE921F-69AE-11D9-BED3-505054503030",
|
"0CCE921F-69AE-11D9-BED3-505054503030",
|
||||||
|
"0CCE921E-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE9245-69AE-11D9-BED3-505054503030"
|
"0CCE9245-69AE-11D9-BED3-505054503030"
|
||||||
],
|
],
|
||||||
"title": "SCM Database Handle Failure"
|
"title": "SCM Database Handle Failure"
|
||||||
@@ -20082,10 +20082,10 @@
|
|||||||
"id": "d1909400-93d7-de3c-ba13-153c64499c7c",
|
"id": "d1909400-93d7-de3c-ba13-153c64499c7c",
|
||||||
"level": "low",
|
"level": "low",
|
||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
|
"0CCE9245-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE921D-69AE-11D9-BED3-505054503030",
|
"0CCE921D-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE921F-69AE-11D9-BED3-505054503030",
|
|
||||||
"0CCE921E-69AE-11D9-BED3-505054503030",
|
"0CCE921E-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE9245-69AE-11D9-BED3-505054503030"
|
"0CCE921F-69AE-11D9-BED3-505054503030"
|
||||||
],
|
],
|
||||||
"title": "Service Registry Key Read Access Request"
|
"title": "Service Registry Key Read Access Request"
|
||||||
},
|
},
|
||||||
@@ -20098,8 +20098,8 @@
|
|||||||
"id": "777523b0-14f8-1ca2-12c9-d668153661ff",
|
"id": "777523b0-14f8-1ca2-12c9-d668153661ff",
|
||||||
"level": "medium",
|
"level": "medium",
|
||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
"0CCE921D-69AE-11D9-BED3-505054503030",
|
|
||||||
"0CCE9245-69AE-11D9-BED3-505054503030",
|
"0CCE9245-69AE-11D9-BED3-505054503030",
|
||||||
|
"0CCE921D-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE921F-69AE-11D9-BED3-505054503030",
|
"0CCE921F-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE921E-69AE-11D9-BED3-505054503030"
|
"0CCE921E-69AE-11D9-BED3-505054503030"
|
||||||
],
|
],
|
||||||
@@ -20121,8 +20121,8 @@
|
|||||||
{
|
{
|
||||||
"channel": "sec",
|
"channel": "sec",
|
||||||
"event_ids": [
|
"event_ids": [
|
||||||
"517",
|
"1102",
|
||||||
"1102"
|
"517"
|
||||||
],
|
],
|
||||||
"id": "9b14c9d8-6b61-e49f-f8a8-0836d0ad98c9",
|
"id": "9b14c9d8-6b61-e49f-f8a8-0836d0ad98c9",
|
||||||
"level": "high",
|
"level": "high",
|
||||||
@@ -20132,8 +20132,8 @@
|
|||||||
{
|
{
|
||||||
"channel": "sec",
|
"channel": "sec",
|
||||||
"event_ids": [
|
"event_ids": [
|
||||||
"5449",
|
"5447",
|
||||||
"5447"
|
"5449"
|
||||||
],
|
],
|
||||||
"id": "22d4af9f-97d9-4827-7209-c451ff7f43c6",
|
"id": "22d4af9f-97d9-4827-7209-c451ff7f43c6",
|
||||||
"level": "high",
|
"level": "high",
|
||||||
@@ -20163,24 +20163,24 @@
|
|||||||
"id": "cd93b6ed-961d-ed36-92db-bd44bccda695",
|
"id": "cd93b6ed-961d-ed36-92db-bd44bccda695",
|
||||||
"level": "high",
|
"level": "high",
|
||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
"0CCE9228-69AE-11D9-BED3-505054503030",
|
"0CCE9229-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE9229-69AE-11D9-BED3-505054503030"
|
"0CCE9228-69AE-11D9-BED3-505054503030"
|
||||||
],
|
],
|
||||||
"title": "User Couldn't Call a Privileged Service 'LsaRegisterLogonProcess'"
|
"title": "User Couldn't Call a Privileged Service 'LsaRegisterLogonProcess'"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"channel": "sec",
|
"channel": "sec",
|
||||||
"event_ids": [
|
"event_ids": [
|
||||||
"4776",
|
|
||||||
"4624",
|
"4624",
|
||||||
|
"4776",
|
||||||
"4625"
|
"4625"
|
||||||
],
|
],
|
||||||
"id": "8b40829b-4556-9bec-a8ad-905688497639",
|
"id": "8b40829b-4556-9bec-a8ad-905688497639",
|
||||||
"level": "high",
|
"level": "high",
|
||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
"0CCE9217-69AE-11D9-BED3-505054503030",
|
"0CCE9217-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE9215-69AE-11D9-BED3-505054503030",
|
"0CCE923F-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE923F-69AE-11D9-BED3-505054503030"
|
"0CCE9215-69AE-11D9-BED3-505054503030"
|
||||||
],
|
],
|
||||||
"title": "Hacktool Ruler"
|
"title": "Hacktool Ruler"
|
||||||
},
|
},
|
||||||
@@ -20229,10 +20229,10 @@
|
|||||||
"id": "d81faa44-ff28-8f61-097b-92727b8af44b",
|
"id": "d81faa44-ff28-8f61-097b-92727b8af44b",
|
||||||
"level": "high",
|
"level": "high",
|
||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
"0CCE9245-69AE-11D9-BED3-505054503030",
|
|
||||||
"0CCE921F-69AE-11D9-BED3-505054503030",
|
"0CCE921F-69AE-11D9-BED3-505054503030",
|
||||||
|
"0CCE921E-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE921D-69AE-11D9-BED3-505054503030",
|
"0CCE921D-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE921E-69AE-11D9-BED3-505054503030"
|
"0CCE9245-69AE-11D9-BED3-505054503030"
|
||||||
],
|
],
|
||||||
"title": "Password Dumper Activity on LSASS"
|
"title": "Password Dumper Activity on LSASS"
|
||||||
},
|
},
|
||||||
@@ -20245,8 +20245,8 @@
|
|||||||
"id": "9ce591d7-6b6d-444a-8c27-8ca626dddad3",
|
"id": "9ce591d7-6b6d-444a-8c27-8ca626dddad3",
|
||||||
"level": "high",
|
"level": "high",
|
||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
"0CCE9227-69AE-11D9-BED3-505054503030",
|
"0CCE9226-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE9226-69AE-11D9-BED3-505054503030"
|
"0CCE9227-69AE-11D9-BED3-505054503030"
|
||||||
],
|
],
|
||||||
"title": "Important Scheduled Task Deleted/Disabled"
|
"title": "Important Scheduled Task Deleted/Disabled"
|
||||||
},
|
},
|
||||||
@@ -20265,8 +20265,8 @@
|
|||||||
{
|
{
|
||||||
"channel": "sec",
|
"channel": "sec",
|
||||||
"event_ids": [
|
"event_ids": [
|
||||||
"4738",
|
"5136",
|
||||||
"5136"
|
"4738"
|
||||||
],
|
],
|
||||||
"id": "c9123898-04d5-2d3b-5e2b-7c0c92111480",
|
"id": "c9123898-04d5-2d3b-5e2b-7c0c92111480",
|
||||||
"level": "high",
|
"level": "high",
|
||||||
@@ -20279,16 +20279,16 @@
|
|||||||
{
|
{
|
||||||
"channel": "sec",
|
"channel": "sec",
|
||||||
"event_ids": [
|
"event_ids": [
|
||||||
"4656",
|
"4663",
|
||||||
"4663"
|
"4656"
|
||||||
],
|
],
|
||||||
"id": "763d50d7-9452-0146-18a1-9ca65e3a2f73",
|
"id": "763d50d7-9452-0146-18a1-9ca65e3a2f73",
|
||||||
"level": "medium",
|
"level": "medium",
|
||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
"0CCE921D-69AE-11D9-BED3-505054503030",
|
"0CCE9245-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE921E-69AE-11D9-BED3-505054503030",
|
"0CCE921E-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE921F-69AE-11D9-BED3-505054503030",
|
"0CCE921F-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE9245-69AE-11D9-BED3-505054503030"
|
"0CCE921D-69AE-11D9-BED3-505054503030"
|
||||||
],
|
],
|
||||||
"title": "Azure AD Health Service Agents Registry Keys Access"
|
"title": "Azure AD Health Service Agents Registry Keys Access"
|
||||||
},
|
},
|
||||||
@@ -20363,8 +20363,8 @@
|
|||||||
{
|
{
|
||||||
"channel": "sec",
|
"channel": "sec",
|
||||||
"event_ids": [
|
"event_ids": [
|
||||||
"4741",
|
"4743",
|
||||||
"4743"
|
"4741"
|
||||||
],
|
],
|
||||||
"id": "b607775d-e3fe-3fb8-c40e-4e52b3fbe44d",
|
"id": "b607775d-e3fe-3fb8-c40e-4e52b3fbe44d",
|
||||||
"level": "low",
|
"level": "low",
|
||||||
@@ -20376,8 +20376,8 @@
|
|||||||
{
|
{
|
||||||
"channel": "sec",
|
"channel": "sec",
|
||||||
"event_ids": [
|
"event_ids": [
|
||||||
"4904",
|
"4905",
|
||||||
"4905"
|
"4904"
|
||||||
],
|
],
|
||||||
"id": "00f253a0-1035-e450-7f6e-e2291dee27ec",
|
"id": "00f253a0-1035-e450-7f6e-e2291dee27ec",
|
||||||
"level": "informational",
|
"level": "informational",
|
||||||
@@ -20479,8 +20479,8 @@
|
|||||||
"level": "medium",
|
"level": "medium",
|
||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
"0CCE921D-69AE-11D9-BED3-505054503030",
|
"0CCE921D-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE921E-69AE-11D9-BED3-505054503030",
|
"0CCE921F-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE921F-69AE-11D9-BED3-505054503030"
|
"0CCE921E-69AE-11D9-BED3-505054503030"
|
||||||
],
|
],
|
||||||
"title": "Windows Defender Exclusion Deleted"
|
"title": "Windows Defender Exclusion Deleted"
|
||||||
},
|
},
|
||||||
@@ -21275,11 +21275,11 @@
|
|||||||
{
|
{
|
||||||
"channel": "sec",
|
"channel": "sec",
|
||||||
"event_ids": [
|
"event_ids": [
|
||||||
"4730",
|
|
||||||
"632",
|
"632",
|
||||||
"4728",
|
"4728",
|
||||||
"634",
|
|
||||||
"4729",
|
"4729",
|
||||||
|
"634",
|
||||||
|
"4730",
|
||||||
"633"
|
"633"
|
||||||
],
|
],
|
||||||
"id": "506379d9-8545-c010-e9a3-693119ab9261",
|
"id": "506379d9-8545-c010-e9a3-693119ab9261",
|
||||||
@@ -21601,8 +21601,8 @@
|
|||||||
"id": "bc42c437-1ea8-fd0f-d964-e37a58d861fc",
|
"id": "bc42c437-1ea8-fd0f-d964-e37a58d861fc",
|
||||||
"level": "medium",
|
"level": "medium",
|
||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
"0CCE9226-69AE-11D9-BED3-505054503030",
|
|
||||||
"0CCE9215-69AE-11D9-BED3-505054503030",
|
"0CCE9215-69AE-11D9-BED3-505054503030",
|
||||||
|
"0CCE9226-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE9227-69AE-11D9-BED3-505054503030"
|
"0CCE9227-69AE-11D9-BED3-505054503030"
|
||||||
],
|
],
|
||||||
"title": "Remote Schtasks Creation"
|
"title": "Remote Schtasks Creation"
|
||||||
@@ -21627,8 +21627,8 @@
|
|||||||
"id": "84202b5b-54c1-473b-4568-e10da23b3eb8",
|
"id": "84202b5b-54c1-473b-4568-e10da23b3eb8",
|
||||||
"level": "medium",
|
"level": "medium",
|
||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
"0CCE9215-69AE-11D9-BED3-505054503030",
|
"0CCE9217-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE9217-69AE-11D9-BED3-505054503030"
|
"0CCE9215-69AE-11D9-BED3-505054503030"
|
||||||
],
|
],
|
||||||
"title": "Multiple Users Failing to Authenticate from Single Process"
|
"title": "Multiple Users Failing to Authenticate from Single Process"
|
||||||
},
|
},
|
||||||
@@ -21699,9 +21699,9 @@
|
|||||||
"id": "888d3e17-a1ed-6b11-895c-e1f9b96b35be",
|
"id": "888d3e17-a1ed-6b11-895c-e1f9b96b35be",
|
||||||
"level": "high",
|
"level": "high",
|
||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
"0CCE921D-69AE-11D9-BED3-505054503030",
|
|
||||||
"0CCE9245-69AE-11D9-BED3-505054503030",
|
"0CCE9245-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE921F-69AE-11D9-BED3-505054503030",
|
"0CCE921F-69AE-11D9-BED3-505054503030",
|
||||||
|
"0CCE921D-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE921E-69AE-11D9-BED3-505054503030"
|
"0CCE921E-69AE-11D9-BED3-505054503030"
|
||||||
],
|
],
|
||||||
"title": "Stored Credentials in Fake Files"
|
"title": "Stored Credentials in Fake Files"
|
||||||
@@ -21765,10 +21765,10 @@
|
|||||||
"id": "a4504cb2-23f6-6d94-5ae6-d6013cf1d995",
|
"id": "a4504cb2-23f6-6d94-5ae6-d6013cf1d995",
|
||||||
"level": "medium",
|
"level": "medium",
|
||||||
"subcategory_guids": [
|
"subcategory_guids": [
|
||||||
"0CCE921F-69AE-11D9-BED3-505054503030",
|
|
||||||
"0CCE921E-69AE-11D9-BED3-505054503030",
|
"0CCE921E-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE9245-69AE-11D9-BED3-505054503030",
|
"0CCE921F-69AE-11D9-BED3-505054503030",
|
||||||
"0CCE921D-69AE-11D9-BED3-505054503030"
|
"0CCE921D-69AE-11D9-BED3-505054503030",
|
||||||
|
"0CCE9245-69AE-11D9-BED3-505054503030"
|
||||||
],
|
],
|
||||||
"title": "Suspicious Multiple File Rename Or Delete Occurred"
|
"title": "Suspicious Multiple File Rename Or Delete Occurred"
|
||||||
},
|
},
|
||||||
@@ -22184,8 +22184,8 @@
|
|||||||
"channel": "sec",
|
"channel": "sec",
|
||||||
"event_ids": [
|
"event_ids": [
|
||||||
"4657",
|
"4657",
|
||||||
"13",
|
"12",
|
||||||
"12"
|
"13"
|
||||||
],
|
],
|
||||||
"id": "46595663-e666-c413-ccf4-028a618ca712",
|
"id": "46595663-e666-c413-ccf4-028a618ca712",
|
||||||
"level": "critical",
|
"level": "critical",
|
||||||
|
|||||||
Reference in New Issue
Block a user