Files
hayabusa/rules/sigma/builtin/win_susp_add_domain_trust.yml
T
DustInDark 0cfa806baf Feature/addruletype to sigma rule#230 (#235)
* added ruletype to SIGMA rule #230

* added ruletype to SIGMA rule converter tool #231
2021-11-28 18:14:51 +09:00

22 lines
461 B
YAML

title: Addition of Domain Trusts
author: Thomas Patzke
date: 2019/12/03
description: Addition of domains is seldom and should be verified for legitimacy.
detection:
SELECTION_1:
EventID: 4706
condition: SELECTION_1
falsepositives:
- Legitimate extension of domain structure
id: 0255a820-e564-4e40-af2b-6ac61160335c
level: medium
logsource:
product: windows
service: security
status: stable
tags:
- attack.persistence
- attack.t1098
ruletype: SIGMA