Skip to content

[Rule Tuning] Rule Tunings to add T1078 technique and subtechniques #2529

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
imays11 opened this issue Feb 7, 2023 · 0 comments · Fixed by #2530
Closed

[Rule Tuning] Rule Tunings to add T1078 technique and subtechniques #2529

imays11 opened this issue Feb 7, 2023 · 0 comments · Fixed by #2530
Assignees
Labels
Rule: Tuning tweaking or tuning an existing rule

Comments

@imays11
Copy link
Contributor

imays11 commented Feb 7, 2023

Link to rule

Rare User Logon - add sub-techniques

Unusual Windows Username - add sub-techniques

Spike in Successful Logon Events from a Source IP - add technique and sub-techniques

Description

The Mitre Eval Score Analysis - 2022 [ Refer ] identified the following:

  • Valid Accounts (T1078)
  • Valid Accounts: Domain Accounts (T1078.002)
  • Valid Accounts: Local Accounts (T1078.003)

...to be added to the above rules to reflect the techniques above

Example Data

N/A

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Rule: Tuning tweaking or tuning an existing rule
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant