Updated detected events
This commit is contained in:
@ -96,8 +96,11 @@ See 'Logging setup' section below for how to configure these logs
|
|||||||
* Suspicious service creation
|
* Suspicious service creation
|
||||||
* Service creation errors
|
* Service creation errors
|
||||||
* Stopping/starting the Windows Event Log service (potential event log manipulation)
|
* Stopping/starting the Windows Event Log service (potential event log manipulation)
|
||||||
|
* Mimikatz
|
||||||
|
* `lsadump::sam`
|
||||||
|
* `token::elevate`
|
||||||
* EMET & Applocker Blocks
|
* EMET & Applocker Blocks
|
||||||
* Sensitive Privilege Use (Mimikatz)
|
|
||||||
|
|
||||||
...and more
|
...and more
|
||||||
|
|
||||||
|
Reference in New Issue
Block a user