Files
OTRF-OSSEM-DM/relationships/user_enabled_user.yml
Jose Rodriguez ed1cbddce4 General update on relationships
- updated numerical event_id to string.
- alignment with OSSEM-DD and readme description
2022-09-22 13:07:27 -04:00

36 lines
883 B
YAML

relationship_id: REL-2022-0024
name: User enabled User
contributors:
- Jose Rodriguez @Cyb3rPandaH
- Roberto Rodriguez @Cyb3rWard0g
- Olaf Hartong @olafhartong
attack:
data_source: user account
data_component: user account modification
behavior:
source: user
relationship: enabled
target: user
security_events:
- event_id: '4722'
name: A user account was enabled.
platform: windows
audit_category: Account Management
audit_sub_category: User Account Management
channel: Security
log_source: Microsoft-Windows-Security-Auditing
event_version:
- '0'
- event_id: DeviceEvents
name: DeviceEvents
platform: windows
log_source: Microsoft Defender for Endpoint
filter_in:
- ActionType: UserAccountModified
event_version:
- '0'
- '1'
references:
- https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4722
notes: null