mirror of
https://github.com/OTRF/OSSEM-DM
synced 2026-06-08 12:05:55 +00:00
ed1cbddce4
- updated numerical event_id to string. - alignment with OSSEM-DD and readme description
36 lines
883 B
YAML
36 lines
883 B
YAML
relationship_id: REL-2022-0024
|
|
name: User enabled User
|
|
contributors:
|
|
- Jose Rodriguez @Cyb3rPandaH
|
|
- Roberto Rodriguez @Cyb3rWard0g
|
|
- Olaf Hartong @olafhartong
|
|
attack:
|
|
data_source: user account
|
|
data_component: user account modification
|
|
behavior:
|
|
source: user
|
|
relationship: enabled
|
|
target: user
|
|
security_events:
|
|
- event_id: '4722'
|
|
name: A user account was enabled.
|
|
platform: windows
|
|
audit_category: Account Management
|
|
audit_sub_category: User Account Management
|
|
channel: Security
|
|
log_source: Microsoft-Windows-Security-Auditing
|
|
event_version:
|
|
- '0'
|
|
- event_id: DeviceEvents
|
|
name: DeviceEvents
|
|
platform: windows
|
|
log_source: Microsoft Defender for Endpoint
|
|
filter_in:
|
|
- ActionType: UserAccountModified
|
|
event_version:
|
|
- '0'
|
|
- '1'
|
|
references:
|
|
- https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4722
|
|
notes: null
|