mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
minor
This commit is contained in:
@@ -3,7 +3,7 @@ id: 57551656-ebdb-11eb-afdf-acde48001122
|
||||
version: 1
|
||||
date: '2021-07-23'
|
||||
author: Michael Haag, Mauricio Velazco, Splunk
|
||||
type: batch
|
||||
type: Hunting
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The following analytic identifies access to SAM, SYSTEM or SECURITY databases' within the file path of `windows\system32\config` using Windows Security EventCode 4663. This particular behavior is related to credential access, an attempt to either use a Shadow Copy or recent CVE-2021-36934 to access the SAM database.
|
||||
|
||||
Reference in New Issue
Block a user