Skip to content

Playbook .security subfield missing on TargetSID field? #8977

Locked Answered by Jaap79
Jaap79 asked this question in Q&A
Discussion options

You must be logged in to vote

THIS Q&A CAN BE CLOSED!

I found it. Mistake on my own side... I had to use:
(event.code.security:"4728" AND winlog.event_data.TargetSid.security:*-512)

The sigma rule I made included a double " and the ElastAlert replaced it with a '*-512' instead!. Fixed!

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by dougburks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
1 participant