LoFP LoFP / legitimate remote administration activity

Techniques

Sample rules

Outgoing Logon with New Credentials

Description

Detects logon events that specify new credentials

Detection logic

condition: selection
selection:
  EventID: 4624
  LogonType: 9