Techniques
Sample rules
Successful Account Login Via WMI
- source: sigma
- technicques:
- t1047
Description
Detects successful logon attempts performed with WMI
Detection logic
condition: selection
selection:
EventID: 4624
ProcessName|endswith: \WmiPrvSE.exe