Skip to content

Conversation

sbousseaden
Copy link
Contributor

@sbousseaden sbousseaden commented Jan 15, 2024

First Time Seen NewCredentials Logon Process :

excluding when the subject user name is the machine account and processes running from %programfiles%

Process Created with a Duplicated Token :

excluding couple of FPs by effective parent and parent.executable.

Interactive Logon by an Unusual Process :

excluding msiexec.exe, w3wp.exe and %programfiles%

Copy link

cla-checker-service bot commented Jan 15, 2024

💚 CLA has been signed

@sbousseaden sbousseaden changed the title [Tuning] First Time Seen NewCredentials Logon Process [Tuning] Tuning Windows - 3 Rules Jan 15, 2024
@Samirbous Samirbous self-assigned this Feb 5, 2024
@Samirbous Samirbous requested review from Samirbous and removed request for Samirbous February 5, 2024 15:50
@Samirbous Samirbous merged commit 853e189 into elastic:main Feb 20, 2024
protectionsmachine pushed a commit that referenced this pull request Feb 20, 2024
* Update privilege_escalation_newcreds_logon_rare_process.toml * Update privilege_escalation_make_token_local.toml * Update privilege_escalation_make_token_local.toml * Update privilege_escalation_create_process_with_token_unpriv.toml --------- Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com> Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> Removed changes from: - rules/windows/privilege_escalation_create_process_with_token_unpriv.toml - rules/windows/privilege_escalation_newcreds_logon_rare_process.toml (selectively cherry picked from commit 853e189)
protectionsmachine pushed a commit that referenced this pull request Feb 20, 2024
* Update privilege_escalation_newcreds_logon_rare_process.toml * Update privilege_escalation_make_token_local.toml * Update privilege_escalation_make_token_local.toml * Update privilege_escalation_create_process_with_token_unpriv.toml --------- Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com> Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> (cherry picked from commit 853e189)
protectionsmachine pushed a commit that referenced this pull request Feb 20, 2024
* Update privilege_escalation_newcreds_logon_rare_process.toml * Update privilege_escalation_make_token_local.toml * Update privilege_escalation_make_token_local.toml * Update privilege_escalation_create_process_with_token_unpriv.toml --------- Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com> Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> (cherry picked from commit 853e189)
protectionsmachine pushed a commit that referenced this pull request Feb 20, 2024
* Update privilege_escalation_newcreds_logon_rare_process.toml * Update privilege_escalation_make_token_local.toml * Update privilege_escalation_make_token_local.toml * Update privilege_escalation_create_process_with_token_unpriv.toml --------- Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com> Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> (cherry picked from commit 853e189)
protectionsmachine pushed a commit that referenced this pull request Feb 20, 2024
* Update privilege_escalation_newcreds_logon_rare_process.toml * Update privilege_escalation_make_token_local.toml * Update privilege_escalation_make_token_local.toml * Update privilege_escalation_create_process_with_token_unpriv.toml --------- Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com> Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> (cherry picked from commit 853e189)
protectionsmachine pushed a commit that referenced this pull request Feb 20, 2024
* Update privilege_escalation_newcreds_logon_rare_process.toml * Update privilege_escalation_make_token_local.toml * Update privilege_escalation_make_token_local.toml * Update privilege_escalation_create_process_with_token_unpriv.toml --------- Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com> Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> (cherry picked from commit 853e189)
protectionsmachine pushed a commit that referenced this pull request Feb 20, 2024
* Update privilege_escalation_newcreds_logon_rare_process.toml * Update privilege_escalation_make_token_local.toml * Update privilege_escalation_make_token_local.toml * Update privilege_escalation_create_process_with_token_unpriv.toml --------- Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com> Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> (cherry picked from commit 853e189)
protectionsmachine pushed a commit that referenced this pull request Feb 20, 2024
* Update privilege_escalation_newcreds_logon_rare_process.toml * Update privilege_escalation_make_token_local.toml * Update privilege_escalation_make_token_local.toml * Update privilege_escalation_create_process_with_token_unpriv.toml --------- Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com> Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> (cherry picked from commit 853e189)
protectionsmachine pushed a commit that referenced this pull request Feb 20, 2024
* Update privilege_escalation_newcreds_logon_rare_process.toml * Update privilege_escalation_make_token_local.toml * Update privilege_escalation_make_token_local.toml * Update privilege_escalation_create_process_with_token_unpriv.toml --------- Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com> Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> (cherry picked from commit 853e189)
protectionsmachine pushed a commit that referenced this pull request Feb 20, 2024
* Update privilege_escalation_newcreds_logon_rare_process.toml * Update privilege_escalation_make_token_local.toml * Update privilege_escalation_make_token_local.toml * Update privilege_escalation_create_process_with_token_unpriv.toml --------- Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com> Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> (cherry picked from commit 853e189)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment