Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

short_lived_windows_accounts.yml adding risk to user #2353

Open
jwindley-splunk opened this issue Aug 31, 2022 · 1 comment
Open

short_lived_windows_accounts.yml adding risk to user #2353

jwindley-splunk opened this issue Aug 31, 2022 · 1 comment

Comments

@jwindley-splunk
Copy link
Contributor

Can we not get the 'src_user' (from the Account Management dataset) in the results of the search? This would be more useful to add risk to rather than the target user account name that was created/deleted

@josehelps
Copy link
Collaborator

Hey @jwindley-splunk mind pointing me back to specific searches/detections you had in mind for this issue?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants