You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Detects remote logins by Administrative users. Administrative users are identified using your local naming convention. Because each environment controls their user naming convention, this rule's expression must first be tailored around your environment and enabled. Adjust the section that reads: "LIKE '%admin%'" to your environment's administrator naming convention.
Additional Details
Detail
Value
Type
Templated Match
Category
Lateral Movement
Apply Risk to Entities
device_hostname, device_ip, user_username
Signal Name
Windows Admin User Remote Logon
Summary Expression
Remote logon by administrative user: {{user_username}} on host: {{device_hostname}}