You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Rules: Modification of Windows Network Logon Scripts
Description
Detects modifications of Windows Network Logon Scripts on domain controllers. Windows Network Logon Scripts are distributed to systems on a domain and can be used by an adversary to establish persistence across a network.
Additional Details
Detail
Value
Type
Templated Match
Category
Persistence
Apply Risk to Entities
device_hostname
Signal Name
Modification of Windows Logon Scripts
Summary Expression
Observed network logon script modification on host: {{device_hostname}}