You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The rule didn't match this event 4662. (sorry for the german field names)
The problem seems to be that the accessmask is specified as a string in the rule. When changing AccessMask: '0x100' to AccessMask: 0x100 the rules matches correctly. I used THOR APT Scanner in version 10.7.12 on a kali linux machine for the scan.
Best regards,
ail4ni
The text was updated successfully, but these errors were encountered:
Hey @ail4ni thanks for reporting this. Can you export the evtx with this specific log event and share it here. It would be more helpful to debug this.
Thanks.
Hi,
I came across a possible bug in one of your rules.
https://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/security/win_security_dcsync.yml#L29
The rule didn't match this event 4662. (sorry for the german field names)
The problem seems to be that the accessmask is specified as a string in the rule. When changing
AccessMask: '0x100'
toAccessMask: 0x100
the rules matches correctly. I used THOR APT Scanner in version 10.7.12 on a kali linux machine for the scan.Best regards,
ail4ni
The text was updated successfully, but these errors were encountered: