Skip to content

Instantly share code, notes, and snippets.

@MarkUlmer
Created August 28, 2017 16:18
Show Gist options
  • Save MarkUlmer/4df5b111ac55768b74ddda16a50baa9a to your computer and use it in GitHub Desktop.
Save MarkUlmer/4df5b111ac55768b74ddda16a50baa9a to your computer and use it in GitHub Desktop.
ArcSight Logger Search - Windows Events for Group Membership Changes
deviceEventClassId IN ["Microsoft-Windows-Security-Auditing:4737","Microsoft-Windows-Security-Auditing:4732","Microsoft-Windows-Security-Auditing:4757","Microsoft-Windows-Security-Auditing:4733","Microsoft-Windows-Security-Auditing:4729","Microsoft-Windows-Security-Auditing:4756"] and NOT (destinationUserName ENDSWITH "$") and NOT (sourceUserName ENDSWITH "$")
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment