Skip to content

Instantly share code, notes, and snippets.

@MarkUlmer
Created August 28, 2017 16:16
Show Gist options
  • Save MarkUlmer/87308c61053c0e02273af35e356f6861 to your computer and use it in GitHub Desktop.
Save MarkUlmer/87308c61053c0e02273af35e356f6861 to your computer and use it in GitHub Desktop.
ArcSight Logger Search - Windows Events for Account Changes
deviceEventClassId IN ["Microsoft-Windows-Security-Auditing:4740","Microsoft-Windows-Security-Auditing:4722","Microsoft-Windows-Security-Auditing:4738","Microsoft-Windows-Security-Auditing:4781","Microsoft-Windows-Security-Auditing:4720","Microsoft-Windows-Security-Auditing:4725","Microsoft-Windows-Security-Auditing:4724","Microsoft-Windows-Security-Auditing:4723","Microsoft-Windows-Security-Auditing:4767","Microsoft-Windows-Security-Auditing:6279"] and NOT (destinationUserName ENDSWITH "$") and NOT (sourceUserName ENDSWITH "$")
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment