Skip to content

Instantly share code, notes, and snippets.

@Samirbous
Created January 28, 2023 23:05
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save Samirbous/ace96ae7ec63ecf36df7a20fcaa52613 to your computer and use it in GitHub Desktop.
Save Samirbous/ace96ae7ec63ecf36df7a20fcaa52613 to your computer and use it in GitHub Desktop.
any where event.action == "Directory Service Access" and
event.code == "4662" and
not winlog.event_data.SubjectUserSid : "S-1-5-18" and
winlog.event_data.AccessListDescription : "Read Property" and
length(winlog.event_data.Properties) >= 800
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment