Skip to content

Instantly share code, notes, and snippets.

@Samirbous
Created January 4, 2022 14:27
Show Gist options
  • Star 1 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save Samirbous/ecdfe0216cbc687e2fe7f2d5f8bc1a21 to your computer and use it in GitHub Desktop.
Save Samirbous/ecdfe0216cbc687e2fe7f2d5f8bc1a21 to your computer and use it in GitHub Desktop.
event.code:4688 and winlog.event_data.TargetUserSid :"S-1-0-0" and not winlog.event_data.TargetUserName:*$ and
not winlog.event_data.TargetUserName:- and not winlog.event_data.TargetUserName:"defaultuser100000" and
not winlog.event_data.TargetUserName : ("LOCAL SERVICE" or "NETWORK SERVICE") and
not winlog.event_data.TargetDomainName : ("NT Service" or "Font Driver Host")
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment