Skip to content

Commit

Permalink
fix(rules): fix rule for ldapfw name impersonation
Browse files Browse the repository at this point in the history
  • Loading branch information
dekelpaz committed Nov 2, 2023
1 parent 7a71de3 commit 3a21753
Showing 1 changed file with 2 additions and 2 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -21,8 +21,8 @@ logsource:
detection:
selection:
EventLog: LDAPFW
EventID: 259
DN|re: 'sAMAccountName:\w+[,][\s]'
EventID: 261
EntryList|re: 'sAMAccountName:[^,$]*([,]{1}|$)'
condition: selection
falsepositives:
- Unknown
Expand Down

0 comments on commit 3a21753

Please sign in to comment.