Data Source: Windows Event Log Security 4728

Description

Data source object for Windows Event Log Security 4728

Details

Property Value
Source XmlWinEventLog:Security
Sourcetype XmlWinEventLog
Separator EventCode
Name ▲▼ Technique ▲▼ Type ▲▼
Windows AD add Self to Group Account Manipulation TTP
Windows AD Privileged Group Modification Account Manipulation TTP

Supported Apps

Event Fields

+ Fields
  <span class="pill kill-chain">_time</span>
  
</div>

Required Output Fields

  • dest

Source: GitHub | Version: 2