Smartcard Disabled and Not Re-enabled
Similar to my previous rule, this detects when a user accounts smartcard is disabled (change code 2060) but not subsequently re-enabled (change code 2092) within the observed timeframe. This could indicate malicious activity such as an attacker disabling accounts to bypass multi-factor authentication or other security controls. This version of the rule is designed to run as a scheduled correlation based on your time acceptance of a users smartcard being disabled. This will suppress the quick helpdesk troubleshooting of accounts since it only fires if the smartcard remains disabled, however the detection will be slower since it does not fire on the real time event.
Cortex XDR

