• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    User All Event Log Activity

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Goksel Atakan@gokselatakan
    •updated Aug 10, 2026•4•0•9

    This rule monitors Windows event logs for activity involving the SAM account name, which may indicate account enumeration, credential access attempts, or malicious modifications to account security settings.

    Cortex XDR

    Tags

    T1087 - Account DiscoveryT1098 - Account ManipulationTA0007 - DiscoveryTA0003 - PersistenceUser Account ModifiedCredential AccessWindowsWindows Eventlog SecurityActive Directory Domain Services

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?