User All Event Log Activity
This rule monitors Windows event logs for activity involving the SAM account name, which may indicate account enumeration, credential access attempts, or malicious modifications to account security settings.
Cortex XDR

This rule monitors Windows event logs for activity involving the SAM account name, which may indicate account enumeration, credential access attempts, or malicious modifications to account security settings.

Already have an account?