Skip to content

Commit

Permalink
Set target group when possible
Browse files Browse the repository at this point in the history
  • Loading branch information
marc-gr committed Feb 3, 2021
1 parent c20482d commit cc4c4cd
Show file tree
Hide file tree
Showing 35 changed files with 102 additions and 2 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -1941,10 +1941,16 @@ var security = (function () {
.Convert({
fields: [
{from: "winlog.event_data.TargetUserSid", to: "group.id"},
{from: "winlog.event_data.TargetSid", to: "group.id"},
{from: "winlog.event_data.TargetUserName", to: "group.name"},
{from: "winlog.event_data.TargetDomainName", to: "group.domain"},
],
ignore_missing: true,
}).Add(function(evt) {
if (!evt.Get("user.target")) return;
evt.Put("user.target.group.id", evt.Get("group.id"));
evt.Put("user.target.group.name", evt.Get("group.name"));
evt.Put("user.target.group.domain", evt.Get("group.domain"));
})
.Build();

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@
},
"group": {
"domain": "TEST",
"id": "S-1-5-21-1717121054-434620538-60925301-2903",
"name": "testdistlocal"
},
"host": {
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@
},
"group": {
"domain": "TEST",
"id": "S-1-5-21-1717121054-434620538-60925301-2903",
"name": "testdistlocal1"
},
"host": {
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@
},
"group": {
"domain": "TEST",
"id": "S-1-5-21-1717121054-434620538-60925301-2903",
"name": "testdistlocal1"
},
"host": {
Expand All @@ -37,6 +38,11 @@
"id": "S-1-5-21-1717121054-434620538-60925301-2794",
"name": "at_adm",
"target": {
"group": {
"domain": "TEST",
"id": "S-1-5-21-1717121054-434620538-60925301-2903",
"name": "testdistlocal1"
},
"name": "Administrator"
}
},
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@
},
"group": {
"domain": "TEST",
"id": "S-1-5-21-1717121054-434620538-60925301-2903",
"name": "testdistlocal1"
},
"host": {
Expand All @@ -37,6 +38,11 @@
"id": "S-1-5-21-1717121054-434620538-60925301-2794",
"name": "at_adm",
"target": {
"group": {
"domain": "TEST",
"id": "S-1-5-21-1717121054-434620538-60925301-2903",
"name": "testdistlocal1"
},
"name": "Administrator"
}
},
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@
},
"group": {
"domain": "TEST",
"id": "S-1-5-21-1717121054-434620538-60925301-2903",
"name": "testdistlocal1"
},
"host": {
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@
},
"group": {
"domain": "TEST",
"id": "S-1-5-21-1717121054-434620538-60925301-2904",
"name": "testglobal"
},
"host": {
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@
},
"group": {
"domain": "TEST",
"id": "S-1-5-21-1717121054-434620538-60925301-2904",
"name": "testglobal1"
},
"host": {
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@
},
"group": {
"domain": "TEST",
"id": "S-1-5-21-1717121054-434620538-60925301-2904",
"name": "testglobal1"
},
"host": {
Expand All @@ -37,6 +38,11 @@
"id": "S-1-5-21-1717121054-434620538-60925301-2794",
"name": "at_adm",
"target": {
"group": {
"domain": "TEST",
"id": "S-1-5-21-1717121054-434620538-60925301-2904",
"name": "testglobal1"
},
"name": "Administrator"
}
},
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@
},
"group": {
"domain": "TEST",
"id": "S-1-5-21-1717121054-434620538-60925301-2904",
"name": "testglobal1"
},
"host": {
Expand All @@ -37,6 +38,11 @@
"id": "S-1-5-21-1717121054-434620538-60925301-2794",
"name": "at_adm",
"target": {
"group": {
"domain": "TEST",
"id": "S-1-5-21-1717121054-434620538-60925301-2904",
"name": "testglobal1"
},
"name": "Administrator"
}
},
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@
},
"group": {
"domain": "TEST",
"id": "S-1-5-21-1717121054-434620538-60925301-2904",
"name": "testglobal1"
},
"host": {
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@
},
"group": {
"domain": "TEST",
"id": "S-1-5-21-1717121054-434620538-60925301-2905",
"name": "testuni"
},
"host": {
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@
},
"group": {
"domain": "TEST",
"id": "S-1-5-21-1717121054-434620538-60925301-2905",
"name": "testuni2"
},
"host": {
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@
},
"group": {
"domain": "TEST",
"id": "S-1-5-21-1717121054-434620538-60925301-2905",
"name": "testuni2"
},
"host": {
Expand All @@ -37,6 +38,11 @@
"id": "S-1-5-21-1717121054-434620538-60925301-2794",
"name": "at_adm",
"target": {
"group": {
"domain": "TEST",
"id": "S-1-5-21-1717121054-434620538-60925301-2905",
"name": "testuni2"
},
"name": "Administrator"
}
},
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@
},
"group": {
"domain": "TEST",
"id": "S-1-5-21-1717121054-434620538-60925301-2905",
"name": "testuni2"
},
"host": {
Expand All @@ -37,6 +38,11 @@
"id": "S-1-5-21-1717121054-434620538-60925301-2794",
"name": "at_adm",
"target": {
"group": {
"domain": "TEST",
"id": "S-1-5-21-1717121054-434620538-60925301-2905",
"name": "testuni2"
},
"name": "Administrator"
}
},
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@
},
"group": {
"domain": "TEST",
"id": "S-1-5-21-1717121054-434620538-60925301-2905",
"name": "testuni2"
},
"host": {
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,8 @@
"event": {
"action": "session-reconnected",
"category": [
"authentication"
"authentication",
"session"
],
"code": 4778,
"kind": "event",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,8 @@
"event": {
"action": "session-disconnected",
"category": [
"authentication"
"authentication",
"session"
],
"code": 4779,
"kind": "event",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@
},
"group": {
"domain": "WLBEAT",
"id": "S-1-5-21-101361758-2486510592-3018839910-1110",
"name": "DnsUpdateProxy"
},
"host": {
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@
},
"group": {
"domain": "WLBEAT",
"id": "S-1-5-21-101361758-2486510592-3018839910-1112",
"name": "test_group2"
},
"host": {
Expand All @@ -34,6 +35,11 @@
"id": "S-1-5-21-101361758-2486510592-3018839910-500",
"name": "Administrator",
"target": {
"group": {
"domain": "WLBEAT",
"id": "S-1-5-21-101361758-2486510592-3018839910-1112",
"name": "test_group2"
},
"name": "Administrator"
}
},
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@
},
"group": {
"domain": "WLBEAT",
"id": "S-1-5-21-101361758-2486510592-3018839910-1112",
"name": "test_group2v2"
},
"host": {
Expand All @@ -34,6 +35,11 @@
"id": "S-1-5-21-101361758-2486510592-3018839910-500",
"name": "Administrator",
"target": {
"group": {
"domain": "WLBEAT",
"id": "S-1-5-21-101361758-2486510592-3018839910-1112",
"name": "test_group2v2"
},
"name": "Administrator"
}
},
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@
},
"group": {
"domain": "WLBEAT",
"id": "S-1-5-21-101361758-2486510592-3018839910-1112",
"name": "test_group2v2"
},
"host": {
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@
},
"group": {
"domain": "WLBEAT",
"id": "S-1-5-21-101361758-2486510592-3018839910-1111",
"name": "test_group1"
},
"host": {
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@
},
"group": {
"domain": "WLBEAT",
"id": "S-1-5-21-101361758-2486510592-3018839910-1111",
"name": "test_group1"
},
"host": {
Expand All @@ -34,6 +35,11 @@
"id": "S-1-5-21-101361758-2486510592-3018839910-500",
"name": "Administrator",
"target": {
"group": {
"domain": "WLBEAT",
"id": "S-1-5-21-101361758-2486510592-3018839910-1111",
"name": "test_group1"
},
"name": "Administrator"
}
},
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@
},
"group": {
"domain": "WLBEAT",
"id": "S-1-5-21-101361758-2486510592-3018839910-1111",
"name": "test_group1"
},
"host": {
Expand All @@ -34,6 +35,11 @@
"id": "S-1-5-21-101361758-2486510592-3018839910-500",
"name": "Administrator",
"target": {
"group": {
"domain": "WLBEAT",
"id": "S-1-5-21-101361758-2486510592-3018839910-1111",
"name": "test_group1"
},
"name": "Administrator"
}
},
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@
},
"group": {
"domain": "WLBEAT",
"id": "S-1-5-21-101361758-2486510592-3018839910-1111",
"name": "test_group1v1"
},
"host": {
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@
},
"group": {
"domain": "WLBEAT",
"id": "S-1-5-21-101361758-2486510592-3018839910-1111",
"name": "test_group1v1"
},
"host": {
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@
},
"group": {
"domain": "WLBEAT",
"id": "S-1-5-21-101361758-2486510592-3018839910-1112",
"name": "test_group2v2"
},
"host": {
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@
},
"group": {
"domain": "WLBEAT",
"id": "S-1-5-21-101361758-2486510592-3018839910-1113",
"name": "Test_group3"
},
"host": {
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@
},
"group": {
"domain": "WLBEAT",
"id": "S-1-5-21-101361758-2486510592-3018839910-1113",
"name": "Test_group3v2"
},
"host": {
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@
},
"group": {
"domain": "WLBEAT",
"id": "S-1-5-21-101361758-2486510592-3018839910-1113",
"name": "Test_group3v2"
},
"host": {
Expand All @@ -34,6 +35,11 @@
"id": "S-1-5-21-101361758-2486510592-3018839910-500",
"name": "Administrator",
"target": {
"group": {
"domain": "WLBEAT",
"id": "S-1-5-21-101361758-2486510592-3018839910-1113",
"name": "Test_group3v2"
},
"name": "Administrator"
}
},
Expand Down
Loading

0 comments on commit cc4c4cd

Please sign in to comment.