Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Added new rule to the "0580-win-security_rules.xml" file #408

Merged
merged 3 commits into from
May 30, 2019

Conversation

MiguelCasaresRobles
Copy link
Member

Hi team,

I have added a new rule to catch the event which ID is 1102 and the description is: The audit log was cleared.

Regards,

Miguel Casares

Hi team,

I have added a new rule to catch the event which ID is 1102 and the description is: The audit log was cleared.

Regards,

Miguel Casares
@MiguelCasaresRobles MiguelCasaresRobles added operations rules Rules related issues labels May 23, 2019
@MiguelCasaresRobles MiguelCasaresRobles self-assigned this May 23, 2019
@MiguelCasaresRobles MiguelCasaresRobles changed the base branch from master to 3.9 May 23, 2019 10:51
rules/0580-win-security_rules.xml Outdated Show resolved Hide resolved
@chemamartinez chemamartinez added this to the 22nd week milestone May 27, 2019
Performed requested changes.

That rule was wrong due to the correct security value is INFORMATION instead of AUDIT_SUCCESS so the parent rule should be the 60100, not 60103.
@chemamartinez chemamartinez merged commit 5a33531 into 3.9 May 30, 2019
@chemamartinez chemamartinez deleted the 3.9-new-rules-ID1102 branch May 30, 2019 16:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
operations rules Rules related issues
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants