Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Incomplete list of Alerts #682

Open
esatymn opened this issue Mar 25, 2024 · 2 comments
Open

Incomplete list of Alerts #682

esatymn opened this issue Mar 25, 2024 · 2 comments

Comments

@esatymn
Copy link

esatymn commented Mar 25, 2024

[Enter feedback here]

Greetings!

I have noticed that the list of alerts at this page is incomplete. A customer requested log details being sent to Sentinel or a SIEM to identify the correct alert names.

Will it be possible to add sample logs for the below (and perhaps more) missing alerts?

  • Suspected exploitation attempt on Windows Print Spooler service (external ID 2415)
  • Suspected NTLM relay attack (Exchange account) (external ID 2037)
  • Suspected rogue Kerberos certificate usage (external ID 2047)
  • Suspected SMB packet manipulation (CVE-2020-0796 exploitation) (external ID 2406)
  • Exchange Server Remote Code Execution (CVE-2021-26855) (external ID 2414)
  • Suspicious modification of a sAMNameAccount attribute (CVE-2021-42278 and CVE-2021-42287 exploitation) (external ID 2419)
  • Suspected Netlogon privilege elevation attempt (CVE-2020-1472 exploitation) (external ID 2411)
  • Suspected AS-REP Roasting attack (external ID 2412)
  • Suspected Golden Ticket usage (ticket anomaly using RBCD) (external ID 2040)
  • Suspicious edit of the Resource Based Constrained Delegation Attribute by a machine account (KrbRelayUp)
  • Suspicious Kerberos delegation attempt using BronzeBit method (CVE-2020-17049 exploitation) (external ID 2048)

Regards

Document Details

Do not edit this section. It is required for learn.microsoft.com ➟ GitHub issue linking.

@batamig
Copy link
Collaborator

batamig commented Mar 25, 2024

@RonitLitinsky can you take a look at this item? Can we plan to update the docs for any of these?

@esatymn
Copy link
Author

esatymn commented Mar 26, 2024 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants