Detection rules › By event
Microsoft-Windows-Security-Auditing event 4656
Sigma (12)
- Azure AD Health Monitoring Agent Registry Keys Access
- Azure AD Health Service Agents Registry Keys Access
- LSASS Access From Non System Account
- Password Dumper Activity on LSASS
- Potential Secure Deletion with SDelete
- Potentially Suspicious AccessMask Requested From LSASS
- Processes Accessing the Microphone and Webcam
- SAM Registry Hive Handle Request
- SCM Database Handle Failure
- SysKey Registry Keys Access
- WCE wceaux.dll Access
- Windows Defender Exclusion Registry Key - Write Access Requested