Detection rules › By eventMicrosoft-Windows-Security-Auditing event 46613 detection rules reference this event. View event page.Sigma (3)AD Privileged Users or Groups Reconnaissance severity high T1087.002 Password Policy Enumerated severity medium T1201 Reconnaissance Activity severity high T1069.002, T1087.002