Detection rules › By eventMicrosoft-Windows-Security-Auditing event 46722 detection rules reference this event. View event page.Elastic (1)Suspicious Remote Registry Access via SeBackupPrivilege T1003, T1003.002, T1003.004, T1021, T1021.002 Splunk (1)Windows Special Privileged Logon On Multiple Hosts T1021.002, T1087, T1135