Detection rules › By eventMicrosoft-Windows-Security-Auditing event 47942 detection rules reference this event. View event page.Sigma (1)Password Change on Directory Service Restore Mode (DSRM) Account severity high T1098 Splunk (1)Windows AD DSRM Password Reset T1098