Detection rules › Kusto Query Language

DEV-0270 New User Creation

Source
upstream

'The following query tries to detect creation of a new user using a known DEV-0270 username/password schema'

MITRE ATT&CK coverage

TacticTechniques
PersistenceT1098 Account Manipulation
Privilege EscalationT1098 Account Manipulation

Event coverage

ProviderEvent IDTitle
Security-Auditing4688A new process has been created.

Stages and Predicates

Stage 1: source

<union>

Stage 2: union

union of 2 branches

Stage 3: extend

Stage 4: extend

Stage 5: extend