Detection rules › Sigma

Locked Workstation

Severity
informational
Author
Alexandr Yampolskyi, SOC Prime
Source
upstream

Detects locked workstation session events that occur automatically after a standard period of inactivity.

Event coverage

ProviderEvent IDTitle
Security-Auditing4800The workstation was locked.

Stages and Predicates

Stage 1: selection