Skip to content

[BUG] Detection picking up domain account creation on DC #3736

@dluxtron

Description

@dluxtron

Detection https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_create_local_account.yml

Picking up domain user accounts created on a DC - may be worth adding a note to false positives section to exclude events from a DC?

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions