Update WindowsSystemTimeChange.yaml
This commit is contained in:
Родитель
70e49edf6e
Коммит
d6ca732e3f
|
@ -1,7 +1,8 @@
|
|||
id: 9fd6f61d-2cc3-48de-acf5-7194e78d6ea1
|
||||
name: Windows System Time changed on hosts
|
||||
description: |
|
||||
'Identifies when the system time was changed on a Windows host which can indicate potential timestomping activities.'
|
||||
'Identifies when the system time was changed on a Windows host which can indicate potential timestomping activities.
|
||||
Reference: Event ID 4616 is only available when the full event collection is enabled - https://docs.microsoft.com/azure/sentinel/connect-windows-security-events'
|
||||
requiredDataConnectors:
|
||||
- connectorId: SecurityEvents
|
||||
dataTypes:
|
||||
|
|
Загрузка…
Ссылка в новой задаче