Alerts related to data source "Windows Event Collector".
A computer account was promoted to DC
A machine certificate was issued with a mismatch
A new machine attempted Kerberos delegation
A user account was modified to password never expires
A user certificate was issued with a mismatch
A user changed the Windows system time
A user enabled a default local account
A user modified the CA audit policy
A user printed an unusual number of files
A user received multiple weakly encrypted service tickets
A user requested multiple service tickets
A user sent multiple TGT requests to irregular service
A user was added to a Windows security group
ADFS DKM Key Access
Administrator groups enumerated via LDAP
Deletion of AD CS certificate database entries
Excessive user account lockouts
Key credential attribute modification
Local group enumeration
Local user account creation
Local user account creation by a machine account
Machine account was added to a domain admins group
Mailbox Client Access Setting (CAS) changed
Masquerading as a default local account
Member added to a Windows local security group
Multiple suspicious user accounts were created
Multiple TGT requests for users without Kerberos pre-authentication
Multiple user accounts were deleted
PKINIT TGT authentication request
Possible Kerberos relay attack
Possible Privilege Escalation using Delegated MSA account
Potential DCSync by an unusual user
PowerShell used to export mailbox contents
PowerShell used to remove mailbox export request logs
Privileged certificate request via certificate template
Rare machine account creation
Sensitive account password reset attempt
Service ticket request with a spoofed sAMAccountName
Short-lived user account
Single account excessively locked out
SPNs cleared from a machine account
Suspicious access of the System Management Container
Suspicious account attribute modification that matches that of another account
Suspicious certificate template modification
Suspicious dNSHostName attribute change to DC name
Suspicious domain user account creation
Suspicious hidden user created
Suspicious modification of the AdminSDHolder's ACL
Suspicious sAMAccountName change
TGT request with a spoofed sAMAccountName - Event log
Unusual user account enablement
Unusual user account unlock
User account delegation change
User added SID History to an account
User added to a group and removed
User added to the SMS Admins local group
Vulnerable certificate template loaded
Was this helpful?