Rule Library
Sigma Rules
3 rules found for "Marius Rothenbücher"
3,731Total
3,132Detection
457Emerging
139Hunting
Detectionhighexperimental
Azure Login Bypassing Conditional Access Policies
Detects a successful login to the Microsoft Intune Company Portal which could allow bypassing Conditional Access Policies and InTune device trust using a tool like TokenSmith.
Microsoft 365audit
Josh Nickels+1Wed Jan 08cloud
Detectionmediumtest
Group Policy Abuse for Privilege Addition
Detects the first occurrence of a modification to Group Policy Object Attributes to add privileges to user accounts or use them to add users as local admins.
Windowssecurity
Elastic Security+2Wed Sep 04windows
Detectionmediumtest
Startup/Logon Script Added to Group Policy Object
Detects the modification of Group Policy Objects (GPO) to add a startup/logon script to users or computer objects.
Windowssecurity
Elastic Security+2Fri Sep 06windows