Rule Library
Sigma Rules
2 rules found for "keepwatch"
3,731Total
3,132Detection
457Emerging
139Hunting
Detectionmediumtest
Potential SPN Enumeration Via Setspn.EXE
Detects service principal name (SPN) enumeration used for Kerberoasting
WindowsProcess Creation
Markus Neis+1Wed Nov 14windows
Detectionhightest
Security Support Provider (SSP) Added to LSA Configuration
Detects the addition of a SSP to the registry. Upon a reboot or API call, SSP DLLs gain access to encrypted and plaintext passwords stored in Windows.
WindowsRegistry Event
iwillkeepwatchFri Jan 18windows