Comparing values of 2 fields in detection. #52
Unanswered
anon-e-mousse
asked this question in
Q&A
Replies: 1 comment
-
I also think this feature would be helpful for writing rules. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Hey all,
I was wondering whether there is a way to compare 2 field values within a sigma rule.
My use case:
In order to see whether a new user account is domain or local, I would like to compare the new users domain name and the hostname. If they are the same that would indicate local account.
So the detection would look something like the following:
detection:
selection:
EventID: 4720
filter:
host: DomainName
condition: selection and filter
Please do not recommend other ways of detecting local accounts vs domain accounts. This is relevant to other alerts too.
Thanks!
Beta Was this translation helpful? Give feedback.
All reactions