Password Policy Enumerated

 Original Source: [Sigma source]
Title: Password Policy Enumerated
Status: test
Description:Detects when the password policy is enumerated.
References:
  -https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4661
  -https://github.com/jpalanco/alienvault-ossim/blob/f74359c0c027e42560924b5cff25cdf121e5505a/os-sim/agent/src/ParserUtil.py#L951
Author: Zach Mathis
Date: 2023-05-19
modified:None
Tags:
  • -'attack.discovery'
  • -'attack.t1201'
Logsource:
  • product: windows
  • service: security
  • definition: dfd8c0f4-e6ad-4e07-b91b-f2fca0ddef64
Detection:
  selection:
    EventID: '4661'
    AccessList|contains: '%%5392'
    ObjectServer: 'Security Account Manager'
  condition:selection
Falsepositives:
Level: medium