GoldenSpray Lab
event.action: Logon AND event.outcome: failure
event.action: Logon AND event.outcome: failure AND winlog.event_data.IpAddress: "77.91.78.115"








Last updated
event.action: Logon AND event.outcome: failure
event.action: Logon AND event.outcome: failure AND winlog.event_data.IpAddress: "77.91.78.115"








Last updated
event.action: Logon AND winlog.event_data.IpAddress: "77.91.78.115"event.code: 11 AND "ST-WIN02" AND "mwilliams"
#OR
event.code: 1 AND "ST-WIN02" AND "mwilliams"event.code: 1 AND "ST-WIN02" AND "*mimikatz.exe"event.action: Logon AND winlog.event_data.IpAddress: "77.91.78.115"event.code: 1 AND "*schtasks.exe"event.code: 11 AND winlog.event_data.Image: *powershell AND "jsmith"