Skip to content

Conversation

@cr-mpandya
Copy link
Contributor

  • Windows - Failed Logins Across Multiple Hosts
  • Windows - Logins to multiple systems from the same IP
  • Windows - Logon using built-in Administrator accounts
  • PowerShell Encoded Command Detection
  • Windows - Scheduled Task Started/Deleted
  • rdp logons after working hours (logon type 10)
  • Modifications on File Servers

@cr-mpandya cr-mpandya changed the title Add usecases for windows Added usecases for windows Jan 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants