Skip to content

Commit 642c94f

Browse files
Merge pull request #3801 from anunesms/patch-5
Update alerts-overview.md
2 parents 99c0995 + c221af2 commit 642c94f

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

ATPDocs/alerts-overview.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -63,7 +63,7 @@ The following table lists the mapping between alert names, their corresponding u
6363
| [Suspected WannaCry ransomware attack](lateral-movement-alerts.md#suspected-wannacry-ransomware-attack-external-id-2035) | 2035 | Medium | Lateral movement |
6464
| [Remote code execution over DNS](lateral-movement-alerts.md#remote-code-execution-attempt-over-dns-external-id-2036) | 2036 | Medium | Lateral movement, Privilege escalation |
6565
| [Suspected NTLM relay attack](lateral-movement-alerts.md#suspected-ntlm-relay-attack-exchange-account-external-id-2037) | 2037 | Medium or Low if observed using signed NTLM v2 protocol | Lateral movement, Privilege escalation |
66-
| [Security principal reconnaissance (LDAP)](credential-access-alerts.md#security-principal-reconnaissance-ldap-external-id-2038) | 2038 | Medium | Credential access |
66+
| [Security principal reconnaissance (LDAP)](credential-access-alerts.md#security-principal-reconnaissance-ldap-external-id-2038) | 2038 | High (in case resolutions issues or Specific Tool detected) and Medium | Credential access |
6767
| [Suspected NTLM authentication tampering](lateral-movement-alerts.md#suspected-ntlm-authentication-tampering-external-id-2039) | 2039 | Medium | Lateral movement, Privilege escalation |
6868
| [Suspected Golden Ticket usage (ticket anomaly using RBCD)](persistence-privilege-escalation-alerts.md#suspected-golden-ticket-usage-ticket-anomaly-using-rbcd-external-id-2040) | 2040 | High | Persistence |
6969
| [Suspected rogue Kerberos certificate usage](lateral-movement-alerts.md#suspected-rogue-kerberos-certificate-usage-external-id-2047) | 2047 | High | Lateral movement |

0 commit comments

Comments
 (0)