Skip to content

Commit 62464ad

Browse files
committed
Update credential_access_forced_authentication.toml
1 parent 4b0453e commit 62464ad

File tree

1 file changed

+3
-1
lines changed

1 file changed

+3
-1
lines changed

rules/cross-platform/credential_access_forced_authentication.toml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -35,7 +35,9 @@ tags = [
3535
"OS: Linux",
3636
"Use Case: Threat Detection",
3737
"Tactic: Credential Access",
38-
"Data Source: Elastic Defend"
38+
"Data Source: Elastic Defend",
39+
"Data Source: Active Directory",
40+
"Use Case: Active Directory Monitoring",
3941
]
4042
timestamp_override = "event.ingested"
4143
type = "eql"

0 commit comments

Comments
 (0)