File tree Expand file tree Collapse file tree 1 file changed +2
-2
lines changed
Expand file tree Collapse file tree 1 file changed +2
-2
lines changed Original file line number Diff line number Diff line change @@ -8,13 +8,13 @@ updated_date = "2024/07/22"
88author = [" Elastic" ]
99description = """
1010Identifies a potential forced authentication. Attackers may attempt to force targets to authenticate to a Linux machine
11- controlled by them to capture hashes or to enable relay attacks.
11+ controlled by them to capture hashes or enable relay attacks.
1212"""
1313from = " now-9m"
1414index = [" logs-endpoint.events.network-*" , " logs-system.security-*" ]
1515language = " eql"
1616license = " Elastic License v2"
17- name = " Potential Forced Authentication"
17+ name = " Active Directory Forced Authentication from Linux Host "
1818references = [
1919 " https://www.thehacker.recipes/a-d/movement/mitm-and-coerced-authentications/ms-efsr" ,
2020 " https://www.thehacker.recipes/a-d/movement/mitm-and-coerced-authentications/ms-rprn" ,
You can’t perform that action at this time.
0 commit comments