Splunk Search

How to generate a search that will show standard user accounts that escalate to administrator?

rodiers01
New Member

Good afternoon all. After an attacker gathers the login credentials for a standard user account they will want to elevate those same credentials to become an administrator. I'm looking to see if there's a search that I can run which will look for something like that? I'd like to generate an e-mail alert.

I have the following set-up below...

Cisco Security Suite, IIS Logging, Splunk App for Web Analytics, MS Windows AD Objects, Splunk App for Windows Infrastructure, Splunk Support for Active Directory.

Thanks folks.

0 Karma

woodcock
Esteemed Legend

Start here:

... EventCode=4728 OR EventCode=4732
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...