Hi All,Has anybody implemented a search to detect the following use case ?https://adsecurity.org/?p=1785 Any suggestions how to write the query will be highly appreciated. We are getting AD logs in with all the necessary auditing enabled.