Locked Workstation
Detects locked workstation session events that occur automatically after a standard period of inactivity.
Sigma rule (View on GitHub)
1title: Locked Workstation
2id: 411742ad-89b0-49cb-a7b0-3971b5c1e0a4
3status: stable
4description: Detects locked workstation session events that occur automatically after a standard period of inactivity.
5references:
6 - https://www.cisecurity.org/controls/cis-controls-list/
7 - https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf
8 - https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf
9 - https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4800
10author: Alexandr Yampolskyi, SOC Prime
11date: 2019-03-26
12modified: 2023-12-11
13tags:
14 - attack.impact
15 # - CSC16
16 # - CSC16.11
17 # - ISO27002-2013 A.9.1.1
18 # - ISO27002-2013 A.9.2.1
19 # - ISO27002-2013 A.9.2.2
20 # - ISO27002-2013 A.9.2.3
21 # - ISO27002-2013 A.9.2.4
22 # - ISO27002-2013 A.9.2.5
23 # - ISO27002-2013 A.9.2.6
24 # - ISO27002-2013 A.9.3.1
25 # - ISO27002-2013 A.9.4.1
26 # - ISO27002-2013 A.9.4.3
27 # - ISO27002-2013 A.11.2.8
28 # - PCI DSS 3.1 7.1
29 # - PCI DSS 3.1 7.2
30 # - PCI DSS 3.1 7.3
31 # - PCI DSS 3.1 8.7
32 # - PCI DSS 3.1 8.8
33 # - NIST CSF 1.1 PR.AC-1
34 # - NIST CSF 1.1 PR.AC-4
35 # - NIST CSF 1.1 PR.AC-6
36 # - NIST CSF 1.1 PR.AC-7
37 # - NIST CSF 1.1 PR.PT-3
38logsource:
39 product: windows
40 service: security
41detection:
42 selection:
43 EventID: 4800
44 condition: selection
45falsepositives:
46 - Likely
47level: informational
References
Related rules
- AADInternals PowerShell Cmdlets Execution - ProccessCreation
- AADInternals PowerShell Cmdlets Execution - PsScript
- AWS EC2 Disable EBS Encryption
- AWS EFS Fileshare Modified or Deleted
- AWS EFS Fileshare Mount Modified or Deleted