Skip to content

RDP rules need to be updated to switch from SecurityEvent table to Defender tables such as DeviceLogonEvents table #13377

@AmudaPalani

Description

@AmudaPalani

Describe the bug
This rule https://github.com/Azure/Azure-Sentinel/blob/master/Detections/SecurityEvent/RDP_Nesting.yaml is no longer valid because this event id logs are sent to DeviceLogonEvents table instead of SecurityEvent table. But this rule is yet to be updated. Please update this rule?

Metadata

Metadata

Labels

DetectionDetection specialty review needed

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions