X-Git-Url: http://ftp.carnet.hr/carnet-debian/scm?p=ossec-hids.git;a=blobdiff_plain;f=etc%2Frules%2Fmsauth_rules.xml;h=eda0490462ecfd4822e2cca218435486c0c0e25f;hp=432c3847278aa50313c84c3d53571dd5c5b3c6d9;hb=6ef2f786c6c8ead94841b5f93baf9f43421f08c8;hpb=301048b51990573e58a30dc4a5bb4ec285cad554 diff --git a/etc/rules/msauth_rules.xml b/etc/rules/msauth_rules.xml index 432c384..eda0490 100755 --- a/etc/rules/msauth_rules.xml +++ b/etc/rules/msauth_rules.xml @@ -1,4 +1,5 @@ - 18106 - ^529 + ^529$ Logon Failure - Unknown user or bad password. http://www.ultimatewindowssecurity.com/events/com190.html win_authentication_failed, @@ -209,7 +210,7 @@ 18106 - ^530 + ^530$ Logon Failure - Account logon time restriction violation. http://www.ultimatewindowssecurity.com/events/com191.html @@ -218,7 +219,7 @@ 18106 - ^531 + ^531$ Logon Failure - Account currently disabled. http://www.ultimatewindowssecurity.com/events/com192.html win_authentication_failed,login_denied, @@ -226,7 +227,7 @@ 18106 - ^532 + ^532$ Logon Failure - Specified account expired. http://www.ultimatewindowssecurity.com/events/com193.html win_authentication_failed,login_denied, @@ -234,7 +235,7 @@ 18106 - ^533 + ^533$ Logon Failure - User not allowed to login at this computer. http://www.ultimatewindowssecurity.com/events/com194.html @@ -243,7 +244,7 @@ 18106 - ^534 + ^534$ Logon Failure - User not granted logon type. http://www.ultimatewindowssecurity.com/events/com195.html win_authentication_failed, @@ -251,7 +252,7 @@ 18106 - ^535 + ^535$ Logon Failure - Account's password expired. http://www.ultimatewindowssecurity.com/events/com196.html win_authentication_failed, @@ -259,35 +260,35 @@ 18106 - ^536|^537 + ^536$|^537$ Logon Failure - Internal error. win_authentication_failed, 18106 - ^539 + ^539$ Logon Failure - Account locked out. win_authentication_failed, 18105 - ^672|^673|^675|^676|^681|^4769 + ^672$|^673$|^675$|^676$|^681$|^4769$ Windows DC Logon Failure. win_authentication_failed, - + 18104 - ^520 + ^520$ System time changed. time_changed, 18102 - ^1076 + ^1076$ unexpected shutdown system_error, system_shutdown, Unexpected Windows shutdown. @@ -295,7 +296,7 @@ 18104 - ^671|^4767 + ^671$|^4767$ User account unlocked. http://www.ultimatewindowssecurity.com/events/com291.html account_changed, @@ -303,14 +304,14 @@ 18114 - ^631|^635|^658 + ^631$|^635$|^658$ Security enabled group created. adduser,account_changed, 18114 - ^634|^638|^662 + ^634$|^638$|^662$ Security enabled group deleted. adduser,account_changed, @@ -318,7 +319,7 @@ 18101 - ^7040 + ^7040$ policy_changed, Service startup type was changed. This does not appear to be logged on Windows 2000. @@ -326,27 +327,27 @@ 18101 - ^11724 + ^11724$ alert_by_email Application Uninstalled. 18101 - ^11707 + ^11707$ alert_by_email Application Installed. 18104 - ^4608 + ^4608$ Windows is starting up. 18104 - ^538|^4634|^4647 + ^538$|^4634$|^4647$ Windows User Logoff. @@ -490,7 +491,7 @@ 18207,18208 - ID:\s+\p*S-1-5-32-544\p* + ID:\s+\p*S-1-5-32-544 Administrators Group Changed group_changed,win_group_changed, http://support.microsoft.com/kb/243330 @@ -812,7 +813,7 @@ --> 18107,18149 - ^528|^538|^540 + ^528$|^538$|^540$ ^LOCAL SERVICE|^NETWORK SERVICE|^ANONYMOUS LOGON Windows Logon Success (ignored). @@ -848,14 +849,14 @@ 18105 - ^18456 + ^18456$ win_authentication_failed, MS SQL Server Logon Failure. 18104 - ^18454|^18453 + ^18454$|^18453$ MS SQL Server Logon Success. authentication_success,