IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Use Case Suggestion: Disabled Account Enabled

    Posted Thu July 13, 2023 12:00 AM
    Edited by Cyber Post Thu July 13, 2023 12:11 AM

    Hi All,

    I need a suggestion on excluding the below items from the Rule.

    We have a rule in place to monitor if any of the disabled accounts are enabled using Microsoft Windows security logs.

    But when a new account is created it will be by default in the disabled state. How can we exclude the same event from the rule?

    Customers don't want to trigger if a new account created in the disabled state was enabled at a later point.

    There is one Rule for adding the disabled account to the reference set and another rule for detecting when the disabled account in the reference set got enabled,

    How to exclude and in which Rule do we need to exclude what? 

    Thanks



  • 2.  RE: Use Case Suggestion: Disabled Account Enabled

    Posted Fri July 14, 2023 04:33 AM

    So, you do not want to trigger if a user account was enabled in short period of time after that user account was created ...  Can't something like this be used for exclusion?
    AND NOT when these rules match at least this many times in this many minutes after any of these rules match with the same event properties



    ------------------------------
    Dusan VIDOVIC
    ------------------------------



  • 3.  RE: Use Case Suggestion: Disabled Account Enabled

    Posted Fri July 14, 2023 05:11 AM

    Thanks @Dusan VIDOVIC Will try this.