Tag
high
advisory
Windows Audit Policy Restored via Auditpol.exe
2 rules 1 TTPAttackers may use auditpol.exe with the /restore argument to replace the existing audit policy with a malicious one, disabling auditing to evade detection, potentially leading to full machine compromise or lateral movement.
Splunk Enterprise +2
auditpol
audit-policy
defense-evasion
windows
2r
1t
high
advisory
Windows Audit Policy Disabled
3 rulesDetection of disabled important audit policies via Windows EventCode 4719, indicating potential attacker attempts to evade detection on a compromised domain controller, leading to data theft, privilege escalation, and network compromise.
Splunk Enterprise +2
audit-policy
defense-evasion
windows
3r