diff --git a/Windows Logon Sessions/91570-win_logonsessions_rules.xml b/Windows Logon Sessions/91570-win_logonsessions_rules.xml new file mode 100644 index 0000000..f73733e --- /dev/null +++ b/Windows Logon Sessions/91570-win_logonsessions_rules.xml @@ -0,0 +1,13 @@ + + + json + \.+ + \.+ + Windows Logon Sessions - Snapshot + + T1078 + + no_full_log + windows_logonsessions, + +