Rule Info
Name
Potentially Suspicious Explicit Credential Local Logon
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects potentially suspicious explicit credential logon events where the user
is trying to logon with explicit credentials (username and password) that are
different from the current user context. It might indicate an attacker attempting
to escalate privileges after obtaining credentials for a different user account.
Date
2026-07-23 00:00:00
Modified
None
Id
e3c6d245-7b8f-4e2a-c17f-a9d0e5b38f62
Tags
attack.privilege-escalation attack.stealth attack.t1134 attack.t1134.003
Type
Community Rule
Link to Public Repo
Rule History
Author
Title
Date
Commit
Swachchhanda Shrawan Poudel
Merge PR #6169 from @swachchhanda000 - Add LegacyHive Indicators
2026-08-03
