This is a helper report for the lateral movement report pack and alerting capability that was released a while back.
This will query for the eventID's that are required to trip the alerting and reporting that were released, to make it easier to understand if the required data is available for the content that was published.
https://community.rsa.com/community/products/netwitness/blog/2016/03/09/lateral-movementwindows
Contents:
1 report
8 rules
Imports into Threats - Windows Lateral Movement
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.