alert any $EXTERNAL_NET any -> $HOME_NET any (msg: "[Strategy] Test - Stage A"; after: track by_src, count 2, seconds 300; sid: 10444675; rev: 12; reference: x; classtype: successful-user; xbits: set, WINDOWS_AUTHUseraccountcreateA, track ip_src, expire 86400; program: *Security*; pcre: "/ 4720: | 624: /"; )
alert any $EXTERNAL_NET any -> $HOME_NET any (msg: "[Strategy] Test - Stage B"; after: track by_src, count 2, seconds 300; sid: 44825366; rev: 6; classtype: successful-user; reference: x; xbits: isset,WINDOWS_AUTHUseraccountcreateA,track ip_src; xbits: set, WINDOWS_AUTHUseraccountdeleteB, track ip_src, expire 86400; program: *Security*; pcre: "/ 4726: | 630: /"; )
alert any $EXTERNAL_NET any -> $HOME_NET any (msg: "[Strategy] Test - Stage C"; after: track by_src, count 3, seconds 300; sid: 42509443; rev: 4; content: !"$ Account Domain|3a|"; program: *Security*; reference: ANP Default Rule; xbits: isset,WINDOWS_AUTHUseraccountdeleteB,track ip_src; xbits: set, WINDOWS_SECURITYAsecurity_ena, track ip_src, expire 86400; reference: x classtype: system-event; pcre: "/ 4735: | 639: /"; )