You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to Wazuh mailing list
Hi!
We have a software deployment server that accesses other pc's in our environment that uses LAPS as credentials for install.
I am receiving a lot of alerts (SID# 92652: Successful Remote Logon Detected - NTLM authentication, possible pass-the-hash attack).
I would like to silence the alerts from these accounts/machine pushing the software. Below is my custom rule, but wazuh seems to ignore it. Formatting is correct but as I type this the below looks a little wonky from pasting.