fix(windows): simplify authentication correlation and repair rules that never fire - #2803
Merged
kryonsx merged 1 commit intoSep 30, 2026
Merged
Conversation
…at never fire Authentication correlation (filter 3.2.2 and seven rules): - Keep one derived source, log.authenticationSource. Drop log.authenticationSourceType and log.authenticationSourceDomain: on 27 servers the kind never separated a source, and the domain split one account written two ways more often than it separated two accounts. - Drop the two logon markers. The failed-logon marker repeated the search terms; the success marker was written on every successful logon and no rule read it. Kerberos and AD FS markers stay; their predicates cannot be written as exact terms. Remove the checks and history terms they imply. - Brute force counts failures per computer and source, whatever account they target, so password spraying is caught and one source raises one alert. Success after failures skips computer accounts. Rules that could never fire or broke at runtime: - LSASS handle access: both patterns were invalid (\l, \P), so the rule never matched; access mask 0x120089 was written as 1180185. - Certificate services: read Requester; SubjectUserName does not exist in events 4886 and 4887. - AdminSDHolder: read the ObjectDN of event 5136; 4662 names objects by GUID and 4670 does not cover directory objects. - SMBv1: event 3000 of the SMB server is the signal; the agent sends no message text. - Ransomware file writes: history searched target.user, which 4663 never has, so every candidate failed evaluation and tripped the circuit breaker. Count by dataSource, account and access mask. Alert keys that never resolved now use fields that exist (SAM, LSASS, ransomware, certificate, SMBv1). Dead branches removed: Sysmon event 1 with NewProcessName, pre-Vista logon codes and 4769 in the loopback Remote Desktop rule, and an NTDS history block that counted any object access on the computer. Co-Authored-By: Claude Opus 5.5 <[email protected]>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Review of all 48 Windows correlation rules against real logs from 27 v11.2.15 servers. That release runs this exact
v11commit (89cd26c4): the deployed Windows filter and rules are byte-identical. All server access was read-only.This pull request makes two kinds of fix:
1. Authentication correlation: simpler, same or better results
Filter
3.2.2and seven rules: brute force, failures followed by success, Kerberoasting, AS-REP roasting, silver ticket, golden ticket and AD FS.One source field instead of three.
log.authenticationSourcestays: the network address, else the workstation, else a domain-qualified account.log.authenticationSourceTypeandlog.authenticationSourceDomainare removed.Two unused markers removed.
log.authenticationCandidate.bruteforceAttackonly repeated the event code and the presence of source and account, which the search terms already require....bruteforceMultipleLogonFailureFollowedBySuccesswas written on every successful logon (about 3 million a day) and no rule read it.Brute force counts failures per computer and source, whatever account they target. This follows the rule's own description and catches password spraying (one source, many accounts, few tries each). Replaying 2 days of real failures from all servers:
One alert per computer and source; repeats are suppressed for 7 days.
Failures followed by success skips computer accounts (names ending in
$). They are 44% of successful logons, their passwords are machine-generated, and each one used to trigger a history search.Repeated
exists(...)checks and a duplicated list value in Kerberoasting are removed.2. Rules that could never fire, or broke when they ran
\l,\P), soregexMatchalways returned false. Mask0x120089was written as1180185(that is0x120219).1179785.SubjectUserName, which events 4886/4887 don't have; none of 726 real events had it.log.data.Requester, present on all of them.ObjectDN, notObjectName. 4670 never covers directory objects.log.data.ObjectDN. SYSTEM is excluded by its SID (S-1-5-18), so translated names are excluded too.log.message, which the Windows agent doesn't send (absent on 26 of 27 servers).Microsoft-Windows-SMBServeris itself the signal: Microsoft documents that the SMBServer Audit log writes 3000 for each SMBv1 access.target.user, which no 4663 has (0 of 936,902). Every candidate failed with "expression value cannot be nil after placeholder resolution", and after 5 errors the engine switched the rule off.origin.user, present on 100%) and access mask.Alert keys that never existed on these events are replaced with keys that do (SAM, LSASS, ransomware, certificate, SMBv1). Dead code removed:
eventCode 1branches that readNewProcessName. Sysmon usesImage, and no event 1 reached any server.Testing
plugins/alerts,go test ./...passes). 17 new raw fixtures cover every changed behavior, plus a spray case in the history test.v11files, the new cases fail for the reasons above: no match for LSASS, certificate, AdminSDHolder and SMBv1; the computer account matches; the spray misses; ransomware raises the nil-placeholder error.8a3ade7, the samecel.pluginbuild as the servers; the v11 events and alerts plugins; OpenSearch 2.19.1). Originalv11and this branch were run with the same inputs:Overlap with #2784
#2784 also touches
golden_ticket_detection.ymland the Windows filter. A test merge conflicts only in the golden ticket rule: its version line and its alert keys. There, #2784'sdeduplicateByshould win. The filter merges cleanly. I will rebase whichever of the two merges second.Not changed
log.message. Fixing it needs sample 342/516 events, because the event fields aren't documented.🤖 Generated with Claude Code