Windows User Account Activity Create User (via Splunk)

info Nessus Network Monitor Plugin ID 710001

Synopsis

SIEM Pull Service has detected via Splunk query that, on this Windows system, a user account was created.

Description

SIEM Pull Service has detected via Splunk query that, on this Windows system, a user account was created. The query used was (sourcetype="WinEventLog:Security" Message="*user*created*")

Solution

N/A

Plugin Details

Severity: Info

ID: 710001

Family: Policy

Published: 8/20/2004

Updated: 5/18/2018