60106administrateurWindows Logon Sucess Adminno_full_logauthentication_success,pci_dss_10.2.5,gpg13_7.1,gpg13_7.2,gdpr_IV_32.2,hipaa_164.312.b,nist_80>9265110User: $(win.eventdata.subjectDomainName)\$(win.eventdata.targetUserName) logged using Remote Desktop Connection (RDP) from ip:$(win.eventdata.ipAddress).T1021.001T1078.00260103^4672$^S-1-5-18$Special privileges assigned to new logon.T1484no_full_log60103^528$|^540$|^673$|^4624$|^4769$Windows Logon Successno_full_logT107860103^538$|^551$|^4634$|^4647$Windows User Logoffno_full_log67028Privileged logon during quiet hours (00:00–05:00 local)no_full_log60137administrateurWindows Logoff Adminno_full_logauthentication_success,pci_dss_10.2.5,gpg13_7.1,gpg13_7.2,gdpr_IV_32.2,hipaa_164.312.b,nist_80>