AN1137
Analytic 1137
Windows
Detects anomalous usage of local accounts to log into a system, especially accounts not typically used interactively or outside business hours.
WinEventLog:Security
EventCode=4624, 4648
WinEventLog:Security
EventCode=4672
[TimeWindow]
Tune for normal business hours to reduce false positives from legitimate after-hours work.
[UserContext]
Define list of legitimate local users for interactive access.
AN1138
Analytic 1138
Linux
Detects interactive or service logins from local accounts outside expected operational context or at anomalous times.
auditd:USER_LOGIN
USER_LOGIN
linux:auth
sshd login
[TimeWindow]
Define operational hours or expected login times per host.
[HostRole]
Differentiate expected behavior for server vs. workstation.
AN1139
Analytic 1139
macOS
Detects abnormal or rare logins via local accounts through system or remote mechanisms such as SSH.
macos:unifiedlog
loginwindow or sshd
[UserContext]
Restrict expected local users by device owner or role.
[TimeWindow]
Set appropriate bounds based on endpoint usage patterns.