Identity Compromise Investigation

SkillSecurity

Investigate suspected account compromise, brute force followed by success, impossible travel, privilege escalation and lateral movement across Linux and Windows; use when a user account appears in suspicious authentication activity.

Available today. Use it from your connected AI after setup.

Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

Then ask your AI: use the Identity Compromise Investigation skill

What this skill tells your AI

The instructions your AI receives, as published by gensecaihq/wazuh-autopilot in backend/app/skills/identity-compromise/SKILL.md and read by ahel’s review.

Accounts are the most common path to impact. Decide whether an account is compromised, how far it was used, and what containment is justified.

Key events and the Wazuh rules that surface them

Rule numbers are from the stock Wazuh 4.14 ruleset. Many Windows events are only alerted on when the channel is collected and not filtered. If there's no rule, search the raw event with search_security_events (field data.win.system.eventID). Load wazuh-windows-sysmon for Windows field paths.

PlatformEventWazuh rulesMeaning
WindowsEvent ID 4624rule 60106 (level 3)successful logon; check data.win.eventdata.logonType: 2 interactive, 3 network, 10 RemoteInteractive/RDP
WindowsEvent ID 4625rules 60105, 60122 (level 5); burst → rule 60204 (level 10)failed logon; subStatus separates bad password from unknown user
WindowsEvent ID 4648none (search raw events)logon with explicit credentials (runas, lateral tools)
WindowsEvent ID 4672rule 67028 (level 3)special privileges assigned: admin-equivalent logon. Low level, high meaning for non-admins
WindowsEvent ID 4720, Event ID 4722rule 60109 (level 8)account created / enabled
WindowsEvent ID 4738rule 60110 (level 8)account changed
WindowsEvent ID 4728, Event ID 4732, Event ID 4756rules 60141, 60144, 60151 (level 5); rule 60154 Administrators group changed (level 12)member added to security-enabled global / local / universal group
WindowsEvent ID 4740 lockoutrule 60115 (level 9)account locked out after multiple failures
WindowsEvent ID 4768, Event ID 4771none stock (search raw events)Kerberos TGT request / pre-auth failure: spraying against a DC
Linuxsshd failurerules 5716, 5760 (level 5); rule 5710 non-existent user (level 5)single failures
Linuxsshd burstrules 5712, 5720, 5763 (level 10); rule 5758 max attempts exceeded (level 8)composite brute-force rules
Linuxsshd successrule 5715 (level 3)Accepted password / publickey
Linuxsudorule 5402 to root (level 3), rule 5401 failed (level 5), rule 5403 first time for user (level 4)privilege use
LinuxPAMrule 5503 login failed (level 5), rule 5551 multiple failures (level 10)console / other PAM services
Linuxaccount changesrule 5902 new user (level 8), rule 5904 user information changed (level 8)useradd / usermod

Procedure

  1. List all auth events for the user over 7 days (search_security_events(query="<user>")), and aggregate by source IP and host (get_alerts_aggregated).
  2. Establish baseline: usual source IPs, hosts, hours, logon types.
  3. Test each hypothesis below; record which are supported.
  4. Determine scope: every host the account touched after the suspected compromise time.

Hypotheses and indicators

PatternIndicatorsATT&CK
Brute force → successrule 60204 or rules 5712, 5763 then rule 60106 or rule 5715 from the same sourceT1110 → T1078
Password sprayingone source, many users, few attempts eachT1110.003
Impossible travelsuccessful logons from locations whose distance/time implies > ~900 km/hT1078
New source / off-hourssuccess from never-seen IP/ASN or outside baseline hoursT1078
Privilege escalationrule 67028 for a non-admin, group adds (rules 60141, 60144, 60154), rule 5402 by an unusual userT1078.002/.003, T1098
Lateral movementsame account, new hosts in short time; logon type 3/10 chains; SSH hopsT1021 (.001 RDP, .002 SMB, .004 SSH)
Persistence via accountnew account created by the suspect account (rules 60109, 5902), SSH key added (FIM on authorized_keys, see wazuh-fim-investigation)T1136, T1098.004

Verdict

  • Compromised — success from attacker-controlled source, or malicious actions by the account. Confidence ≥ 0.8.
  • Targeted, not compromised — failures only, no success. Recommend blocking the source, not disabling the user.
  • Inconclusive — anomalies without malicious actions; recommend user verification.

Recommend disable_user (proposed by response-planner) only with evidence of successful malicious use. Service accounts and break-glass accounts: flag the business impact explicitly; prefer blocking the source or isolating the host first.

Output

  • add_entities (user as victim; source IPs as attacker; hosts touched).
  • link_mitre for supported techniques.
  • update_case severity/confidence.
  • add_finding titled Identity assessment: <user> with baseline, hypotheses table (supported / not supported + evidence), hosts in scope, verdict, recommended containment. standard_refs: NIST-800-61r3, CIS-v8.1:5 (Account Management), CIS-v8.1:6 (Access Control Management).

Signals

GitHub stars
57
Forks
16
Last commit
Sep 2026
Advanced
Item type
skill
Key
identity-compromise
Source
github.com/gensecaihq/wazuh-autopilot