SA_ESS_Windows v6.0.0
| Date | Version | Author | [Type] Description |
|---|---|---|---|
| 2025-03-20 | 6.0.0 | Arnold | !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! [BREAKING] The action field doesn't have a "catch all" anymore based on the Audit keywords field, this is so the action field in the windows_signature_extended.csv will be used. !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! [ADD] Eventtypes for data access and account management, made a seperate eventtype for EventCode=4738 [ADD] New userAccountControl values and made it more clear if a Kerberos delegation is a constrained or unconstrained delegation. [ADD] Collection for AD user identities [ADD] Savedsearch to fill the ad_user_accounts collection with data from admon. [MOD] The windows_signature_extended.csv has a extra field "reason" for the authentication datamodel. In the future the signature field for authentication failure will only contain "Logon Failure" and the failure reason will be in the reason field. [MOD] Removed the eventtype "WindowsLogin_Explicit" from the Authentication datamodel. |