Skip to content

SWELF Testing

Ceramicskate0 edited this page Oct 3, 2018 · 10 revisions

SWELF Testing:


Currently testing on windows 10 with configured Device Guard/app whitelisting, UAC, HIDS, locked down powershell configuration, EMET, and AV. App is designed to be run as a scheduled task for now. Im taking recommendations via issues just label as enhancements for design, UI, source code, and features.

New Features:

  • Currently testing central config option in app to use ANY web server in HTTP as location to store app config and have app read it making Enterprise config easier than GPO of scheduled task.

Log Collection Platforms or SIEMs being used in testing SWELF:

- Kibana/ELK (on Security Onion)

- Splunk 

- Graylog

- Kiwi Syslog

APP Security:

Security Testing and Security Improvements being pushed in 0.4.0.0 release.

Clone this wiki locally