Skip to content

Latest commit

 

History

History
35 lines (32 loc) · 2.55 KB

README.md

File metadata and controls

35 lines (32 loc) · 2.55 KB

Windows Advanced Audit Policy Map

Purpose

The first purpose of this project is to establish an exhaustive map of the correspondence between Windows advanced audit policy settings and event ids.
I then added the estimated volume of each policy settings if enabled.
I also marked audit policy settings recommended by ANSSI to be enabled.
This project is based on the documentation for Windows 10/11 and Windows Server >= 2016

Display the PDF version

Contribution

If you have ideas to improve this project, contributions are of course welcome <3

Documentation

ANSSI Guide
Microsoft Documentation