You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository has been archived by the owner on Nov 1, 2023. It is now read-only.
Something you might want to add or note about enabling "Advanced Audit Configuration" via gpo and what events at a min you should turn on. Or don't need based on what sysmon pulls.
The only thing I worry about is if you had an issue with sysmon and you had no "Advanced Audit Configuration" might be hard to find issues.
Noticed this in my testing since I did not apply my normal gpo for configuring event logging. (Did want to add anything that would conflict with LME) Was looking for normal user login events, and they were missing.
The text was updated successfully, but these errors were encountered:
I would expect using the audit settings on the same page under "Appendix A - Minimum recommended minimum audit policy" would get you close to having the relevant event logged:
Something you might want to add or note about enabling "Advanced Audit Configuration" via gpo and what events at a min you should turn on. Or don't need based on what sysmon pulls.
The only thing I worry about is if you had an issue with sysmon and you had no "Advanced Audit Configuration" might be hard to find issues.
Noticed this in my testing since I did not apply my normal gpo for configuring event logging. (Did want to add anything that would conflict with LME) Was looking for normal user login events, and they were missing.
The text was updated successfully, but these errors were encountered: