Skip to content
This repository has been archived by the owner on Nov 1, 2023. It is now read-only.

[GPO settings on what to log] #56

Closed
ehosmer opened this issue Jan 31, 2020 · 2 comments
Closed

[GPO settings on what to log] #56

ehosmer opened this issue Jan 31, 2020 · 2 comments
Labels
enhancement New feature or request

Comments

@ehosmer
Copy link

ehosmer commented Jan 31, 2020

Something you might want to add or note about enabling "Advanced Audit Configuration" via gpo and what events at a min you should turn on. Or don't need based on what sysmon pulls.

The only thing I worry about is if you had an issue with sysmon and you had no "Advanced Audit Configuration" might be hard to find issues.

Noticed this in my testing since I did not apply my normal gpo for configuring event logging. (Did want to add anything that would conflict with LME) Was looking for normal user login events, and they were missing.

@ehosmer ehosmer added the enhancement New feature or request label Jan 31, 2020
@1n6w3coza
Copy link

I have noticed a lot of the forwarded events in Chapter 1 Files > lme_wec_config.xml appear to come from here:

https://docs.microsoft.com/en-us/windows/security/threat-protection/use-windows-event-forwarding-to-assist-in-intrusion-detection#appendix-e--annotated-baseline-subscription-event-query

I would expect using the audit settings on the same page under "Appendix A - Minimum recommended minimum audit policy" would get you close to having the relevant event logged:

https://docs.microsoft.com/en-us/windows/security/threat-protection/use-windows-event-forwarding-to-assist-in-intrusion-detection#appendix-a---minimum-recommended-minimum-audit-policy

@duncan-ncc
Copy link
Contributor

Closed due to project archive

@duncan-ncc duncan-ncc closed this as not planned Won't fix, can't repro, duplicate, stale Apr 3, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

3 participants