Azure / SimuLand

Understand adversary tradecraft and improve detection strategies
MIT License
694 stars 79 forks source link

Update Windows Events Data Collection to Data Collection Rules (DCR) and XPath Queries #26

Closed Cyb3rWard0g closed 2 years ago

Cyb3rWard0g commented 2 years ago

A New Version of the Windows Security Events Connector?

According to Microsoft docs, the new Windows Security Events connector lets you stream security events from any Windows server (physical or virtual, on-premises or in any cloud) connected to your Azure Sentinel workspace. There are now two versions of this connector:

Other Windows Event Providers

We also need to use DCRs to handle the collection of events from other Windows event providers besides Microsoft-Windows-Security-Auditing

References: