EricZimmerman / evtx

C# based evtx parser with lots of extras
MIT License
280 stars 59 forks source link

Update Sysmon events with User fields #171

Closed AndrewRathbun closed 3 years ago

AndrewRathbun commented 3 years ago

https://twitter.com/Cyb3rWard0g/status/1453123054243024897/photo/1

Description

Please include a summary of the change and (if applicable) which issue is fixed.

Checklist:

Please replace every instance of [ ] with [X]

Thank you for your submission and for contributing to the DFIR community!

AndrewRathbun commented 3 years ago

https://github.com/microsoft/MSTIC-Sysmon/blob/f1477c0512b0747c1455283069c21faec758e29d/windows/schemas/sysmonv13.30_4.81.xml#L61