EricZimmerman / evtx

C# based evtx parser with lots of extras
MIT License
272 stars 59 forks source link

Create System_Microsoft-Windows-GroupPolicy_1130.map #183

Closed HSICFA closed 2 years ago

HSICFA commented 2 years ago

New map for System event ID 1130 GPO Script Failure. Multiple payload columns mapped.

Description

Please include a summary of the change and (if applicable) which issue is fixed.

Checklist:

Please replace every instance of [ ] with [X]

Thank you for your submission and for contributing to the DFIR community!

AndrewRathbun commented 2 years ago

Looks great, thank you!