EricZimmerman / evtx

C# based evtx parser with lots of extras
MIT License
280 stars 59 forks source link

Windows Security Center State Changed Map #237

Closed reece394 closed 5 months ago

reece394 commented 5 months ago

Description

I read an interesting post on SANS here and noticed the Event Log mentioned wasn't mapped yet hence the pull request.

Added a map file for Event ID 15 which is triggered when the Security Center state is changed.

Checklist:

Please replace every instance of [ ] with [X] OR click on the checkboxes after you submit your PR

Thank you for your submission and for contributing to the DFIR community!