JPCERTCC / LogonTracer

Investigate malicious Windows logon by visualizing and analyzing Windows event log
Other
2.7k stars 441 forks source link

Can we use LogonTracer in a large company? #53

Open Manoubi88 opened 5 years ago

Manoubi88 commented 5 years ago

Can we use LogonTracer to monitor logs in a company that generates 1 Gbt (300k event) evtx file per hour?

allamiro commented 4 years ago

You should start by testing it in a test environment before moving to production environment and report any issues you have here as for me I'm planning to test especially interested on how filtering works - meaning how can you filter specific event IDs and Fields using this