Closed JohnLaTwC closed 3 years ago
Great.
I could add these commands mentioned in the comments in the batch installer.
/// This function will optionally log messages to the eventlog
/// To enable viewing in the eventlog run this command to create the message IDs for Raccine
/// As admin:
/// eventcreate.exe / L Application / T Information / id 1 / so Raccine / d "Raccine event message"
/// eventcreate.exe / L Application / T Information / id 2 / so Raccine / d "Raccine event message"
///
/// To configure event logging, set this registry key to 2
/// REG.EXE ADD HKCU\Software\Raccine / v Logging / t REG_DWORD / d 2
Adds optional Windows Event logging to Raccine. This allows collection of Raccine events to a SIEM and sigma rules :)