OTRF / OSSEM

Open Source Security Events Metadata (OSSEM)
MIT License
1.22k stars 212 forks source link

Windows Security logs, fields mismatch for Object Access #92

Open nicolasreich opened 3 years ago

nicolasreich commented 3 years ago

Hello, the In some Windows Security logs concerning Object Access, the field (e.g. 4656) AccessList is translated into user_privilege_list while for others it is object_access_list. Which one is right?

PS: Is opening issues on this repo the right procedure for issues like this? Is there something you would prefer?

Cyb3rWard0g commented 3 years ago

Hey @nicolasreich , yes thank you very much for sharing the feedback and this is the best way to report those mismatch. As I mentioned in a previous issue, we are reviewing those events and fixing a few of those inconsistencies from an endpoint perspective.