gravwell / kits

A collection of open source Gravwell kits
BSD 2-Clause "Simplified" License
3 stars 15 forks source link

New Kit: Windows #165

Open kris-watts-gravwell opened 3 months ago

kris-watts-gravwell commented 3 months ago

General issue for tracking a generic windows kit.

Helpful links

https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/ https://www.xplg.com/windows-server-security-events-list/ https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/plan/appendix-l--events-to-monitor

Query library stuff

Dashboards

Playbook

Resources

Next iteration

keith-smiley-gravwell commented 1 month ago

Update...

keith-smiley-gravwell commented 1 month ago

Added a few more dashboards, playbooks