palantir / windows-event-forwarding

A repository for using windows event forwarding for incident detection and response
Other
1.22k stars 268 forks source link

Adding ADFS, Duo, DG, EG, Office, WMI #13

Closed clong closed 6 years ago

clong commented 6 years ago

This PR Addresses the following issues:

1 - Add subscriptions for ADFS

2 - Add subscriptions for Duo

3 - Add subscriptions for Device Guard

5 - Add subscriptions for office alerts.

6 - Add WEF subscription for TPM-WMI

8 - Add WEF Subscriptions for Exploit Guard

11 - Don't hide Microsoft signed entries in AutorunsToWinEventLog

Additional changes: