palantir / windows-event-forwarding

A repository for using windows event forwarding for incident detection and response
Other
1.23k stars 268 forks source link

Fr/wef subscription table #20

Closed cryps1s closed 6 years ago

cryps1s commented 6 years ago

Added a WEF event mappings table. Maps an audit policy -> event ID -> subscription -> channel. Also includes whether or not the event is expected to be logged on DCs, Servers, and Workstations.