palantir / windows-event-forwarding

A repository for using windows event forwarding for incident detection and response
Other
1.22k stars 268 forks source link

Add subscriptions for Device Guard #3

Closed cryps1s closed 6 years ago

cryps1s commented 7 years ago

Add WEF subscription for Device Guard operational logs.

cryps1s commented 6 years ago

Microsoft-Windows-DeviceGuard/Operational, all events

cryps1s commented 6 years ago

Handled via branch: https://github.com/palantir/windows-event-forwarding/pull/13