palantir / windows-event-forwarding

A repository for using windows event forwarding for incident detection and response
Other
1.23k stars 268 forks source link

EventID 4648 not included #36

Closed patrickg2525 closed 5 years ago

patrickg2525 commented 5 years ago

May want to included EventID 4648 in Authentication subscription, per V-43712, which is in Active Directory Domain Security STIG

Sorry - Never mind... it's covered in Explicit-Credentials subscription