palantir / windows-event-forwarding

A repository for using windows event forwarding for incident detection and response
Other
1.22k stars 268 forks source link

Added query 4 and 5 #42

Closed mdecrevoisier closed 2 years ago

mdecrevoisier commented 4 years ago

Query 4: replication changes can be detected to catch DCsync attack Query 5: all directory service logs. Use full for security and also detect LDAP queries instead of LDAPS