palantir / windows-event-forwarding

A repository for using windows event forwarding for incident detection and response
Other
1.22k stars 267 forks source link

Add WEF Subscriptions for Exploit Guard ASR #7

Closed cryps1s closed 7 years ago

cryps1s commented 7 years ago

Add WEF Subscription for Exploit Guard ASR.

EventIDs:

Reference: https://docs.microsoft.com/en-us/windows/threat-protection/windows-defender-exploit-guard/attack-surface-reduction-exploit-guard

cryps1s commented 7 years ago

Closing as duplicate