sans-blue-team / DeepBlueCLI

GNU General Public License v3.0
2.19k stars 355 forks source link

Add Event ID 1102 #18

Closed Shady-2012 closed 4 years ago

Shady-2012 commented 4 years ago

Hello Eric,

So we were practicing in SANS504 with your DeepBlueCLI script and when Chris cleared all the logs then ran the script again we didn't see the event ID "1102" - The Audit Log Was Cleared". However, we really believe this event should be add to the script :).

Thank you,

joswr1ght commented 4 years ago

Great idea! Commited.