nsacyber/Event-Forwarding-Guidance
Configuration guidance for implementing collection of security relevant Windows Event Log events by using Windows Event Forwarding. #nsacyber
PowerShellNOASSERTION
Issues
- 0
AppLocker event descriptions inaccurate
#19 opened by IAmAnthem - 0
Subscription Organization
#17 opened by CliffordRichmond - 3
- 0
- 0
Spelling error on Provider "Microsoft-Windows-CertificateServicesClient-Lifecycle-System"
#14 opened by hcs0 - 3
"Microsoft-Windows-CertificationAuthority" is not the event log - it is source of events from Application log
#9 opened by vburov - 4
Incorrect event id specified for "CA Permissions Corrupted or Missing" in section "Certificate Services" of "Windows Event Monitoring Guidance\Recommended Events to Collect" document
#10 opened by vburov - 2
Getting 404 on IAD site
#8 opened by gregs5 - 1
Why not just level 3?
#1 opened by ciberesponce - 0
XPath queries for WiFi connection encryption and authentication status events have right brackets in wrong spots
#3 opened by iadgovuser1