Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add event logs for Microsoft-Windows-Windows Firewall With Advanced Security provider #39

Open
Cyb3rPandaH opened this issue Jun 28, 2022 · 0 comments
Assignees
Labels
documentation Improvements or additions to documentation help wanted Extra attention is needed

Comments

@Cyb3rPandaH
Copy link
Contributor

Some relationships in OSSEM-DM use events such as 2004 (Firewall rule added), 2006 (Firewall rule deleted)

Reference: https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-firewall/windows-firewall-with-advanced-security

@Cyb3rPandaH Cyb3rPandaH added documentation Improvements or additions to documentation help wanted Extra attention is needed labels Jun 28, 2022
@Cyb3rPandaH Cyb3rPandaH self-assigned this Jun 28, 2022
Cyb3rPandaH added a commit to OTRF/OSSEM-DM that referenced this issue Jun 28, 2022
…Security events

- log_source: Microsoft-Windows-Windows Firewall With Advanced Security
- issue created in OSSEM-DD: Creation of dictionaries required - OTRF/OSSEM-DD#39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
documentation Improvements or additions to documentation help wanted Extra attention is needed
Projects
None yet
Development

No branches or pull requests

1 participant