-
Notifications
You must be signed in to change notification settings - Fork 600
[Security Content] Windows Setup Guides - WinEventLog & Sysmon #5162
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
Nice work! Couple of thoughts.
|
@terrancedejesus Oops, they were supposed to be in the |
|
||
To build an efficient and production-ready configuration, we strongly recommend exploring these community resources: | ||
- https://github.com/trustedsec/SysmonCommunityGuide | ||
- https://github.com/olafhartong/sysmon-modular |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
👍
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I think we need to update https://github.com/elastic/detection-rules/blob/main/docs/docset.yml as well. @Mpdreamz can you confirm?
@Mpdreamz can you take a look at @Mikaayenson's comment? Thanks! |
Issues
Resolves https://github.com/elastic/ia-trade-team/issues/681
Summary
This PR adds setup guides to the repo’s
docs
folder, covering all Windows Event Logs and Sysmon events currently used in the ruleset.Built upon the work I did at #4501
Tips for reviewers
You can render the markdown files by clicking here: