chainsaw
chainsaw copied to clipboard
Security channel-based detections
Just a proof of concept for detecting some anomalies in event logs even if Sysmon is not deployed across the organization - but the audit policy is configured correctly.
LOL, didn't pay attention to the level attribute. fixed it