piExpr

Results 2 issues of piExpr

Started logging events and modifying config. All these events are Sysmon event IDs. Is there proper configuration to use to include Windows actual Event IDs instead of Sysmon? My use...

Working on collecting LSA audit and operational events on Windows OS by using AMA and SysMon. I show several LSA control HKEY in configuration but how do I know if...