Giter VIP home page Giter VIP logo

event-forwarding-guidance's Introduction

Event Forwarding Guidance

This repository hosts content for aiding administrators in collecting security relevant Windows event logs using Windows Event Forwarding (WEF). This repository is a companion to Spotting the Adversary with Windows Event Log Monitoring paper. The list of events in this repository are more up to date than those in the paper.

The repository contains:

  • Recommended Windows events to collect. Regardless of using WEF or a third party SIEM, the list of recommended events should be useful as a starting point for what to collect. The list of events in this repository are more up to date than those in the paper.
  • Scripts to create custom Event Log views and create WEF subscriptions.
  • WEF subscriptions in XML format.

Links

License

See LICENSE.

Disclaimer

See DISCLAIMER.

event-forwarding-guidance's People

Contributors

iadgovadmin avatar iadgovuser1 avatar iadgovuser13 avatar iadgovuser6 avatar iadgovuser8 avatar philkloose avatar ralish avatar vburov avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

event-forwarding-guidance's Issues

Prerequisite Audit Policy/Advanced Audit Policies

I apologize if this is not the proper avenue, but it was the only one I could recognize. Is it listed anywhere what the baseline audit/advanced audit policy settings/GPOs that need to be in place in order for all these event IDs to exist in the first place (ex. Microsoft Recommended baseline, or secure audit policy settings, or perhaps audit policy settings specific to this repo. -Cliff, CISSP

Event with ID = 7045 from System log has incorrect source

Event with ID = 7045 from System log has incorrect source in section "Software and Service Installation" of "Recommended Events to Collect" document.
Correct source for this event is "Service Control Manager":

  • Provider
    [ Name] Service Control Manager
    [ Guid] {555908d1-a6d7-4695-8e1e-26931d2012f4}
    [ EventSourceName] Service Control Manager
  • EventID 7045
    Also, I create pull request #12 to modify "RecommendedEvents.json" file

Why not just level 3?

Level 3 gives you the warnings--level 2 will be very noisy. If you do level 2, it would require additional analytics after collection (i.e. at the WEC) to make use of them...

Thoughts?

Subscription Organization

I emailed [email protected] for more specific contact information Nov. 19th but have heard nothing back yet...

I have connectivity between sources and collector, and have had events come in for test subscriptions. My question/concern is how to most simply organize individual subscriptions, given the fact that event IDs are only unique to sources, and not logs. For example, is it the case that the particular event IDs recommended to be tracked in the Excel spreadsheet "are" unique for each log, or would I have to separate each subscription by event source to be sure I was not getting different events (one I care about, and others I don't want to forward) from the same log that happened to have the same event ID?

Getting 404 on IAD site

The report referenced in the README that sends one here:
https://www.iad.gov/iad/library/ia-guidance/security-configuration/applications/spotting-the-adversary-with-windows-event-log-monitoring.cfm

...results in a 404 if you click on the "GET FILE" icon. Is there another location for this report? Not sure if this is version 2, but I was able to d/l a version of the file from this URL:

https://www.iad.gov/iad/library/reports/spotting-the-adversary-with-windows-event-log-monitoring.cfm

AppLocker event descriptions inaccurate

8002,8003,8004 are not described correctly in the RecommendedEvents files.

https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/applocker/using-event-viewer-with-applocker

8002 - allowed to run
8003 - would be blocked if enforcement was on
8004 - was blocked

8006 Would be blocked if Enforcement On Microsoft-Windows-AppLocker/MSI and Script
8007 Was Blocked Warning Microsoft-Windows-AppLocker/MSI and Script

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.