
Documentation and scripts to properly enable Windows event logs.
This is yet another guide on properly configuring and monitoring Windows event logs with an emphasis on logging for sigma rules.
This is a work in progress, so check back please periodically for updates.
Zach Mathis (@yamatosecurity). As I do more research and testing, I plan on periodically updating this as there is much room for improvement (both in the documentation as well as in creating more detection rules.) PRs are welcome and will gladly add you as a contributor. If you find any errors in this documentation, please let me know and I will fix them as soon as possible.
If you find any of this useful, please give a star on GitHub as it will probably help motivate me to continue updating this.
Most of the information comes from Microsoft's Advanced security auditing FAQ, sigma rules, the ACSC Event Logging Guide and my own research/testing. I would like to thank the sigma community in particular for making threat detection open source and free for the benefit of all of the defenders out there.