Add detector and event log to watch for Event Log Service stop/start as an indicator or event log tampering with eventlogedit
This commit is contained in:
1087
DeepBlue.ps1
1087
DeepBlue.ps1
File diff suppressed because it is too large
Load Diff
BIN
evtx/disablestop-eventlog.evtx
Normal file
BIN
evtx/disablestop-eventlog.evtx
Normal file
Binary file not shown.
Reference in New Issue
Block a user