Updated detected events

This commit is contained in:
Eric Conrad
2019-05-03 12:21:17 -03:00
committed by GitHub
parent 712b25e9f4
commit e3cb0142c6

View File

@ -96,8 +96,11 @@ See 'Logging setup' section below for how to configure these logs
* Suspicious service creation
* Service creation errors
* Stopping/starting the Windows Event Log service (potential event log manipulation)
* Mimikatz
* `lsadump::sam`
* `token::elevate`
* EMET & Applocker Blocks
* Sensitive Privilege Use (Mimikatz)
...and more