Files
DCO-SOGs/3 DC/Agents/1) DCO_GPO_CUSTOMER.md

665 B

sysmon

sysmon config

inputs for splunk

splunk universal forwarder

elastic agent

Event Logs

  • process tracking #enables CMD logging
  • enable wmi
  • enable powershell remoting
  • Audit Policy