Microsoft eventlog mindmap provides a global view of most valuable and security related Windows Event logs, as well as their auditing capacities. It enables defenders to enhance visibility on monitored assets for different purposes:
Log collection (eg: into a SIEM)
Threat hunting
Forensic / DFIR
Troubleshooting
https://github.com/mdecrevoisier/Microsoft-eventlog-mindmap
Post #3342
1.11K
