audit mode - remote event logs? #956
Replies: 6 comments 30 replies
-
|
Hi, |
Beta Was this translation helpful? Give feedback.
-
Beta Was this translation helpful? Give feedback.
-
Beta Was this translation helpful? Give feedback.
-
|
Using the app gives me more and more ideas on how to improve things to make it even better! :-)
More ideas might come soon :-) |
Beta Was this translation helpful? Give feedback.
-
|
One more suggestion. Yesterday I wanted to create a new supplemental policy but forgot to change the policy name. So it overwrote an existing xml policy without asking for confirmation. A small 'are you sure you want to overwrite the existing file' would be a lifesaver here :-) |
Beta Was this translation helpful? Give feedback.
-
|
Hi @BelOrta-TDP They will be available in AppControl Manager v2.0.68.0 |
Beta Was this translation helpful? Give feedback.







Uh oh!
There was an error while loading. Please reload this page.
-
I read https://github.com/HotCakeX/Harden-Windows-Security/wiki/How-To-Generate-Audit-Logs-via-App-Control-Policies, where you say that "The logs can also be collected in bulk from thousands of systems by the Microsoft Defender for Endpoint Advanced Hunting". We don't use Defender... Is there another way to collect these logs? I was thinking about logforwarding to a central log collector, and then run your tool there, but that feels a bit messy. Maybe there is a way to make your tool scan remote event logs (for a list of endpoints) ?
Beta Was this translation helpful? Give feedback.
All reactions