Today I Learned about Auditpol, Sysmon, and Sysmon Configurations
Download MP3
What SimeonOnSecurity learned about and found interesting today
SimeonOnSecurity learned and discovered several interesting things today related to Windows security and event monitoring.
First, two new and updated repositories were identified. The Automate-Sysmon repository provides a solution for automating the installation, configuration, and management of Sysmon, a popular tool for monitoring and logging system activity on Windows systems. The Windows-Audit-Policy repository provides a solution for automating the configuration of Windows audit policies, which control the auditing of various security-related events on Windows systems.