Title
#windows
defensivedepth

defensivedepth

03/23/2021, 1:34 PM
In your poc, is sysmon still outputting events to the eventlog? Your poc just allows us to more easily manipulate the sysmon data without having to use the
windows_events
table to ship the sysmon logs?
manu

manu

03/23/2021, 6:09 PM
yes sysmon still outputs it's log via it's own trace session. we create a new trace session to receive the events and fwd accordingly. If you notice there are 2 trace sessions, one that we create from event publisher.
6:25 PM
@defensivedepth yeah.
windows_events
being generic over diff channels and sources can't be projected generically. The data manipulation and types of queries that one create with such tables at endpoint itself opens a new set of opportunity.