Project Sauron Versions Save

Tools to create a Native Windows Audit Collection Platform. Active Directory example provided

1.3

7 years ago

Whats New

  • Added Group Policy container monitoring to Object Management field.
  • Preview Custom Views for Domain Members

Whats Changed

  • Updated Shortname for Account Logon from DC_AL_CVS/CVF to DC_AL_LS/LF
  • Basic typos and cleanup

Note. You need to grab all the files below including Source Code.zip which has the .PS1 files.

1.2

7 years ago

Whats New

  • Added a "-ReadExistingEvents" switch to the Create-Subscriptions script to flag wether to send existing events when a subscription is applied to a server.
  • Added the Weak LDAP Binds channels.

Whats Changed

  • Renamed "Credential Validation" back to "Account Logon" to match the audit subsystem category name.
  • Separated "Account Logon\Credential Validation Success" into separate containers for Credential Validation, Kerberos AS and Kerberos TGS.
  • Added Validation Failure Kerberos TGS.
  • Typo in one of the Logon Channel names from "Serivice" to "Service"

1.1

7 years ago

Whats new in 1.1

  • Split the preparation of event channels and subscription generation into 2 separate scripts.
  • Moved pre-canned files to be available in the release details instead of the repository.