Data Source: Windows Event Log Security 5441

Description

Logs Windows Filtering Platform filters that were present when the Base Filtering Engine started, including provider, filter, layer, conditions, and filter action metadata.

Details

Property Value
Source XmlWinEventLog:Security
Sourcetype XmlWinEventLog
Separator EventCode
Name ▲▼ Technique ▲▼ Type ▲▼
Windows EDRSilencer Custom Outbound Filter Added Disable or Modify Tools TTP

Supported Apps

Event Fields

+ Fields
  <span class="pill kill-chain">_time</span>
  
</div>

Required Output Fields

  • dest

Source: GitHub | Version: 1