Replies: 1 comment 1 reply
-
@mischw Thanks for the suggestion! Sure we can add that in there. |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
I came across a set of evtx files where a logon in the security log (ID 4624) was already deleted (brute force flooded the log) but I could still find it in other places like
Microsoft-Windows-TerminalServices-LocalSessionManager
with an corresponding event ID 21 (RDP). Hayabusa did not find a logon when usinglogon-summary
. Are there plans to have it look at some of the other IDs too, like the mentioned 21, in case the 4624 have been flooded out?Beta Was this translation helpful? Give feedback.
All reactions