Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Windows Security logs, Computer Account Management auditing fields mismatch between events #90

Open
nicolasreich opened this issue Oct 19, 2020 · 1 comment

Comments

@nicolasreich
Copy link
Contributor

nicolasreich commented Oct 19, 2020

In the Data Dictionary of Windows Security Event 4741, the field UserParameters is translated into target_host_user_paremeters (with a typo), and UserAccountControl into target_host_user_account_control. For Event 4742, the corresponding fields are translated into target_host_parameters and target_host_account_control, so with one user fewer. I haven't been able to find those defined in the CDM; what is the right standard field name?

@Cyb3rWard0g
Copy link
Collaborator

Hey @nicolasreich ! Thank you very much for going through the events standardization and providing feedback. We are still working on those and trying to create the right data entity for those and attributes. I will add that to the list of upcoming updates. I believe initially it was meant to be part of the Target Entity. That needs to be reviewed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants