Forum Discussion

Joe Stern's avatar
Joe Stern
Iron Contributor
Aug 12, 2020

ATP Query to find an event ID in the security log

I've applied the August 2020 update to my domain controllers, and now I need to watch for event ID 5829 in the system log.    This seems like a good candidate for Advanced Hunting. I think the quer...

Resources