MDATP - how to? is it possible to:

Hi All,


Asking some potentially dumb questions & looking for guidance if these actions are possible:

  • Monitor for any changes in the Event Log settings - i.e. change of size, retention, file, etc for System/Security/Application/Powershell Event Logs
  • Monitor for any changes to the HOST/HOSTS file - could just use Folder Protection/Controlled Folder access?

I'm particularly interested if there is any way of monitoring for any changes to the Event Logs



@David Caddick 


Is there anything in particular that you want to monitor on the event logs?


All activities of an on boarded machine can be found on the timelines section on the MDATP portal for that particular machine