Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

FIM System Tests: Windows EventID 4659 #642

Closed
Molter73 opened this issue Apr 3, 2020 · 0 comments · Fixed by #648
Closed

FIM System Tests: Windows EventID 4659 #642

Molter73 opened this issue Apr 3, 2020 · 0 comments · Fixed by #648
Assignees

Comments

@Molter73
Copy link
Contributor

Molter73 commented Apr 3, 2020

Related issue
wazuh/wazuh#4670

Description

Add a test for the deferred delete windows events (EventID 4659).

In order to detect this event, a Sending FIM event:... log message must be captured that has the event type deleted and does not have the audit field process_name to distinguish it from a regular delete generated by a Windows event with ID 4660.

Platforms

  • Windows
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

8 participants