You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Similar to the process tracker we should add a usn tracker.
The trouble with the usn journal is that it is very verbose so it's hard to interpret. Ideally we want to summarize the log to just relevant info ideally only Creation and deleting events. We need to be able to target by paths as well.
We need to also estimate the load on the system due to this. Ideally it is cheap enough to run always on all systems.
The text was updated successfully, but these errors were encountered:
Just to add to the conversation, imho we want file telemetry to include process context.
USN is great for forensics but not as high security value as other techniques.
Similar to the process tracker we should add a usn tracker.
The trouble with the usn journal is that it is very verbose so it's hard to interpret. Ideally we want to summarize the log to just relevant info ideally only Creation and deleting events. We need to be able to target by paths as well.
We need to also estimate the load on the system due to this. Ideally it is cheap enough to run always on all systems.
The text was updated successfully, but these errors were encountered: