v.1.3.0
Changelog
Changed
- Updated terraform lab deployment script to provision whitelisting files
- Updated documentation and wiki
- Updated workbook queries to exclude whitelisted Sysmon events
Added
- DNS whitelisting
- File access whitelist
- File create whitelist
- Image load whitelist
- Network whitelist
- Pipe whitelist
- Process access whitelist
- Process create whitelist
- Registry whitelist
- Remote thread whitelist
- Whitelisting macro functions