<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Audit on Anything About IT</title><link>https://www.verboon.info/tags/audit/</link><description>Recent content in Audit on Anything About IT</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 26 Sep 2021 20:15:06 +0000</lastBuildDate><atom:link href="https://www.verboon.info/tags/audit/index.xml" rel="self" type="application/rss+xml"/><item><title>Detect Audit Policy Modifications with Microsoft 365 Defender</title><link>https://www.verboon.info/2021/09/detect-audit-policy-modifications-with-microsoft-365-defender/</link><pubDate>Sun, 26 Sep 2021 20:15:06 +0000</pubDate><guid>https://www.verboon.info/2021/09/detect-audit-policy-modifications-with-microsoft-365-defender/</guid><description>&lt;p&gt;Hello there,&lt;/p&gt;
&lt;p&gt;In today&amp;rsquo;s blog post I want to share with you an advanced hunting query to detect audit policy modifications using Microsoft Defender 365 advanced hunting. Following the MITRE ATT&amp;amp;CK framework this would be &lt;a href="https://attack.mitre.org/techniques/T1484/001/"&gt;T1484.001 Domain Policy Modification: Group Policy Modification&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Microsoft Defender for Endpoint can help us detect audit policy modifications by running the following query:&lt;/p&gt;
&lt;p&gt;
 &lt;img src="092621_1955_DetectAudit1.png" alt=""&gt;

&lt;/p&gt;
&lt;p&gt;Detailed information about the audit policy changes is displayed in the AdditionalFields data. Now all we need to do is to translate these values into human readable data.&lt;/p&gt;</description></item><item><title>How to create your Defender ATP Admin Audit Log Dashboard</title><link>https://www.verboon.info/2020/04/how-to-create-your-defender-atp-admin-audit-log-dashboard/</link><pubDate>Sat, 11 Apr 2020 20:11:07 +0000</pubDate><guid>https://www.verboon.info/2020/04/how-to-create-your-defender-atp-admin-audit-log-dashboard/</guid><description>&lt;p&gt;Hello everyone,&lt;/p&gt;
&lt;p&gt;In today&amp;rsquo;s blogpost I will walk you through the process of creating an admin audit log dashboard for Defender Advanced Threat Protection. During my past customer engagements, I was often asked if there is a way to show device actions taken by Defender ATP admins. The answer is yes, this is possible. First the information is available through the Defender ATP API, second the information is also stored within the Windows event log of the device itself.&lt;/p&gt;</description></item></channel></rss>