drop security evtx csv · detect object access audit subcategory disabling · identify file system registry and sam auditing gaps · surface what file access was made invisible · runs locally
security evtx csv
drop security evtx csv (multi-file)
or click
4719 object-access subcategories · 4907 sacl strip · 4656 sensitive handles before disable
drop security evtx csv exports