Skip to content

Noticed Missing EID 9,4 & 10 for Microsoft-Windows-Ntfs#259

Merged
AndrewRathbun merged 9 commits into
EricZimmerman:masterfrom
vikas891:master
Apr 29, 2026
Merged

Noticed Missing EID 9,4 & 10 for Microsoft-Windows-Ntfs#259
AndrewRathbun merged 9 commits into
EricZimmerman:masterfrom
vikas891:master

Conversation

@vikas891

Copy link
Copy Markdown
Contributor

I've ran a few EVTX logs against these maps and verify that these are working.

Description

Please include a summary of the change and (if applicable) which issue is fixed.

Checklist:

Please replace every instance of [ ] with [X] OR click on the checkboxes after you submit your PR

  • [X ] I have ensured a Provider is listed for the new Map(s) being submitted
  • [X ] I have ensured the filename(s) of any new Map(s) being submitted follows the approved format, i.e. Channel-Name_Provider-Name_EventID.map. In summary, all spaces and special characters are replaced with a hyphen with an underscore separates Channel Name, Provider Name, and Event ID
  • [X ] I have tested and validated the new Map(s) work with my test data and achieve the desired output
  • [X ] I have provided example event data (# Example Event Data:) at the bottom of my Map(s), if possible
  • [X ] I have consulted the Guide/Template to ensure my Map(s) follow the same format

Thank you for your submission and for contributing to the DFIR community!

I've ran a few EVTX logs against these maps and verify that these are working.
@AndrewRathbun AndrewRathbun self-assigned this Apr 29, 2026
@AndrewRathbun AndrewRathbun added the enhancement New feature or request label Apr 29, 2026
@AndrewRathbun AndrewRathbun changed the title Noticed Missing EID 9,4 & 10 Noticed Missing EID 9,4 & 10 for Microsoft-Windows-Ntfs Apr 29, 2026
@AndrewRathbun
AndrewRathbun merged commit 1659e2f into EricZimmerman:master Apr 29, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants