Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,10 @@ Releases are tagged `vX.Y.Z` and published with a zip and a SHA256 checksum.

## [Unreleased]

### Changed

- 馃Л **One checklist for fitting the kit to your environment.** The Safety page opens with what to settle before rolling out (your selection, a pilot, SIEM cost, sensitive logs, Group Policy precedence, change process, rollback, your own obligations), linked from the README and Getting started.

## [2.2.1] - 2026-09-24

More of the logs that matter for lateral movement, and one fix, from a cross-check against other published Windows auditing baselines: SMB server guest logons and security events, the two RDP logs written before a session starts, and Group Policy-forced "do not overwrite" retention reported instead of fought.
Expand Down
8 changes: 7 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -98,7 +98,13 @@ The kit never touches the settings that can hang or lock out a host
(`CrashOnAuditFail`, "do not overwrite" retention, global object access
auditing, blanket SACLs) and never reboots, restarts services or shrinks
logs. Heavy settings carry a risk note the builder shows before you select
them. Use at your own risk.
them.

It's a starting point: fit it to your own infrastructure (selection, pilot,
SIEM cost, Group Policy, change process) before rolling out, using the
checklist in
[Safety & FAQ](https://spydisec.github.io/WinLogKit/safety/#fit-it-to-your-environment-first).
Provided as is, without warranty; use at your own risk.

## Contributing

Expand Down
7 changes: 5 additions & 2 deletions docs/getting-started.md
Original file line number Diff line number Diff line change
Expand Up @@ -90,8 +90,11 @@ pipeline or an Intune/RMM check as-is.
decisions; [Coverage](mapping.md) shows what they add. To build a
selection from scratch instead, run `.\New-LoggingBaseline.ps1`
([Baselines](baselines.md#building-your-own)).
3. **Roll it out** with Intune or Group Policy ([Deploy](deployment.md)).
4. **Collect it centrally**, if you use Windows Event Forwarding
3. **Fit it to your environment**: SIEM cost, Group Policy, change process
and your own obligations
([checklist](safety.md#fit-it-to-your-environment-first)).
4. **Roll it out** with Intune or Group Policy ([Deploy](deployment.md)).
5. **Collect it centrally**, if you use Windows Event Forwarding
([Collect](wec.md)).

## Where things land
Expand Down
37 changes: 37 additions & 0 deletions docs/safety.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,43 @@ The settings that can genuinely hurt a Windows machine, how the kit avoids
every one of them, and which of the *safe* settings still cost real disk
and money.

## Fit it to your environment first

WinLogKit is a sourced starting point, not a finished policy for your
estate. Before rolling it out:

- **Pick, then adjust, a selection.** Start from the role preset, copy it,
and turn settings on or off for your hosts
([Baselines](baselines.md#role-presets)). Keep your copy in version
control.
- **Pilot it.** Run `-WhatIf`, apply on a test host that mirrors
production, and watch it for at least a week: event volume, disk (the
[storage check](#disk-space)) and anything your monitoring or backup
agents do differently.
- **Check the cost downstream.** Every event you turn on is ingested,
stored and licensed by your SIEM. Agree ingest and retention with whoever
runs and pays for it.
- **Treat the logs as sensitive.** Command-line capture and PowerShell
logging can record credentials typed on a command line. Restrict who can
read these logs and where they're forwarded.
- **Know what else sets policy.** On domain-joined hosts, Group Policy
replaces local settings at the next refresh: deliver fleet-wide through
[Group Policy or Intune](deployment.md), and check that nothing else
(other baselines, security tools) sets conflicting audit policy or log
retention.
- **Follow your change process.** The kit never reboots or restarts
services, but it does change audit policy and log settings. Schedule it
like any other configuration change, especially on domain controllers
and certificate authorities.
- **Verify, and keep the way back.** Run `Test-LoggingBaseline.ps1` after
every change. The first real run saves a rollback copy, and `-Rollback`
restores it.
- **Check your obligations.** Retention periods, privacy and sector rules
differ by organisation and country; the kit doesn't decide them for you.

WinLogKit is provided as is, without warranty, under the
[MIT License](https://github.com/spydisec/WinLogKit/blob/main/LICENSE).

## What the kit will never do

Windows auditing has settings that can hang, halt or lock out a server. The
Expand Down
Loading