What's Monitored in Beta 1
- File locations where software can establish persistence on the host
- Sensitive services such as ssh and file sharing configuration files
- All events are designed to be tightly interlinked and enriched with the primary cmdReporter telemetry data stream
Event Format
- In Beta 1, the HID logs will retain their FILE_EVENT format.
- In a later Beta, the format of HID events will change. We will communicate timelines once available.