1104(S) The security log is now full. | Microsoft Learn
Threat Hunting Using Windows Security Log - Security Investigation
Solved Event Properties - Event 4798, Microsoft Windows | Chegg.com
Active Directory Enumeration detected by Microsoft Security solutions | by Derk van der Woude | Medium
4798(S) A user's local group membership was enumerated. | Microsoft Learn
BloodHound Inner Workings & Limitations – Part 1: User Rights Enumeration Through SAMR & GPOLocalGroup – Compass Security Blog
SIEM - Security information and event management — Zercurity 1.6.0 (41f38f0) documentation
Event ID 4688: What Is It & How to Enable It - Windows Report
What Is & How to Track a Windows Audit Failure in 2023 | Newsletter software, Software deals, Content curation
Samir on Twitter: "the cool thing about those 2 newly introducted MS security eventid 4799, 4798 is that they will capture any local group/user discovery attempts even if done via winapis, below