- Currently, Logins are captured via Domain Controllers using specific set of EventIDs.
- would it be possible, if we can gather the logs directly from the Linux Machines as all movement on the Linux machines is recorded on Logs.
- This means we would have to monitor Linux machines individually