Hi All,
We've had MSFT Threat running over 30 days now. 2 virtual VMs, one running console the other gateway. The gateway has a mirrored network port back to 1 of 2 virtual domain controllers. I did a packet capture on the mirrored port and
traffic is coming through from the domain controller. I see users, memberships and password info but I'm missing a lot of other stuff. What could be causing this? Thank you.
Some things I can't see are:
User Activity - No activity
Computers recently logged onto by this user - None
Recently accessed resources - None