Registry Auditing with ELSA Event 4657 ELSA parser Security Onion http://malwarearchaeology.squarespace.com/ http://malwarearchaeology.squarespace.com/logging/ http://giuoco.org/security/configure-file-and-registry-auditing-with-powershell/