CISO2CISO.COM & CYBER SECURITY GROUP

CISO2CISO Notepad Series SOC Technical Documents TOP Featured Post Windows Cybersecurity

Windows Event Security Log Analysis

ContentsIntroduction ……………………………………………………………………………………………………………………………….. 2Event Log Format ………………………………………………………………………………………………………………………… 3Account Management Events ………………………………………………………………………………………………………. 4Account Logon and Logon Events ………………………………………………………………………………………………….. 5Access to Shared Objects …………………………………………………………………………………………………………… 11Scheduled Task Logging ……………………………………………………………………………………………………………… 12Object...