You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

1.1 KiB

1CategoryURL
2Andrea Fortunahttps://www.andreafortuna.org/2019/06/12/windows-security-event-logs-my-own-cheatsheet/
3Mike Lombardihttps://www.sans.org/cyber-security-summit/archives/file/summit-archive-1511904841.pdf
4NSAhttps://github.com/nsacyber/Event-Forwarding-Guidance/tree/master/Events
5Microsoft ADhttps://docs.microsoft.com/en-us/windows-server/identity/ad-ds/plan/appendix-l--events-to-monitor
6SANS Forensics Guidancehttps://isc.sans.edu/forums/diary/Windows+Events+log+for+IRForensics+Part+1/21493/
7Michael Goughhttps://www.malwarearchaeology.com/cheat-sheets
8Hunters Forgehttps://github.com/hunters-forge/OSSEM/tree/master/attack_data_sources
9JP-CERThttps://www.jpcert.or.jp/english/pub/sr/20170612ac-ir_research_en.pdf
10ASDhttps://www.cyber.gov.au/acsc/view-all-content/publications/windows-event-logging-and-forwarding
11Splunk UBAhttps://docs.splunk.com/Documentation/UBA/latest/GetDataIn/WindowsEvents
12Sygnia Golden SAMLhttps://www.sygnia.co/golden-saml-advisory
13JSCU-NLhttps://github.com/JSCU-NL/logging-essentials
14Michel de CREVOISIERhttps://github.com/mdecrevoisier/EVTX-to-MITRE-Attack