New Job-Role Training Path: Active Directory Penetration Tester! Learn More

ancostel

Earned a new badge!

Badge Icon

Log keeper

For completing the Windows Event Logs & Finding Evil module

2376

Users earned this badge

0.16%

Users have this badge

Completed on 26 Dec 2023

Windows Event Logs & Finding Evil

This module covers the exploration of Windows Event Logs and their significance in uncovering suspicious activities. Throughout the course, we delve into the anatomy of Windows Event Logs and highlight the logs that hold the most valuable information for investigations. The module also focuses on utilizing Sysmon and Event Logs for detecting and analyzing malicious behavior. Additionally, we delve into Event Tracing for Windows (ETW), explaining its architecture and components, and provide ETW-based detection examples. To streamline the analysis process, we introduce the powerful Get-WinEvent cmdlet.