SavitarX
Ctrlk
LinkedinTryHackme
  • README
  • CERTIFICATIONS & notes
    • My Roadmap to Becoming a Penetration Tester & Red Team
    • Comp Network
    • Red Team
    • Blue Team
      • Defensive Security Analyst
        • Security Monitoring & SIEM Fundamentals
        • Windows Event Logs & Finding Evil
          • Analyzing Evil With Sysmon & Event Logs
          • Event Tracing for Windows (ETW)
          • Tapping Into ETW
          • Get-WinEvent
          • Skills Assessment
          • Event IDs Components
        • Introduction to Threat Hunting & Hunting With Elastic
        • Understanding Log Sources & Investigating with Splunk
        • Windows Attacks & Defense
        • Intro to Network Traffic Analysis
        • Intermediate Network Traffic Analysis
        • Working with IDS/IPS
        • Introduction to Malware Analysis
        • YARA & Sigma for SOC Analysts
        • Introduction to Linux Forensics
      • Digital Forensics and Incident Response
    • Web Pentesting
  • Writeups
    • Tryhackme
  • Machines to pratice for
    • CPTS Preparation
    • OSEP
  • The Computer Science and Engineering program
    • Read this
    • Computer Science
    • Security
Powered by GitBook
On this page
  1. CERTIFICATIONS & notes
  2. Blue Team
  3. Defensive Security Analyst

Windows Event Logs & Finding Evil

Analyzing Evil With Sysmon & Event LogsEvent Tracing for Windows (ETW)Tapping Into ETWGet-WinEventSkills AssessmentEvent IDs Components
PreviousUsers Added Or Removed From A Local Group (Within A Specific Timeframe)NextAnalyzing Evil With Sysmon & Event Logs