SavitarX
search
⌘Ctrlk
LinkedinTryHackme
SavitarX
  • README
  • CERTIFICATIONS & notes
    • My Roadmap to Becoming a Penetration Tester & Red Team
    • Comp Network
    • Red Team
    • Blue Team
      • CDSA
        • Security Monitoring & SIEM Fundamentals
        • Windows Event Logs & Finding Evil
          • Analyzing Evil With Sysmon & Event Logs
          • Event Tracing for Windows (ETW)
          • Tapping Into ETW
          • Get-WinEvent
          • Skills Assessment
          • Event IDs Components
        • Introduction to Threat Hunting & Hunting With Elastic
        • Understanding Log Sources & Investigating with Splunk
        • Windows Attacks & Defense
        • Intro to Network Traffic Analysis
        • Intermediate Network Traffic Analysis
        • Working with IDS/IPS
        • Introduction to Malware Analysis
        • YARA & Sigma for SOC Analysts
        • Introduction to Digital Forensics
        • Detecting Windows Attacks with Splunk
      • DFIR
    • Web Pentesting
  • Writeups
    • Tryhackme
    • HTB Sherlocks
  • Machines to pratice for
    • CPTS Preparation
    • CDSA Preparation
    • OSEP
  • The Computer Science and Engineering program
    • Read this
    • Computer Science
    • Security
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
  1. CERTIFICATIONS & noteschevron-right
  2. Blue Teamchevron-right
  3. CDSA

Windows Event Logs & Finding Evil

Analyzing Evil With Sysmon & Event Logschevron-rightEvent Tracing for Windows (ETW)chevron-rightTapping Into ETWchevron-rightGet-WinEventchevron-rightSkills Assessmentchevron-rightEvent IDs Componentschevron-right
PreviousUsers Added Or Removed From A Local Group (Within A Specific Timeframe)chevron-leftNextAnalyzing Evil With Sysmon & Event Logschevron-right