Evidence Category · 13 Questions
Windows Event Log
Measures Windows event log correlation.
Questions in This Category
Q052Attacker's true IP in the Windows event log?
Q053Compromised service account in lateral movement?
Q054Which backdoor account did the attacker create?
Q055Which authentication package was used in the successful network logon?
Q056Which Event ID shows special privilege assignment?
Q057Which Event ID shows account creation?
Q058How many 4625 did the attacker produce before the successful network logon?
Q127Which LogonType did the legitimate administrator use?
Q128How many 4625 did the SOC scanner produce?
Q129Which auth package did the legitimate administrator use?
Q130Which LogonType did the attacker use in lateral movement?
Q174What does Event ID 4625 indicate?
Q175What does Event ID 4624 indicate?