Windows Logs
To watch out for indicators of compromise or indicators of attack.
Windows
Demo 1: Successful Brute Force attempts

Finding New Local Admin Accounts

Recurring Malware on Host

Network and Port Scan

Demo 2: Event clearing

Demo 3: Account manipulation

Windows EventIDs


References
Last updated