Event Log Analysis
Steve Anson · 2019
Microsoft Windows provides detailed auditing capabilities that have improved with each new operating system version. The event logging service can generate a vast amount of information about account logons, file and system access, changes to system configurations, process tracking, and much more. These logs can be stored locally, or they can leverage Window's Event Forwarding store event logs on a remote Windows system. Microsoft provides access to event log data through the built-in Event Viewer application and through PowerShell cmdlets that allow for queries leveraging PowerShell Remoting across the network. Event logs can also be centralized to a third-party security information and event management solution for aggregation and analysis. With proper tuning and log retention, event logs can be an extremely powerful tool for incident responders. By understanding and using event logs efficiently, incident handlers can detect malicious actors, reconstruct a vast amount of adversary activity, and identify impacted systems.