#EventLogs
JPCert Details on Event Tracing Over EventLog for Windows Forensics
JPCert Details on Event Tracing Over EventLog for Windows Forensics
The EventLogs have long been the go-to source for incident investigators in the realm of Windows operating system forensics.
cybersecuritynews.com
November 15, 2024 at 9:41 AM
Active Directory Advanced Threat Hunting: This repo is all about advanced hunting - knowledge is power!
@Microsoft @github @MITREattack @msftsecurity @microsoft365 #Microsoft #ActiveDirectory #MITREATT&CK #Eventlogs #Windows #mvpbuzz #coolstuff #communityrocks
👇👇👇👇
github.com/tomwechsler/...
GitHub - tomwechsler/Active_Directory_Advanced_Threat_Hunting: This repo is about Active Directory Advanced Threat Hunting
This repo is about Active Directory Advanced Threat Hunting - tomwechsler/Active_Directory_Advanced_Threat_Hunting
github.com
February 4, 2025 at 4:48 PM
2/X

✅ New Integrations: FortiEDR, Uptycs EDR, and Elastic 8.16 support!
📝 Refined Telemetry Descriptions: Clearer definitions for EventLogs, EnablingTelemetry, and scoring adjustments.
💻 Website Upgrade: We’ve moved from spreadsheets to a dedicated, accessible website.

December 13, 2024 at 10:12 PM
Small treasures can be found on some EventLogs:
Finding Forensic Goodness In Obscure Windows Event Logs
Digital Forensics and Threat Hunting for Artifacts In Obscure Windows Event Logs
buff.ly
December 6, 2024 at 7:28 PM
December 20, 2024 at 4:45 PM
Interessanter Artikel über Zugriffsrechte auf Windows-Eventlogs. Ich habe bisher keine Möglichkeit gefunden, den Lesezugriff auf Microsoft-Windows-Windows Defender/Operational für interaktive Benutzer einzuschränken.

posts.specterops.io/security-des...
July 8, 2024 at 8:49 PM
Eventlogs can be somehow overwhelming. Found this one here which could be helpful for #detectionengineering

eventlog-compendium.streamlit.app
Eventlog Compendium
is the one-stop shop utility designed to simplify Windows security event log analysis, audit pol...
eventlog-compendium.streamlit.app
April 23, 2025 at 8:54 AM
Discover a comprehensive guide on using PowerShell to manage Windows event logs and beyond:
evotec.xyz/powershell-e...
#PowerShell #EventLogs #CyberSecurity
PowerShell - Everything you wanted to know about Event Logs and then some
If you feel this title is very familiar to you it's because I actually have stolen the title from Kevin Marquette. I'm in awe of his posts that take you thru topic from beginning till the end. No spli...
evotec.xyz
February 16, 2025 at 11:44 AM
hmmm... I keep forgetting to check eventlogs to see what kind of activities are available when I go...

so many events I can't go or participate lol
oh well, time to get fat
December 4, 2024 at 7:08 PM
Meet Humam Kourani, PhD student at #FraunhoferFIT & #SoftwareCampus participant. He's developing a prototype that generates #ProcessModels from #TextualDescriptions & #EventLogs together with #Celonis.📝

🎯 The aim: turning chaos into clarity

👇 Click here:
softwarecampus.de/en/projekt/s...

#HCI
June 25, 2025 at 9:14 AM
@liorbela.bsky.social
[IMP Post] 📌Intune Logs Event Logs Registry and Autopilot Details for Top-Level Troubleshooting
www.anoopcnair.com/intune-logs-...
#MicrosoftIntune #Intune #EventLogs #WindowsLogs #Windows11 #HTMDCommunity
June 5, 2026 at 10:02 AM
A day of SIEM rules followed by some light config templating. Really interesting trawling through windows eventlogs then trying to find it in the pish I ingest.

Tomorrow, wardriving whilst driving round the retail park...
November 15, 2024 at 8:08 PM
just blogged Date Ranges in Log Parser for EventLogs: If you need to trawl through your production s.. http://ping.fm/JlK1Z
November 13, 2024 at 3:06 AM
#mwgic #2026 #Windows #Microsoft #Server #Windows11 #SysAdmin #EventLogs

Microsoft closes one of the oldest troubleshooting gaps in Windows 11 and Server 2025 - Neowin share.google/VmEoQrybs9xx...
Microsoft closes one of the oldest troubleshooting gaps in Windows 11 and Server 2025
For years, a mysterious Windows error left IT admins guessing. Now, Microsoft has finally broken the silence with a long-awaited fix.
share.google
March 6, 2026 at 6:39 AM
Active Directory: Advanced Threat Hunting - MITRE ATT&CK Techniques and the Windows Eventlog ID's!
@microsoft.com @github.com @mvpaward.bsky.social #Microsoft #ActiveDirectory #MITREATT&CK #Eventlogs #Information #mvpbuzz #coolstuff #communityrocks
👇👇👇👇
github.com/tomwechsler/...
March 31, 2025 at 4:14 PM
March 17, 2025 at 4:51 PM
Active Directory: Advanced Threat Hunting - Advanced hunting for group policy settings (Default Domain Controllers Policy)!
@microsoft.com @mvpaward.bsky.social #Microsoft #ActiveDirectory #MITREATT&CK #Eventlogs #Windows #mvpbuzz #coolstuff #communityrocks
👇👇👇👇
github.com/tomwechsler/...
March 16, 2025 at 3:23 PM
March 4, 2025 at 3:23 PM
Active Directory: Advanced Threat Hunting - MITRE ATT&CK Techniques and the Windows Eventlog ID's!
@microsoft.com @github.com #Microsoft #ActiveDirectory #MITREATT&CK #Eventlogs #Information #mvpbuzz #coolstuff #communityrocks
👇👇👇👇
github.com/tomwechsler/...
github.com
February 9, 2025 at 4:48 PM
Active Directory: Advanced Threat Hunting - Advanced hunting for group policy settings (Default Domain Controllers Policy)!
@Microsoft @github @MITREattack @msftsecurity #Microsoft #ActiveDirectory #MITREATT&CK #Eventlogs #Windows #mvpbuzz #coolstuff #communityrocks
👇👇👇👇
github.com/tomwechsler/...
github.com
January 3, 2025 at 4:42 PM
Blogged:: Serie NSClient++ – Teil 4: Eventlog und weiteres!
Serie NSClient++ – Teil 4: Eventlog und weiteres!
Im vierten Teil der NSClient++ Serie geht es um die Überwachung des Windows Eventlogs und weitere kleine Features des NSClients wie z.B. check_multiple. Die Prüfung des Windows Eventlogs kann über mehrere Wege stattfinden. In unserer Serie erfolgt die Prüfung über CheckEventlog und die dazugehörige Filtersprache, durch Angabe verschiedener Filter sind auch hier komplexe Abfragen möglich. Beispielsweise kann mit folgender Abfrage auf vorkommen von Fehlermeldungen (nicht success) innerhalb des Systemlogs geprüft werden die einen Tag alt sind und von einem Service erzeugt wurden. Eine CRITICAL Meldung wird in diesem Fall ab dem ersten Treffer erzeugt. [code lang=“bash“] $ ./check_nrpe -H srv-ts.int.netways.de -p 5666 -c CheckEventLog -a file=system filter=new filter=out filter-eventType==success filter+eventSource=substr:Service ‚filter-generated=>1d‘ MaxCrit=1 [/code] Dabei wird ausgegeben welche Services den Fehler verursacht haben, zur genaueren Diagnose sollte dann das Eventlog herangezogen werden. Die Ausgabe kann je nach Gusto noch mit verschiedenen Parametern angereichert werden. Zu finden ist die Dokumentation der Filtersprache unter http://www.nsclient.org/nscp/wiki/CheckEventLog/CheckEventLog Ein weiterer interessanter Check des NSClients ist im Modul CheckHelpers enthalten. Das Kommando CheckMultiple ermöglicht es ähnlich zu check_multi unter Linux/Unix in einem Connect mehrere Abfragen auszuführen. CheckMultiple erwartet als Argumente die auszuführenden Checks, um Beispielsweise die Festplattenauslastung sowohl auf prozentualer als auch auf absoluter Basis zu messen […]
blog.netways.de
February 25, 2025 at 8:11 AM
Grabbing Eventlogs from busy servers http://bit.ly/1BZ17UD #powershell
December 15, 2024 at 7:04 PM