SIEM and Log Analysis¶
Where to find evidence in logs, what to look for, and the tools for collecting and searching them.
Pages¶
| Page | Description |
|---|---|
| Log Review Approach | A general method for reviewing logs during an incident |
| Windows Event Logs | Event IDs for logons, account changes, processes, and tampering |
| Linux Logs | Log locations and keywords for authentication and system activity |
| Web Server Logs | Signs of attacks in web server access logs |
| Network Device Logs | Firewall and network device log messages worth reviewing |
| Syslog | The syslog protocol and message format |
| Sysmon | Detailed Windows process, network, and file logging |
| Splunk | Splunk setup basics |
| DeepBlueCLI | Threat hunting in Windows event logs with PowerShell |