What Event Logs? Part 1: Attacker Tricks to Remove Event Logs

  Рет қаралды 27,188

SANS Digital Forensics and Incident Response

SANS Digital Forensics and Incident Response

Күн бұрын

Пікірлер: 7
@Ichinin
@Ichinin 7 жыл бұрын
12:46 Minimum size is 1024k and can be set to any multiple of 64k. There are many other ways to detect, prevent and mitigate these attacks: whatever the attacker do, the defender can do too.
@moretwocome21
@moretwocome21 2 жыл бұрын
Very good presentation!
@joyramsarkar9212
@joyramsarkar9212 2 жыл бұрын
Very good sir...its informative
@joebrown-w6q
@joebrown-w6q 4 ай бұрын
Is there a way you can see when logs were deleted? I noticed about a week or two ago. When I went to event viewer in security logs I saw my laptop turn on when I was not even using it! Tonight, I went on to check logs and it didn't even go past the previous day. I turned it off and back on, now I can see past today. Whats going on, can anyone help?
@zzsql
@zzsql 10 ай бұрын
Sounds like the speaker is dialed in on a cell phone. Use VOIP next time so you're clear and easy to understand please.
@nikseetharaman2008
@nikseetharaman2008 6 жыл бұрын
Q&A was highly disappointing - he was unable to answer basic detections questions about the very tactics he brings up.
@Erin-bc8ic
@Erin-bc8ic 5 жыл бұрын
A lot of them seemed very edge-case and niche. Wouldn't expect the presenter to know every single path and scenario. They should ask some better questions next time.
What Event Logs  Part 2  Lateral Movement without Event Logs
1:01:00
SANS Digital Forensics and Incident Response
Рет қаралды 12 М.
SANS DFIR Webcast - Incident Response Event Log Analysis
48:50
SANS Digital Forensics and Incident Response
Рет қаралды 83 М.
Mom Hack for Cooking Solo with a Little One! 🍳👶
00:15
5-Minute Crafts HOUSE
Рет қаралды 23 МЛН
Investigating WMI Attacks
1:00:43
SANS Digital Forensics and Incident Response
Рет қаралды 27 М.
Quick Forensics of Windows Event Logs (DeepBlueCLI)
9:55
John Hammond
Рет қаралды 48 М.
SANS DFIR Webcast - Memory Forensics for Incident Response
1:08:10
SANS Digital Forensics and Incident Response
Рет қаралды 54 М.
Anti-forensics Techniques Used By Threat Actors In The Wild - Hela Lucas
44:35
Security BSides London
Рет қаралды 2,3 М.
SANS Webcast: Effective (Threat) Hunting Techniques
54:01
SANS EMEA
Рет қаралды 30 М.
CMD - Command Prompt Training for IT Professionals (Full Course)
3:18:32
Jobskillshare Skills-Based Platform
Рет қаралды 1,5 МЛН
Practical Malware Analysis Essentials for Incident Responders
50:49
RSA Conference
Рет қаралды 153 М.
Introducing the New SANS DFIR “Hunt Evil“ Poster
1:01:27
SANS Digital Forensics and Incident Response
Рет қаралды 22 М.