home.social

#eventlogs — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #eventlogs, aggregated by home.social.

fetched live
  1. Coty Tuggle put together this cool lightweight incident tracking framework (adapted from earlier work by CrowdStrike). If you're dealing with Windows event logs in your investigation, this looks like a great resource for individual analysts to organize their investigations and produce incident timelines in a reproducible manner. Coty's example does it with Splunk, but it should be easy to adapt his framework to your preferred log analysis platform.

    medium.com/@ctugglev/you-can-r

    #DFIR #Windows #EventLogs

  2. Excited to share my latest paper, "Activity and Sequence Detection Evaluation Metrics," co-authored with my colleagues at the University of St. Gallen. We introduce #AquDeM, a tool for event log comparison, featuring a Python library and a web app for evaluating activity detection methods. Check it out for insights into IoT-based event logs and BPM applications! #IoT #BPM #EventLogs #ProAmbitIon @snsf_ch

    Paper: ceur-ws.org/Vol-3758/paper-13.
    GitHub: github.com/ics-unisg/aqudem

  3. Got #PowerShell 7 and not seeing event logs in your triage? N.B. for PowerShell 7: Windows PowerShell logs events to "Microsoft-Windows-PowerShell/Operational"), but PowerShell 7 now logs events to "PowerShellCore/Operational." Detailed (e.g., Script Block) logging is NOT enabled by default.

    PowerShell 7 includes Group Policy templates and an installation script in $PSHOME. Specifically, you can use the "RegisterManifest.ps1" and "InstallPSCorePolicyDefinitions.ps1" scripts in the PS7 installation directory to enable logging.

    Also, ISE doesn't support PS7 :( --> but there is an official Visual Studio Code extension that does, and it even has an "ISE Mode."

    H/T Nasreddine Bencherchali ( @[email protected] ): twitter.com/nas_bench/status/1

    I also consulted learn.microsoft.com/en-us/powe

    #PowerShell7 #DFIR #eventlogs #logging #artifacts

  4. I have this long-term #project of applying #DifferentiableComputing and #DeepLearning to #industrial #AnomalyDetection.

    I have created a #simulation of a #FlexibleManufacturingSystem for benchmarking on #uncorrelated #ProcessTraces, or #interlaced #EventLogs, and have some approaches to solve this under work.

    If you're interested in this from the perspective of research, collaboration, investment or just general curiosity, please let's get in touch!