#eventlogs — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #eventlogs, aggregated by home.social.
-
#mwgic #2026 #Windows #Microsoft #Server #Windows11 #SysAdmin #EventLogs
Microsoft closes one of the oldest troubleshooting gaps in Windows 11 and Server 2025 - Neowin https://share.google/VmEoQrybs9xxx2V5Y
-
Coty Tuggle put together this cool lightweight incident tracking framework (adapted from earlier work by CrowdStrike). If you're dealing with Windows event logs in your investigation, this looks like a great resource for individual analysts to organize their investigations and produce incident timelines in a reproducible manner. Coty's example does it with Splunk, but it should be easy to adapt his framework to your preferred log analysis platform.
https://medium.com/@ctugglev/you-can-run-but-my-tracker-is-faster-38f9bacaf324
-
Excited to share my latest paper, "Activity and Sequence Detection Evaluation Metrics," co-authored with my colleagues at the University of St. Gallen. We introduce #AquDeM, a tool for event log comparison, featuring a Python library and a web app for evaluating activity detection methods. Check it out for insights into IoT-based event logs and BPM applications! #IoT #BPM #EventLogs #ProAmbitIon @snsf_ch
Paper: https://ceur-ws.org/Vol-3758/paper-13.pdf
GitHub: https://github.com/ics-unisg/aqudem -
PowerShell – Everything you wanted to know about Event Logs: https://evotec.pl/powershell-everything-you-wanted-to-know-about-event-logs/
-
CISA Red Team Shares Key Findings to Improve Monitoring and Hardening of Networks
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-059a
#cybersecurity #hardening #CISARedTeam #Monitoring #eventlogs #EDR -
Got #PowerShell 7 and not seeing event logs in your triage? N.B. for PowerShell 7: Windows PowerShell logs events to "Microsoft-Windows-PowerShell/Operational"), but PowerShell 7 now logs events to "PowerShellCore/Operational." Detailed (e.g., Script Block) logging is NOT enabled by default.
PowerShell 7 includes Group Policy templates and an installation script in $PSHOME. Specifically, you can use the "RegisterManifest.ps1" and "InstallPSCorePolicyDefinitions.ps1" scripts in the PS7 installation directory to enable logging.
Also, ISE doesn't support PS7 :( --> but there is an official Visual Studio Code extension that does, and it even has an "ISE Mode."
H/T Nasreddine Bencherchali ( @[email protected] ): https://twitter.com/nas_bench/status/1616211194934882304
I also consulted https://learn.microsoft.com/en-us/powershell/scripting/whats-new/migrating-from-windows-powershell-51-to-powershell-7?view=powershell-7.3
-
I have this long-term #project of applying #DifferentiableComputing and #DeepLearning to #industrial #AnomalyDetection.
I have created a #simulation of a #FlexibleManufacturingSystem for benchmarking on #uncorrelated #ProcessTraces, or #interlaced #EventLogs, and have some approaches to solve this under work.
If you're interested in this from the perspective of research, collaboration, investment or just general curiosity, please let's get in touch!