From the Field: Logging

๐Ÿ”Ž ๐—™๐—ฟ๐—ผ๐—บ ๐˜๐—ต๐—ฒ ๐—™๐—ถ๐—ฒ๐—น๐—ฑ โ€” Real-World Findings from Security Assessments

๐Ÿ’ฅย ๐Ÿฒ๐Ÿญ.๐Ÿต%ย of infrastructures Iโ€™ve assessedย ๐—ฑ๐—ผ ๐—ป๐—ผ๐˜ ๐—ฐ๐—ผ๐—ป๐—ณ๐—ถ๐—ด๐˜‚๐—ฟ๐—ฒ ๐—ฝ๐—ฟ๐—ผ๐—ฝ๐—ฒ๐—ฟ ๐—น๐—ผ๐—ด๐—ด๐—ถ๐—ป๐—ดย in their Windows environments.

That includes Windows Desktops, Servers, and even Domain Controllers left withย ๐—ฑ๐—ฒ๐—ณ๐—ฎ๐˜‚๐—น๐˜ ๐—ฎ๐˜‚๐—ฑ๐—ถ๐˜๐—ถ๐—ป๐—ด ๐˜€๐—ฒ๐˜๐˜๐—ถ๐—ป๐—ด๐˜€.

๐—ง๐—ต๐—ฒ ๐—ฝ๐—ฟ๐—ผ๐—ฏ๐—น๐—ฒ๐—บ?

By default, Windows logs very little. Without configuring Advanced Auditing, youโ€™re missing critical visibility โ€” and no SIEM can compensate for logs that donโ€™t exist.

And while “just turn on auditing” sounds simple, it’s a trap. Log too little, and you miss attacks. Log everything, and you drown in noise.

๐Ÿ”Žย ๐—›๐—ผ๐˜„ ๐˜๐—ผ ๐˜€๐˜๐—ฎ๐—ฟ๐˜?

Instead of blindly enabling everything, start from your business context:

๐Ÿ”ธWhat industry are you in?

๐Ÿ”ธWhere are you based?

With this, you can ๐—บ๐—ฎ๐—ฝ ๐—น๐—ถ๐—ธ๐—ฒ๐—น๐˜† ๐˜๐—ต๐—ฟ๐—ฒ๐—ฎ๐˜๐˜€ ๐˜‚๐˜€๐—ถ๐—ป๐—ด ๐˜๐—ต๐—ฒ ๐— ๐—œ๐—ง๐—ฅ๐—˜ ๐—”๐—ง๐—ง&๐—–๐—žย framework โ€” identifying whichย APTย groups target your region/sector and whatย tactics, techniques, and proceduresย they use. Itโ€™s not perfect, but itโ€™s a smart starting point.

๐Ÿงฐ ๐—ก๐—ฒ๐—ฒ๐—ฑ ๐—ต๐—ฒ๐—น๐—ฝ?

I have created several free resources to get you started. You can find following relevant resources in my Horizon Secured Academy:

๐Ÿ”ธ๐—”๐—ฑ๐˜ƒ๐—ฎ๐—ป๐—ฐ๐—ฒ๐—ฑ ๐—”๐˜‚๐—ฑ๐—ถ๐˜๐—ถ๐—ป๐—ด ๐—ง๐—ฎ๐—ฏ๐—น๐—ฒ

๐Ÿ”ธ๐—ฆ๐˜†๐˜€๐—บ๐—ผ๐—ป ๐—–๐—ผ๐—ป๐—ณ๐—ถ๐—ด๐˜‚๐—ฟ๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐—š๐˜‚๐—ถ๐—ฑ๐—ฒ

๐Ÿ”ธ๐—ง๐—ต๐—ฟ๐—ฒ๐—ฎ๐˜๐—Ÿ๐—ผ๐—ด ๐—ง๐—ผ๐—ผ๐—น โ€“ Just input your industry and country, and it builds a tailored baseline (including Sysmon) to get you started with meaningful logs.

https://academy.horizon-secured.com/p/threatlog