From the Field: Logs Evaluation

๐Ÿ”Ž ๐—™๐—ฟ๐—ผ๐—บ ๐˜๐—ต๐—ฒ ๐—™๐—ถ๐—ฒ๐—น๐—ฑ โ€” Real-World Findings from Security Assessments

๐Ÿ’ฅย ๐Ÿฐ๐Ÿฎ.๐Ÿต%ย of infrastructures Iโ€™ve assessedย ๐—ฑ๐—ผ๐—ปโ€™๐˜ ๐—ฒ๐˜ƒ๐—ฎ๐—น๐˜‚๐—ฎ๐˜๐—ฒ ๐—น๐—ผ๐—ด๐˜€ ๐—ณ๐—ฟ๐—ผ๐—บ ๐˜๐—ต๐—ฒ๐—ถ๐—ฟ ๐—ช๐—ถ๐—ป๐—ฑ๐—ผ๐˜„๐˜€ ๐—œ๐—ป๐—ณ๐—ฟ๐—ฎ๐˜€๐˜๐—ฟ๐˜‚๐—ฐ๐˜๐˜‚๐—ฟ๐—ฒ

Weโ€™ve talked about Windows logging โ€” but thatโ€™s only part of the picture. You also need to ๐—ฐ๐—ฒ๐—ป๐˜๐—ฟ๐—ฎ๐—น๐—ถ๐˜‡๐—ฒ, ๐—ฎ๐—ป๐—ฎ๐—น๐˜†๐˜‡๐—ฒ, ๐—ฎ๐—ป๐—ฑ ๐—ฑ๐—ฒ๐˜๐—ฒ๐—ฐ๐˜.

๐Ÿ› ๏ธ Even basic detections can give you a ๐—ต๐˜‚๐—ด๐—ฒ ๐˜€๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—ฏ๐—ผ๐—ผ๐˜€๐˜ โ€” no expensive SIEM needed. Iโ€™ve seen massive SIEMs collect data and do nothing useful.

๐—ฆ๐˜๐—ฎ๐—ฟ๐˜ ๐˜„๐—ถ๐˜๐—ต these low-effort, high-impact detection wins:

๐Ÿ”นย ๐—”๐˜‚๐˜๐—ต๐—ฒ๐—ป๐˜๐—ถ๐—ฐ๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐—™๐—ฎ๐—ถ๐—น๐˜‚๐—ฟ๐—ฒ๐˜€

Watch for common brute-force and password spray indicators:

โ€ข 4776 โ€“ Attempted credential validation

โ€ข 4771 โ€“ Kerberos pre-authentication failure

โ€ข 4625 โ€“ Failed logon

โ€ข 4740 โ€“ Account locked out

๐Ÿ’ก On your Domain Controller, ๐˜๐—ฟ๐˜† ๐˜๐—ต๐—ถ๐˜€ ๐—พ๐˜‚๐—ถ๐—ฐ๐—ธ ๐—ฃ๐—ผ๐˜„๐—ฒ๐—ฟ๐—ฆ๐—ต๐—ฒ๐—น๐—น to find bad password attempts and potential lockouts:

$PDC=Get-ADForest |Select-Object -ExpandProperty RootDomain |Get-ADDomain |Select-Object -ExpandProperty PDCEmulator

$BadPasswordCount=Get-ADUser -LDAPFilter ‘(&(objectCategory=user)(badpwdcount>=3))’ -Server $PDC -Properties Name, UserPrincipalName, BadPWDCount, AccountLockoutTime, LockedOut | Select-Object Name, UserPrincipalName, BadPWDCount, AccountLockoutTime, LockedOut | Sort-Object -Descending -Property BadPWDCount

Were you alerted about these attempts? ๐—œ๐—ณ ๐—ป๐—ผ๐˜ โ€” ๐˜๐—ต๐—ฒ๐—ฟ๐—ฒโ€™๐˜€ ๐˜„๐—ผ๐—ฟ๐—ธ ๐˜๐—ผ ๐—ฑ๐—ผ.

๐Ÿ”นย ๐—ข๐˜๐—ต๐—ฒ๐—ฟ ๐—ž๐—ฒ๐˜† ๐—˜๐˜ƒ๐—ฒ๐—ป๐˜๐˜€ ๐˜๐—ผ ๐— ๐—ผ๐—ป๐—ถ๐˜๐—ผ๐—ฟ

โ€ข 1102ย โ€“ Security audit log cleared

โ€ข 104ย โ€“ System/Application log cleared

โ€ข 4765 / 4766ย โ€“ SID History modification attempts

โ€ข 4780ย โ€“ ACL set on admin group members

โ€ข 4794ย โ€“ DSRM password changed

โ€ข 7045ย โ€“ New service installed

๐ŸŽฏ Useย ๐—ฆ๐—”๐—–๐—Ÿ๐˜€ย to track sensitive AD object changes or critical system modifications.

๐Ÿ‘€ Real visibility ๐—ฑ๐—ผ๐—ฒ๐˜€๐—ปโ€™๐˜ ๐—ฟ๐—ฒ๐—พ๐˜‚๐—ถ๐—ฟ๐—ฒ ๐—ฎ ๐Ÿณ-๐—ณ๐—ถ๐—ด๐˜‚๐—ฟ๐—ฒ security budget. These detections are low-cost and high-value.

Letโ€™s create a more comprehensive list. These were just examples.

๐Ÿ‘‰ ๐—ช๐—ต๐—ถ๐—ฐ๐—ต ๐—ฒ๐˜ƒ๐—ฒ๐—ป๐˜ ๐—œ๐——๐˜€ ๐—ฑ๐—ผ ๐˜†๐—ผ๐˜‚ ๐—ฟ๐—ฒ๐—ฐ๐—ผ๐—บ๐—บ๐—ฒ๐—ป๐—ฑ ๐˜„๐—ฎ๐˜๐—ฐ๐—ต๐—ถ๐—ป๐—ด ๐—ผ๐˜‚๐˜ ๐—ณ๐—ผ๐—ฟ?