๐ ๐๐ฟ๐ผ๐บ ๐๐ต๐ฒ ๐๐ถ๐ฒ๐น๐ฑ โ Real-World Findings from Security Assessments
๐ฅ ๐ฐ๐ณ.๐ฒ%ย of infrastructures Iโve assessed ๐ฑ๐ผ๐ปโ๐ ๐ฒ๐ ๐๐ฒ๐ป๐ฑ ๐ฑ๐ฒ๐ณ๐ฎ๐๐น๐ ๐ฎ๐๐ฑ๐ถ๐๐ถ๐ป๐ด ๐ผ๐ป ๐ช๐ถ๐ป๐ฑ๐ผ๐๐ ๐๐ฒ๐๐ธ๐๐ผ๐ฝ & ๐ฆ๐ฒ๐ฟ๐๐ฒ๐ฟ
Auditing is one of the most misunderstood areas in Windows environments. By default, too little is logged; turn everything on and you drown in noise. Finding the right balance is critical โ especially if you forward logs for later analysis.
So how do you tackle this? Two good approaches:
1๏ธโฃย ๐๐ผ๐น๐น๐ผ๐ ๐ ๐ถ๐ฐ๐ฟ๐ผ๐๐ผ๐ณ๐โ๐ ๐ฟ๐ฒ๐ฐ๐ผ๐บ๐บ๐ฒ๐ป๐ฑ๐ฎ๐๐ถ๐ผ๐ป๐
๐น ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐๐ฎ๐๐ฒ๐น๐ถ๐ป๐ฒ๐:
๐ธ ๐๐๐ฑ๐ถ๐ ๐ฃ๐ผ๐น๐ถ๐ฐ๐ ๐๐๐ถ๐ฑ๐ฎ๐ป๐ฐ๐ฒ:
โ ๏ธ ๐ง๐ต๐ถ๐ ๐ด๐๐ถ๐ฑ๐ฎ๐ป๐ฐ๐ฒ ๐๐ฎ๐ ๐ป๐ผ๐ ๐ฟ๐ฒ๐น๐ถ๐ฎ๐ฏ๐น๐ฒ ๐ถ๐ป ๐๐ต๐ฒ ๐ฝ๐ฎ๐๐ due to errors/contradictions. Thereโs been an update, but I havenโt validated it yet. Use carefully, and remember it isnโt tailored to your industry or risks.
2๏ธโฃ ๐จ๐๐ฒ ๐๐ต๐ฒ ๐ ๐๐ง๐ฅ๐ ๐๐ง๐ง&๐๐ ๐ณ๐ฟ๐ฎ๐บ๐ฒ๐๐ผ๐ฟ๐ธ
Map relevant APT groups/TTPs for your region and sector and configure auditing around those. Not simple โ which is why I built ๐ง๐ต๐ฟ๐ฒ๐ฎ๐๐๐ผ๐ด to make it easier:
https://academy.horizon-secured.com/p/threatlog
This gives you auditing aligned with your companyโs threat profile. Of course, ๐ป๐ผ๐๐ต๐ถ๐ป๐ด ๐ถ๐ ๐ญ๐ฌ๐ฌ%, ๐ฎ๐ป๐ฑ ๐ฎ๐๐ฑ๐ถ๐๐ถ๐ป๐ด ๐ถ๐ ๐ป๐ผ๐ ๐ฎ โ๐๐ฒ๐ ๐ผ๐ป๐ฐ๐ฒ ๐ฎ๐ป๐ฑ ๐ณ๐ผ๐ฟ๐ด๐ฒ๐โ ๐๐ฎ๐๐ธ โ it should evolve with your infra.
๐ฌ๐ผ๐ ๐๐ต๐ผ๐๐น๐ฑ ๐ฎ๐น๐๐ผ ๐ฒ๐ ๐๐ฒ๐ป๐ฑ ๐๐ถ๐๐ต ๐ฆ๐๐๐บ๐ผ๐ป:
https://academy.horizon-secured.com/p/windows-infrastructure-security-guides
๐ ๐๐๐น๐น ๐ช๐ถ๐ป๐ฑ๐ผ๐๐ ๐๐ฑ๐๐ฎ๐ป๐ฐ๐ฒ๐ฑ ๐๐๐ฑ๐ถ๐๐ถ๐ป๐ด ๐ฐ๐ฎ๐๐ฒ๐ด๐ผ๐ฟ๐ถ๐ฒ๐:
https://academy.horizon-secured.com/p/advanced-audit-policy-configuration-table
๐ก If your ThreatLog access expired (30 days), just let me know and Iโll restart it for you.
