From the Field: Default Logging

๐Ÿ”Ž ๐—™๐—ฟ๐—ผ๐—บ ๐˜๐—ต๐—ฒ ๐—™๐—ถ๐—ฒ๐—น๐—ฑ โ€” Real-World Findings from Security Assessments

๐Ÿ’ฅ ๐Ÿฐ๐Ÿณ.๐Ÿฒ%ย of infrastructures Iโ€™ve assessed ๐—ฑ๐—ผ๐—ปโ€™๐˜ ๐—ฒ๐˜…๐˜๐—ฒ๐—ป๐—ฑ ๐—ฑ๐—ฒ๐—ณ๐—ฎ๐˜‚๐—น๐˜ ๐—ฎ๐˜‚๐—ฑ๐—ถ๐˜๐—ถ๐—ป๐—ด ๐—ผ๐—ป ๐—ช๐—ถ๐—ป๐—ฑ๐—ผ๐˜„๐˜€ ๐——๐—ฒ๐˜€๐—ธ๐˜๐—ผ๐—ฝ & ๐—ฆ๐—ฒ๐—ฟ๐˜ƒ๐—ฒ๐—ฟ

Auditing is one of the most misunderstood areas in Windows environments. By default, too little is logged; turn everything on and you drown in noise. Finding the right balance is critical โ€” especially if you forward logs for later analysis.

So how do you tackle this? Two good approaches:

1๏ธโƒฃย ๐—™๐—ผ๐—น๐—น๐—ผ๐˜„ ๐— ๐—ถ๐—ฐ๐—ฟ๐—ผ๐˜€๐—ผ๐—ณ๐˜โ€™๐˜€ ๐—ฟ๐—ฒ๐—ฐ๐—ผ๐—บ๐—บ๐—ฒ๐—ป๐—ฑ๐—ฎ๐˜๐—ถ๐—ผ๐—ป๐˜€

๐Ÿ”น ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—•๐—ฎ๐˜€๐—ฒ๐—น๐—ถ๐—ป๐—ฒ๐˜€:

https://learn.microsoft.com/en-us/windows/security/operating-system-security/device-management/windows-security-configuration-framework/windows-security-baselines

๐Ÿ”ธ ๐—”๐˜‚๐—ฑ๐—ถ๐˜ ๐—ฃ๐—ผ๐—น๐—ถ๐—ฐ๐˜† ๐—š๐˜‚๐—ถ๐—ฑ๐—ฎ๐—ป๐—ฐ๐—ฒ:

https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/audit-policy-recommendations?tabs=winclient

โš ๏ธ ๐—ง๐—ต๐—ถ๐˜€ ๐—ด๐˜‚๐—ถ๐—ฑ๐—ฎ๐—ป๐—ฐ๐—ฒ ๐˜„๐—ฎ๐˜€ ๐—ป๐—ผ๐˜ ๐—ฟ๐—ฒ๐—น๐—ถ๐—ฎ๐—ฏ๐—น๐—ฒ ๐—ถ๐—ป ๐˜๐—ต๐—ฒ ๐—ฝ๐—ฎ๐˜€๐˜ due to errors/contradictions. Thereโ€™s been an update, but I havenโ€™t validated it yet. Use carefully, and remember it isnโ€™t tailored to your industry or risks.

 

2๏ธโƒฃ ๐—จ๐˜€๐—ฒ ๐˜๐—ต๐—ฒ ๐— ๐—œ๐—ง๐—ฅ๐—˜ ๐—”๐—ง๐—ง&๐—–๐—ž ๐—ณ๐—ฟ๐—ฎ๐—บ๐—ฒ๐˜„๐—ผ๐—ฟ๐—ธ

Map relevant APT groups/TTPs for your region and sector and configure auditing around those. Not simple โ€” which is why I built ๐—ง๐—ต๐—ฟ๐—ฒ๐—ฎ๐˜๐—Ÿ๐—ผ๐—ด to make it easier:

https://academy.horizon-secured.com/p/threatlog

This gives you auditing aligned with your companyโ€™s threat profile. Of course, ๐—ป๐—ผ๐˜๐—ต๐—ถ๐—ป๐—ด ๐—ถ๐˜€ ๐Ÿญ๐Ÿฌ๐Ÿฌ%, ๐—ฎ๐—ป๐—ฑ ๐—ฎ๐˜‚๐—ฑ๐—ถ๐˜๐—ถ๐—ป๐—ด ๐—ถ๐˜€ ๐—ป๐—ผ๐˜ ๐—ฎ โ€œ๐˜€๐—ฒ๐˜ ๐—ผ๐—ป๐—ฐ๐—ฒ ๐—ฎ๐—ป๐—ฑ ๐—ณ๐—ผ๐—ฟ๐—ด๐—ฒ๐˜โ€ ๐˜๐—ฎ๐˜€๐—ธ โ€” it should evolve with your infra.

๐—ฌ๐—ผ๐˜‚ ๐˜€๐—ต๐—ผ๐˜‚๐—น๐—ฑ ๐—ฎ๐—น๐˜€๐—ผ ๐—ฒ๐˜…๐˜๐—ฒ๐—ป๐—ฑ ๐˜„๐—ถ๐˜๐—ต ๐—ฆ๐˜†๐˜€๐—บ๐—ผ๐—ป:

https://academy.horizon-secured.com/p/windows-infrastructure-security-guides

๐Ÿ“‘ ๐—™๐˜‚๐—น๐—น ๐—ช๐—ถ๐—ป๐—ฑ๐—ผ๐˜„๐˜€ ๐—”๐—ฑ๐˜ƒ๐—ฎ๐—ป๐—ฐ๐—ฒ๐—ฑ ๐—”๐˜‚๐—ฑ๐—ถ๐˜๐—ถ๐—ป๐—ด ๐—ฐ๐—ฎ๐˜๐—ฒ๐—ด๐—ผ๐—ฟ๐—ถ๐—ฒ๐˜€:

https://academy.horizon-secured.com/p/advanced-audit-policy-configuration-table

๐Ÿ’ก If your ThreatLog access expired (30 days), just let me know and Iโ€™ll restart it for you.