My DFIR happy place is a Windows event log with 4688 events. Third-party IR consulting teaches you to have modest expectations at best.
6
9
59
@hal_pomeranz How often do you see the Event ID configured in enterprise environments? 4688 is great to have on servers with relatively few processes spawned. Also, in your experience, how verbose are the logs?
1
Rarely-- but that's partially because of my role as a third-party. Sites that are mature enough to have enabled this event also likely have in-house IR capability, so I'll almost never visit them.
Mar 29, 2022 · 1:32 PM UTC
1

