Digital Forensics and Incident Response | DFIR
  • Blog
  • Infosec
  • Windows Forensics
  • Mac Forensics
  • Memory Forensics
  • Incident Response
  • Contact

Logs and event co-relation

5/11/2017

0 Comments

 
Computer Security logs – contains information about events in an organizational and network
  1. OS Logs -  Logs of OS for server, workstation and network device
i.Event logs: Operational Action by OS
ii.Audit Logs: Security event information like failed auth, file access, policy changes, account changes
  1. Application Logs: All events logs by Program, email server, database server.
  2. Security Logs: Logs of network host based security software log like antivirus logs and all security related logs.
Router log file:
  • Store logs in router cache
  • Detailed info about the network traffic
Honeypot logs:
  • Logs from Honeypots are considered as suspicious
  • The honey pot admin is the only authorized user.
Application Logs: Application logs store event messages recorded by windows application.
Popular Event ID’s
  • 528 – Successful Logged on to an account
  • 531 Logon attempt made by disable account
  • 532 – Expired account
Port number:
UDP Port 123- NTP
Event Correlation Approaches:
  • Graph Based:
  • Netural Network based
  • Codebook-based
  • Rule based:
  • Field-Based:
  • Automated Field:
  • Payload Correlation:
Types of Correlation:
  • Same Platform Correlation
  • Cross Platform Correlation
0 Comments



Leave a Reply.

    Join DFIR Global Slack Channel 

    Mac Forensics
    Windows Forensics
    Forensic Tools

    Categories

    All
    Attack
    Bash
    Bigdata
    Corporate
    Ctf
    Data
    Digital Forensics
    Docker
    EDR
    Forensics
    Hacking
    Hadoop
    HDFS
    Health Care
    Linux
    Memory
    Network
    Network Forensics
    PCIP
    SQL
    Windows
    Wireshark

    Archives

    October 2019
    September 2019
    July 2019
    June 2019
    May 2019
    March 2019
    April 2018
    March 2018
    February 2018
    July 2017
    June 2017
    May 2017
    November 2015
    October 2015
    July 2015
    June 2015
    May 2015
    April 2015
    March 2015

    RSS Feed