mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
33 lines
1.7 KiB
YAML
33 lines
1.7 KiB
YAML
name: Windows Log Manipulation
|
|
id: b6db2c60-a281-48b4-95f1-2cd99ed56835
|
|
version: 2
|
|
date: '2017-09-12'
|
|
description: Adversaries often try to cover their tracks by manipulating Windows logs.
|
|
Use these searches to help you monitor for suspicious activity surrounding log files--an
|
|
essential component of an effective defense.
|
|
narrative: 'Because attackers often modify system logs to cover their tracks and/or
|
|
to thwart the investigative process, log monitoring is an industry-recognized best
|
|
practice. While there are legitimate reasons to manipulate system logs, it is still
|
|
worthwhile to keep track of who manipulated the logs, when they manipulated them,
|
|
and in what way they manipulated them (determining which accesses, tools, or utilities
|
|
were employed). Even if no malicious activity is detected, the knowledge of an attempt
|
|
to manipulate system logs may be indicative of a broader security risk that should
|
|
be thoroughly investigated.\
|
|
|
|
The Analytic Story gives users two different ways to detect manipulation of Windows
|
|
Event Logs and one way to detect deletion of the Update Sequence Number (USN) Change
|
|
Journal. The story helps determine the history of the host and the users who have
|
|
accessed it. Finally, the story aides in investigation by retrieving all the information
|
|
on the process that caused these events (if the process has been identified).'
|
|
author: Rico Valdez, Splunk
|
|
type: ESCU
|
|
references:
|
|
- https://www.crowdstrike.com/blog/bears-midst-intrusion-democratic-national-committee/
|
|
- https://zeltser.com/security-incident-log-review-checklist/
|
|
- http://journeyintoir.blogspot.com/2013/01/re-introducing-usnjrnl.html
|
|
tags:
|
|
analytics_story: Windows Log Manipulation
|
|
usecase: Security Monitoring
|
|
category:
|
|
- Adversary Tactics
|