Windows Security Events For SOC – Part 3

Event monitoring plays a crucial role in determining whether the 5 pillars of Cybersecurity – confidentiality, integrity, availability, authenticity, and non-repudiation are intact or not. Events enablement, capturing and safe storage is another aspect which we will discuss later however in any enterprise and particularly for the ones that have regulatory requirements, feeding the events to a SIEM solution and setting the rules basis deviation would only provide useful actionable information. If rules are not defined properly, finding a relevant and actionable security event is like finding a needle in haystack. Continuing from the previous two articles in this series, this is the third one in line to help the Blue Teams and SOC to determine how they want to set the rules in their log monitoring environments.

Windows Security Events For SOC and Blue Teams
Windows Security Events For SOC and Blue Teams

Event ID 4697 is commonly triggered in Ransomware Attacks, and I have written another dedicated blog here <Click to Read>.

 

#Ransomware Attacks

#SOC Monitoring

Leave a Reply

Discover more from Cybersecurity 24x7

Subscribe now to keep reading and get access to the full archive.

Continue reading