Network Security Channel
2.57K subscribers
5.33K photos
3.42K videos
5.56K files
4.44K links
شروع از سال 1395
Security Operation Center (SOC)
Bug Bounty
Vulnerability
Pentest
Hardening
Linux
Reasearch
Security Network
Security Researcher
DevSecOps
Blue Team
Red Team
Download Telegram
لاگ های مهم ویندوز جهت مانیتورینگ و تحلیل:


4688: A new process has been created

5156: The Windows Filtering Platform has allowed connection

7045: A service was installed in the system

4657: A registry value was modified

4660: An object was deleted

4663: An attempt was made to access, modify, delete an object

7036: a service has entered the stopped state

7040: a service has disabled

#SOC
#EventID
@Engineer_Computer
logon event type.pdf
601.9 KB
🖇Windows Event Log Analysis & Incident
Response Guid
🔎🔍

#SOC
#EventID

@Engineer_Computer
🔏SOC Multi Tool🔏

Chrome Extension for quick:

IP/Domain Reputation Lookup
IP/ Domain Info Lookup
Hash Reputation Lookup (
Decoding of Base64 & HEX using CyberChef
File Extension & Filename Lookup

and more (view pic)

https://chrome.google.com/webstore/detail/soc-multi-tool/diagjgnagmnjdfnfcciocmjcllacgkab/

#SOC
#EventID

@Engineer_Computer
eventid.pdf
182.7 KB
🔎Windows Event Log Cheat Sheet🔍


#security
#EventID
@Engineer_Computer