Deployment Architecture

Windows logs- Do security logs also help to monitor NTFS?

debjit_k
Path Finder

Hi, 

Hope you are doing good just have 1 doubt..

On our Splunk windows, we have onboarded the security logs, so my doubt is does security logs also help to monitor NTFS 

 

Thanks 

Debjit 

Labels (2)
0 Karma

johnhuang
Motivator

There's windows event logs do not monitor NTFS. You may be able get kerberos auth to fileshares but thats about it.

0 Karma

debjit_k
Path Finder

Hi 

So what kind of logs can have NTFS. Actually I want to monitor LOL attacks.

Kindly guide me if we can create any UC using windows security logs for LOL attacks 

 

Thanks 

0 Karma

johnhuang
Motivator

For LOL or “Living off the Land" attacks, the ideal tool is an EDR/HIDS solution that provides you with raw logs, e.g. Carbonblack, or Sysmon which is free.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...