Hi,
Hope you are doing good just have 1 doubt..
On our Splunk windows, we have onboarded the security logs, so my doubt is does security logs also help to monitor NTFS
Thanks
Debjit
There's windows event logs do not monitor NTFS. You may be able get kerberos auth to fileshares but thats about it.
Hi
So what kind of logs can have NTFS. Actually I want to monitor LOL attacks.
Kindly guide me if we can create any UC using windows security logs for LOL attacks
Thanks
For LOL or “Living off the Land" attacks, the ideal tool is an EDR/HIDS solution that provides you with raw logs, e.g. Carbonblack, or Sysmon which is free.