Event ID's or alternate for below activities.

N

Nathan Bob

Dear All,

Could you provide the event ID's or alternate method in order to detect following activities as part of hunting.

Please advise What event IDs to be enabled to track following activities?

When files/Directories are created and marked Hidden
Account Discovery local (Using net user, net localgroup)
Account Discovery domain (Using net user/domain, net group /domain)
Password policy (Using net accounts /domain)
Query Registry (Querying specific registry keys using "reg query")

Thanks,

Nathan

Continue reading...
 

Similar threads

Back
Top Bottom