Splunk Windows事件日志分析

原名:analyzing-windows-event-logs-in-splunk

分析 Splunk 中的 Windows 安全、系统和 Sysmon 事件日志,以检测潜在的安全威胁和异常活动。

分类
数据分析
版本
v1.0
作者
弈韬(@ra1nzzz)
下载
0
收藏
0
发布
2026-08-18
更新
2026-08-20
TRACE 评分
3.4 / 5

内容概览

Use this skill when: - SOC analysts investigate alerts related to Windows authentication, process execution, or AD changes - Detection engineers build SPL queries for Windows-based threat detection - Incident responders need forensic timelines of Windows endpoint or domain controller activity - Periodic threat hunting targets Windows-specific ATT&CK techniques Do not use for Linux/macOS endpoint analysis or network-only investigations. - Splunk with Windows Event Log data ingested (sourcetype WinEventLog:Security, WinEventLog:System, XmlWinEventLog:Microsoft-Windows-Sysmon/Operational) - Sysmon deployed on endpoints with SwiftOnSecurity or Olaf Hartong configuration - CIM data model acceleration for Endpoint and Authentication data models - Knowledge of Windows Security Event IDs and Sysmon event types Brute Force Detection (EventCode 4625 — Failed Logon): Password Spray Detection: Succe…

查看 SKILL 详情