Splunk Windows事件日志分析
原名:analyzing-windows-event-logs-in-splunk
分析 Splunk 中的 Windows 安全、系统和 Sysmon 事件日志,以检测潜在的安全威胁和异常活动。
- 分类
- 数据分析
- 版本
- v1.0
- 作者
- 弈韬(@ra1nzzz)
- 下载
- 0
- 收藏
- 0
- 发布
- 2026-08-18
- 更新
- 2026-08-20
- TRACE 评分
- 3.4 / 5
内容概览
Use this skill when: - SOC analysts investigate alerts related to Windows authentication, process execution, or AD changes - Detection engineers build SPL queries for Windows-based threat detection - Incident responders need forensic timelines of Windows endpoint or domain controller activity - Periodic threat hunting targets Windows-specific ATT&CK techniques Do not use for Linux/macOS endpoint analysis or network-only investigations. - Splunk with Windows Event Log data ingested (sourcetype WinEventLog:Security, WinEventLog:System, XmlWinEventLog:Microsoft-Windows-Sysmon/Operational) - Sysmon deployed on endpoints with SwiftOnSecurity or Olaf Hartong configuration - CIM data model acceleration for Endpoint and Authentication data models - Knowledge of Windows Security Event IDs and Sysmon event types Brute Force Detection (EventCode 4625 — Failed Logon): Password Spray Detection: Succe…