This is such a good Event ID. One more thing I monitor for this is Elevation Token Type '%%1936' or '%%1937' where the account name doesn't contain an $ symbol (ie a real account) which means the UAC is disabled or the account ran the process with Administrator privileges.
shiiiii, bro you save my life. I have been looking for a detailed video tutorial like this for few months and now I found it
Happy to help! Welcome to the channel :)
We just covered this last night in my Cybersecurity course. Thank you for the additional explanation regarding event ID
Awesome! Hopefully you are learning lots from the course 😃
Do you mind sharing the course that you are taking?
This is such a good Event ID. One more thing I monitor for this is Elevation Token Type '%%1936' or '%%1937' where the account name doesn't contain an $ symbol (ie a real account) which means the UAC is disabled or the account ran the process with Administrator privileges.
Awesome! Thanks for the input
thank you, my friend. Good to know this.
Anytime! Event IDs is something easy to get overwhelmed. But fear not, Google is your friend when you need more info on Event IDs😜
Always on point
Great information, thanks.
Glad it was helpful!
Love this :)
Excellent 😁
I appreciate your channel so much, Thank you
You are so welcome!
You have mentioned in the future you show us a tool which is better for These logs.which will be that tool?
This Thursday ill be showing you one tool we can use to view these event logs. But another tool i like to use is called Event Log Explorer.
@@MyDFIR thanks 🙏 great News
very informative👍
Thanks! Hopefully learned something new 😀
Thank you 👍
You are welcome
Perfection level🎉🎉🎉
Thanks for watching ❤️
how to filter log eventid:4625 with logon type=3
You can filter using powershell or push the logs over to Splunk
Kool👍
Thanks for watching!
Great Job
i use windows home
5061 pls no
Whew. It was just some system integrity audit failure oh well
LOL 4624 type 10 service account pls no
event id 4798 chrome.exe im using ungoogled chromium pls what is that mean my browser crash status acces violation after this event.
Great information, thank you very much
Glad it was helpful!