Cybersecurity Tip: Best Windows Event ID To Find Malware

Поделиться
HTML-код
  • Опубликовано: 30 июл 2024
  • Discover the power of one specific Windows Event ID in identifying potential malicious activity. Learn to spot suspicious activities, recognize malware indicators, and leverage this event for effective detection. Strengthen your defenses and stay ahead of threats.
    Windows Event ID Reference: www.ultimatewindowssecurity.c...
    _________________________________
    THE MYDFIR SOC ANALYST COURSE:
    With 8 chapters and 30+ hands-on labs tailored to security operations, I am focused on transforming you into a standout SOC analyst. Beyond tools, you'll master the investigation process and uncover hidden details. Let's make a real difference together.
    ▸Enroll here: academy.mydfir.com/p/soc
    _________________________________
    SIGN UP FOR FREE MENTORSHIP
    Getting started in Cybersecurity is difficult and you don't have to do it alone.
    Let me help you on your journey.
    ▸Sign up for FREE here: www.mydfir.com/mentorship
    _________________________________
    RECOMMEND COURSES FOR BEGINNERS:
    Coursera Google Cybersecurity Program
    Affiliate Link - imp.i384100.net/mydfir
    Microsoft Cybersecurity Analyst Professional Certificate
    Affiliate Link - imp.i384100.net/mydfir-MS
    Coursera Google IT Support Professional Certificate
    Affiliate Link - imp.i384100.net/mydfir-IT
    _________________________________
    PRODUCTS TO HELP YOU GET STARTED
    🗺️ 1-Year Cybersecurity Roadmap: mydfir.gumroad.com/l/roadmap
    📄 Resume Template: mydfir.gumroad.com/l/Resume-T...
    📑 Cover Letter Template: mydfir.gumroad.com/l/Cover-Le...
    🎙️ Interview Questions: www.mydfir.com/interview
    📚 Cybersecurity bookmarks: mydfir.gumroad.com/l/bookmarks
    _________________________________
    EARLY ACCESS & EXCLUSIVE VIDEOS
    Patreon: / mydfir
    _________________________________
    🕒 TIMELINE
    00:00 - Intro
    00:26 - What are Event IDs?
    00:55 - How to avoid confusion
    01:15 - Best Windows Event ID
    01:40 - Introduction to Best Windows Event ID
    02:58 - Demo
    10:05 - Resource for more information on Event IDs
    _________________________________
    FOLLOW ME ON SOCIAL MEDIA:
    ▸Instagram: / mydfir
    ▸X: x.com/@MyDFIR
    Disclaimer: All opinions in my videos are solely my own. Some links provided are affiliate links!
    #cybersecurity #cybersecuritytrainingforbeginners #cybersecurityforbeginners #socanalyst #soc

Комментарии • 25

  • @Bits4you
    @Bits4you 10 месяцев назад

    We just covered this last night in my Cybersecurity course. Thank you for the additional explanation regarding event ID

    • @MyDFIR
      @MyDFIR  10 месяцев назад

      Awesome! Hopefully you are learning lots from the course 😃
      Do you mind sharing the course that you are taking?

  • @ibrahimYODA-qk1ng
    @ibrahimYODA-qk1ng 6 месяцев назад

    Always on point

  • @Bb-307
    @Bb-307 9 месяцев назад

    Excellent 😁

  • @cajunphilippine
    @cajunphilippine Год назад

    thank you, my friend. Good to know this.

    • @MyDFIR
      @MyDFIR  Год назад

      Anytime! Event IDs is something easy to get overwhelmed. But fear not, Google is your friend when you need more info on Event IDs😜

  • @user-ui6mj6bg7b
    @user-ui6mj6bg7b Месяц назад

    Great information, thanks.

    • @MyDFIR
      @MyDFIR  Месяц назад

      Glad it was helpful!

  • @mylosovich24
    @mylosovich24 Год назад

    I appreciate your channel so much, Thank you

    • @MyDFIR
      @MyDFIR  Год назад +1

      You are so welcome!

  • @olumideajose2162
    @olumideajose2162 Год назад

    very informative👍

    • @MyDFIR
      @MyDFIR  Год назад

      Thanks! Hopefully learned something new 😀

  • @user-zh8sr5jk5s
    @user-zh8sr5jk5s 2 месяца назад

    Perfection level🎉🎉🎉

    • @MyDFIR
      @MyDFIR  2 месяца назад

      Thanks for watching ❤️

  • @johnvardy9559
    @johnvardy9559 Год назад +1

    You have mentioned in the future you show us a tool which is better for These logs.which will be that tool?

    • @MyDFIR
      @MyDFIR  Год назад +1

      This Thursday ill be showing you one tool we can use to view these event logs. But another tool i like to use is called Event Log Explorer.

    • @johnvardy9559
      @johnvardy9559 Год назад

      @@MyDFIR thanks 🙏 great News

  • @b3rn4rd01
    @b3rn4rd01 Год назад

    Kool👍

  • @calvinnguyen1699
    @calvinnguyen1699 5 месяцев назад

    how to filter log eventid:4625 with logon type=3

    • @MyDFIR
      @MyDFIR  5 месяцев назад

      You can filter using powershell or push the logs over to Splunk

  • @Chironex_Fleckeri
    @Chironex_Fleckeri Год назад

    5061 pls no

    • @Chironex_Fleckeri
      @Chironex_Fleckeri Год назад

      Whew. It was just some system integrity audit failure oh well

    • @MyDFIR
      @MyDFIR  Год назад

      LOL 4624 type 10 service account pls no