Cybersecurity Tip: Best Windows Event ID To Find Malware

Поделиться
HTML-код
  • Опубликовано: 10 дек 2024

Комментарии • 36

  • @kientrinhuc4214
    @kientrinhuc4214 11 дней назад

    shiiiii, bro you save my life. I have been looking for a detailed video tutorial like this for few months and now I found it

    • @MyDFIR
      @MyDFIR  11 дней назад

      Happy to help! Welcome to the channel :)

  • @Bits4you
    @Bits4you Год назад +1

    We just covered this last night in my Cybersecurity course. Thank you for the additional explanation regarding event ID

    • @MyDFIR
      @MyDFIR  Год назад

      Awesome! Hopefully you are learning lots from the course 😃
      Do you mind sharing the course that you are taking?

  • @c0ri
    @c0ri 16 дней назад

    This is such a good Event ID. One more thing I monitor for this is Elevation Token Type '%%1936' or '%%1937' where the account name doesn't contain an $ symbol (ie a real account) which means the UAC is disabled or the account ran the process with Administrator privileges.

    • @MyDFIR
      @MyDFIR  15 дней назад

      Awesome! Thanks for the input

  • @cajunphilippine
    @cajunphilippine Год назад

    thank you, my friend. Good to know this.

    • @MyDFIR
      @MyDFIR  Год назад

      Anytime! Event IDs is something easy to get overwhelmed. But fear not, Google is your friend when you need more info on Event IDs😜

  • @ibrahimYODA-qk1ng
    @ibrahimYODA-qk1ng 11 месяцев назад

    Always on point

  • @RubenMuñozAragon-e9n
    @RubenMuñozAragon-e9n 5 месяцев назад

    Great information, thanks.

    • @MyDFIR
      @MyDFIR  5 месяцев назад

      Glad it was helpful!

  • @danielantoniassi7646
    @danielantoniassi7646 8 дней назад

    Love this :)

  • @Bb-307
    @Bb-307 Год назад

    Excellent 😁

  • @mylosovich24
    @mylosovich24 Год назад

    I appreciate your channel so much, Thank you

    • @MyDFIR
      @MyDFIR  Год назад +1

      You are so welcome!

  • @johnvardy9559
    @johnvardy9559 Год назад +1

    You have mentioned in the future you show us a tool which is better for These logs.which will be that tool?

    • @MyDFIR
      @MyDFIR  Год назад +1

      This Thursday ill be showing you one tool we can use to view these event logs. But another tool i like to use is called Event Log Explorer.

    • @johnvardy9559
      @johnvardy9559 Год назад

      @@MyDFIR thanks 🙏 great News

  • @olumideajose2162
    @olumideajose2162 Год назад

    very informative👍

    • @MyDFIR
      @MyDFIR  Год назад

      Thanks! Hopefully learned something new 😀

  • @ismayilmammadov8469
    @ismayilmammadov8469 3 месяца назад

    Thank you 👍

    • @MyDFIR
      @MyDFIR  3 месяца назад

      You are welcome

  • @nagulapallibhaskar
    @nagulapallibhaskar 6 месяцев назад

    Perfection level🎉🎉🎉

    • @MyDFIR
      @MyDFIR  6 месяцев назад

      Thanks for watching ❤️

  • @calvinnguyen1699
    @calvinnguyen1699 9 месяцев назад

    how to filter log eventid:4625 with logon type=3

    • @MyDFIR
      @MyDFIR  9 месяцев назад

      You can filter using powershell or push the logs over to Splunk

  • @b3rn4rd01
    @b3rn4rd01 Год назад

    Kool👍

  • @kash212
    @kash212 2 месяца назад

    i use windows home

  • @Chironex_Fleckeri
    @Chironex_Fleckeri Год назад

    5061 pls no

    • @Chironex_Fleckeri
      @Chironex_Fleckeri Год назад

      Whew. It was just some system integrity audit failure oh well

    • @MyDFIR
      @MyDFIR  Год назад

      LOL 4624 type 10 service account pls no

  • @alicelik7956
    @alicelik7956 5 дней назад

    event id 4798 chrome.exe im using ungoogled chromium pls what is that mean my browser crash status acces violation after this event.

  • @midoahmed2725
    @midoahmed2725 3 месяца назад

    Great information, thank you very much

    • @MyDFIR
      @MyDFIR  3 месяца назад

      Glad it was helpful!