New Research Reveals Windows Event Logs Key to Identifying Ransomware Attacks
ID: 94a10d52-bf91-5e13-bb44-e21dd3cbb100
STIX ID: report--94a10d52-bf91-5e13-bb44-e21dd3cbb100
Feed Name: cybersecurityNews.com
JPCERT/CC and other researchers identified distinct Windows Event Log signatures for several human-operated ransomware families (Conti and related variants, Phobos, Midas, BadRabbit, Bisamware), highlighting specific Event IDs and behaviors (e.g., Restart Manager activity, shadow copy deletion, malicious service installation, Windows Installer transactions) and recommending centralized log collection, automated detection rules, and advanced hunting queries to improve detection and investigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
