logo

Getting Analysis Practice from Windows Event Log Sample Attacks

ID: 828597c9-a1c6-5303-87e2-a913258075df

STIX ID: report--828597c9-a1c6-5303-87e2-a913258075df

Feed Name: TrustedSec blog

Threat Score
10/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

This article walks through analyzing Windows event log samples (Sysmon EVTX) from a public GitHub repository to practice detection of malicious activity—focusing on a lateral movement example that uses malicious named pipes (Sysmon Event ID 18) and related Event ID 1 artifacts such as CurrentDirectory, User, PowerShell command patterns and the invocation of whoami; it demonstrates using Sigma rules and the Windows Event Viewer to identify and investigate these indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.