logo

Building a Detection Foundation: Part 2 - Windows Security Events

ID: bb0fdef5-4c28-5075-b56f-cc696ece7259

STIX ID: report--bb0fdef5-4c28-5075-b56f-cc696ece7259

Feed Name: TrustedSec blog

Date Published: 2026-03-09

Date Updated: 2026-05-01

...
...

This article provides practical guidance for configuring Windows Advanced Audit Policy to build a forensic and detection foundation—covering key events (4624, 4634, 4688, 4672, 4648, scheduled task and service events), how to enable command-line capture and auditpol/registry/GPO examples, and notes on gaps in native logging that will be addressed in later parts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.