How Logging Strategies Can Affect Cyber Investigations w/ Kiersten & James
ID: bdcbca6a-f0bc-54cc-bd0e-1a2cf1e1217e
STIX ID: report--bdcbca6a-f0bc-54cc-bd0e-1a2cf1e1217e
Feed Name: Black Hills Infosec Blog
This webinar transcript reviews how Windows logging choices (default auditing, enhanced/advanced audit policies, and Sysmon) impact detection and investigation capability. Through lab demonstrations—a password spray and a malicious download that escalates to TrustedInstaller—the presenters show which logs capture each activity, the complementary value of multiple telemetry sources, and common gaps. They introduce Audit Inspector, a utility that inventories, enforces, and reports audit/Sysmon configurations to reduce logging drift and blind spots across an environment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
