logo

How Logging Strategies Can Affect Cyber Investigations w/ Kiersten & James 

ID: bdcbca6a-f0bc-54cc-bd0e-1a2cf1e1217e

STIX ID: report--bdcbca6a-f0bc-54cc-bd0e-1a2cf1e1217e

Feed Name: Black Hills Infosec Blog

Date Published: 2024-09-23

Date Updated: 2026-04-27

Author: BHIS

...
...

This webinar transcript reviews how Windows logging choices (default auditing, enhanced/advanced audit policies, and Sysmon) impact detection and investigation capability. Through lab demonstrations—a password spray and a malicious download that escalates to TrustedInstaller—the presenters show which logs capture each activity, the complementary value of multiple telemetry sources, and common gaps. They introduce Audit Inspector, a utility that inventories, enforces, and reports audit/Sysmon configurations to reduce logging drift and blind spots across an environment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.