Protecting the Evidence in Real-Time with KQL Queries
ID: 14aa548b-9327-5bf5-88e6-165a873f9e4e
STIX ID: report--14aa548b-9327-5bf5-88e6-165a873f9e4e
Feed Name: Detect FYI
Guidance article on preserving Windows forensic evidence using KQL, emphasizing detection of attacker anti-forensic behavior during ransomware’s final stages. It explains that automatic RegBack backups are disabled by default in modern Windows, weighs the benefits of re-enabling RegBack for recovery, and recommends monitoring related registry keys to detect potential tampering early.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
