Logs your SOC can use every day: a quick reference guide
ID: 56968187-a643-5a6d-992d-89490922e55e
STIX ID: report--56968187-a643-5a6d-992d-89490922e55e
Feed Name: Expel Blog
This quick-reference log guide consolidates default and non-default locations and discovery tips for web server access logs (Apache, IIS, Tomcat, JBoss, Nginx), Confluence, Windows Event logs, browser history databases (Chrome, Edge, Firefox, Safari), and Linux logs (auth, syslog, cron, shell histories), intended to help SOC analysts quickly locate and collect forensic artifacts during investigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
