Event Log Talks a Lot: Identifying Human-operated Ransomware through Windows Event Logs
ID: 6b0520f4-3470-524f-8b15-3005c3899d20
STIX ID: report--6b0520f4-3470-524f-8b15-3005c3899d20
Feed Name: JPCERT Blog
Threat Score
This JPCERT/CC report examines how Windows Event Logs (Application, Security, System, Setup) can leave identifiable traces when various human-operated ransomware families execute, highlighting specific event IDs and patterns for Conti, Phobos, Midas, BadRabbit, Bisamware and other ransomware variants and recommending investigators include event-log analysis in incident response and attribution efforts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
