logo

Event Log Talks a Lot: Identifying Human-operated Ransomware through Windows Event Logs

ID: 6b0520f4-3470-524f-8b15-3005c3899d20

STIX ID: report--6b0520f4-3470-524f-8b15-3005c3899d20

Feed Name: JPCERT Blog

Threat Score
70/100

Date Published: 2024-09-30

Date Updated: 2026-04-19

Author: JPCERT/CC

...
...

This JPCERT/CC report examines how Windows Event Logs (Application, Security, System, Setup) can leave identifiable traces when various human-operated ransomware families execute, highlighting specific event IDs and patterns for Conti, Phobos, Midas, BadRabbit, Bisamware and other ransomware variants and recommending investigators include event-log analysis in incident response and attribution efforts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.