logo

The logs you’ll wish you had configured if (when) you are breached… 

ID: 19c4c089-7a8d-50ce-8998-c7fef87c2b19

STIX ID: report--19c4c089-7a8d-50ce-8998-c7fef87c2b19

Feed Name: Pen Test Partners Blog

Date Published: 2025-10-17

Date Updated: 2026-03-26

Author: Alex Wallace

...
...

This guide outlines five essential logging sources—Windows Event Logs, Sysmon, VPN, AV/EDR, and application logs—and provides practical recommendations on sizing, retention, archiving, monitoring, and SIEM integration to strengthen incident response and forensic visibility. It emphasizes enabling detailed, long-retention logs (especially Security.evtx/System.evtx), deploying Sysmon for granular process/network telemetry, tracking VPN access patterns, actively monitoring AV/EDR events, and recording critical application actions, while advocating centralized logging or forwarding to avoid data loss during investigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.