logo

JPCERT shares Windows Event Log tips to detect ransomware attacks

ID: 6e63fb14-ceff-5b24-bfdf-56f034be9400

STIX ID: report--6e63fb14-ceff-5b24-bfdf-56f034be9400

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-09-30

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

JPCERT/CC published guidance on using Windows Event Logs (Application, Security, System, Setup) to detect traces of ransomware activity before widespread encryption occurs, listing event IDs and characteristic logs tied to multiple families (e.g., Conti/LockBit variants, Phobos, Midas, BadRabbit, Bisamware) and advising monitoring those logs as part of early detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.