Information to Insights: Intrusion Analysis Methodology
ID: 9865d22a-108d-5897-b3c4-7d3d60307ff4
STIX ID: report--9865d22a-108d-5897-b3c4-7d3d60307ff4
Feed Name: Huntress Blog
This blog outlines practical techniques to transform Windows authentication and RDP telemetry into actionable intrusion insights, focusing on analyzing 4624/4625 events (e.g., NTLM vs Kerberos, substatus codes like 0xC0000064/0xC000006A), aggregating patterns across hosts, pivoting with Logon IDs, and detecting registry credential dumping via related 5145 events. It also details how to investigate RDP lateral movement with 4624 type-10 where available and, when security logs are cleared (1102), by leveraging Terminal Services operational logs (event IDs 25 and 1149). Emphasis is placed on methodology over tooling to reliably distinguish malicious activity from benign noise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
