SOURCE Barcelona
BruCON
EuroTrashSecurity Website

SANS Reading Room: EVTX and Windows Event Logging

A new document available in the SANS Reading Room:

This paper will explore Microsoft’s EVTX log format and Windows Event Logging framework. The EVTX data stream and structure will be defined as a basis for the Windows Event Logging framework and log subscription components that can be used to collect and correlate logs in a complex Windows-based environment.

This is a must read if you have to work with Windows environments (collecting and correlating logs). The document is available here.

Leave a Reply

 

 

 

You can use these HTML tags

<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

IMPORTANT! To be able to proceed, you need to solve the following simple math (so we know that you are a human) :-)

What's the sum of 15 and 2 ?
Please leave these two fields as-is: