You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardexpand all lines: Identification.md
+1-21
Original file line number
Diff line number
Diff line change
@@ -3,25 +3,5 @@
3
3
- What is the oldest event recorded? Is it at least as old as policy requires?
4
4
- Which Event IDs can be filtered out, having no value to the investigation?
5
5
- Hopefully you can come to investigate the event log with some key times/activities in mind to act as threads to pull. Focus on those areas of the timeline and spread out.
6
-
7
-
#### Security
8
-
Note any of these Event IDs
9
-
- 1102 events present (log cleared)
10
-
11
-
#### System
12
-
Note any of these Event IDs
13
-
```
14
-
12,13,27,33,42,105,107,1074,7045
15
-
```
16
-
17
-
- 12 (The operating system started at system time xxxx)
18
-
- 13 (The operating system is shutting down at system time xxxx)
19
-
- 27 (Network link is disconnected)
20
-
- 33 (Network link has been established)
21
-
- 41 (The system has rebooted without cleanly shutting down first)
22
-
- 42 (The system is entering sleep.)
23
-
- 105 (Power source change.) Could be a laptop plugging/unplugging power supply.
24
-
- 107 (The system has resumed from sleep.)
25
-
- 1074 (Power off intiated OR initiated the restart of computer)
26
-
- 7045 (A service was installed in the system.)
6
+
- Filter according to [Notable-Event-IDs](Notable-Event-IDs.md)
0 commit comments