Skip to main content
Hackviser Training

Threat Detection with Windows Event Logs

8 sections5 tools

Training Overview

The "Threat Detection with Windows Event Logs" training comprehensively teaches how to analyze event logs in Windows operating systems to detect threats. The training includes the use of Windows Event Viewer, the structure of event logs, and advanced logging techniques with Sysmon. Additionally, it covers threat detection from event logs using tools like evtxecmd, Timeline Explorer, and Get-WinEvent.

What you will learn

  • How to navigate and filter logs using the Windows Event Viewer.
  • How to enhance logging capabilities with Sysmon.
  • How to use command-line tools like EvtxECmd and Get-WinEvent for analysis.
  • How to build timelines of activity using Timeline Explorer.

Tools you will use

  • Windows Event Viewer
  • Sysmon
  • EvtxECmd
  • Timeline Explorer
  • PowerShell

Prerequisites

  • A solid understanding of Windows Fundamentals.
  • Familiarity with common Windows processes and activities.

Who this is for

  • Blue Team members and SOC Analysts.
  • Incident Responders.
  • Windows System Administrators.

Training sections

  1. 1Introduction
  2. 2Event Viewer
  3. 3Components of an Event Log Record
  4. 4Sysmon
  5. 5Analyzing Windows Event Logs with EvtxECmd
  6. 6Timeline Explorer Transfer
  7. 7Get-WinEvent
  8. 8Exam

Continue learning

Practice the topic in a lab or continue with a related Hackviser guide.