16.07.2019 16:03
Topinambour & Windows event logs
TL;DR:
- Block outgoing SMB traffic if you can.
- Hunt or Monitor for event ID 106 in "Microsoft-Windows-TaskScheduler%4Operational.evtx".
- Think about enabling "Audit Process creation" in "Security.evtx" and command line logging.
- Hunt or monitor for event ID 4688 in "Security.evtx".