-
Book Overview & Buying
-
Table Of Contents
-
Feedback & Rating

Effective Threat Investigation for SOC Analysts
By :

As this ebook edition doesn't have fixed pagination, the page numbers below are hyperlinked for reference only, based on the printed edition of this book.
A
URL 251
used, for investigating suspicious inbound IPs 251, 252
accessed URL (cs-uri) field 184
account and group management tracking 73
account creation, tracking 74, 75
account deletion, tracking 74, 75
adding, to security groups 75-77
change activities, tracking 74, 75
account login tracking logs 59
logon sessions, tracking 66, 67
successful administrator logins, tracking 64, 65
successful logins, tracking 62-64
Windows accounts 60
anti-debug techniques 269
URL 24
application event log types 51
application layer DoS attacks 168
APT3 group 119
attacker techniques
Change the font size
Change margin width
Change background colour