thomaschristoforidis-hash/windows-event-log-investigation
GitHub: thomaschristoforidis-hash/windows-event-log-investigation
一个面向初级 SOC 分析师的 Windows 安全事件日志调查实战实验室,涵盖关键 Event ID 分析、登录类型解读和时间线构建。
Stars: 0 | Forks: 0
# Windows 事件日志调查实验室
面向 SOC 分析师技能提升的 Windows 安全事件日志分析实战。
## 概述
本仓库记录了专注于 Windows 安全日志的实战调查工作——这是几乎所有 Windows 相关 SOC 调查中使用的核心原生遥测数据源。
## 包含内容
| 文件 | 描述 |
|------|-------------|
| `Windows_Event_Log_Lab_Report.docx` | 作品集实验报告(Word) |
| `Windows_Event_Log_Lab_Report.md` | Markdown 格式的同名报告 |
| `Windows_Event_Log_Lab_Guide.md` | 分步实践指南 |
## 展示技能
- 筛选和浏览 Windows Event Viewer
- 分析关键 Event ID(4624、4625、4688、4720、4672、1102 等)
- 解读 Logon Type
- 审查账户管理事件
- 构建简单的调查时间线
- 与 Sysmon 和 SIEM 视图进行关联
## 相关实验室
补充了 **Sysmon**、**Active Directory**、**Wazuh SIEM** 和 **Wireshark** 家庭实验室。
## 作者
**Thomas Christoforidis**
有志成为初级 SOC 分析师 / 网络安全分析师
澳大利亚墨尔本
标签:Terraform 安全, Windows事件日志, 安全培训, 安全运营中心, 网络映射, 防御加固