thomaschristoforidis-hash/windows-event-log-investigation

GitHub: thomaschristoforidis-hash/windows-event-log-investigation

一个面向初级 SOC 分析师的 Windows 安全事件日志调查实战实验室,涵盖关键 Event ID 分析、登录类型解读和时间线构建。

Stars: 0 | Forks: 0

# Windows 事件日志调查实验室 面向 SOC 分析师技能提升的 Windows 安全事件日志分析实战。 ## 概述 本仓库记录了专注于 Windows 安全日志的实战调查工作——这是几乎所有 Windows 相关 SOC 调查中使用的核心原生遥测数据源。 ## 包含内容 | 文件 | 描述 | |------|-------------| | `Windows_Event_Log_Lab_Report.docx` | 作品集实验报告(Word) | | `Windows_Event_Log_Lab_Report.md` | Markdown 格式的同名报告 | | `Windows_Event_Log_Lab_Guide.md` | 分步实践指南 | ## 展示技能 - 筛选和浏览 Windows Event Viewer - 分析关键 Event ID(4624、4625、4688、4720、4672、1102 等) - 解读 Logon Type - 审查账户管理事件 - 构建简单的调查时间线 - 与 Sysmon 和 SIEM 视图进行关联 ## 相关实验室 补充了 **Sysmon**、**Active Directory**、**Wazuh SIEM** 和 **Wireshark** 家庭实验室。 ## 作者 **Thomas Christoforidis** 有志成为初级 SOC 分析师 / 网络安全分析师 澳大利亚墨尔本
标签:Terraform 安全, Windows事件日志, 安全培训, 安全运营中心, 网络映射, 防御加固