Date Author Title
2023-08-31Guy BruneauPotential Weaponizing of Honeypot Logs [Guest Diary]
2021-12-23Johannes Ullrichlog4shell and cloud provider internal meta data services (IMDS)
2021-09-11Guy BruneauShipping to Elasticsearch Microsoft DNS Logs
2021-03-12Guy BruneauMicrosoft DHCP Logs Shipped to ELK
2020-02-12Rob VandenBrinkMarch Patch Tuesday is Coming - the LDAP Changes will Change Your Life!
2019-09-17Rob VandenBrinkInvestigating Gaps in your Windows Event Logs
2018-01-07Guy BruneauSSH Scans by Clients Types
2016-08-29Russ McReeRecommended Reading: Intrusion Detection Using Indicators of Compromise Based on Best Practices and Windows Event Logs
2014-09-27Guy BruneauWhat has Bash and Heartbleed Taught Us?
2014-08-15Tom WebbAppLocker Event Logs with OSSEC 2.8
2014-01-04Tom WebbMonitoring Windows Networks Using Syslog (Part One)
2013-02-28Daniel WesemannParsing Windows Eventlogs in Powershell
2010-03-10Rob VandenBrinkWhat's My Firewall Telling Me? (Part 4)
2010-02-23Mark HofmanWhat is your firewall telling you and what is TCP249?
2009-04-16Adrien de BeaupreStrange Windows Event Log entry