Intrusion Detection with Windows Event ID's

Date posted: 2016-09-13
Last updated: 2026-10-04

The best paper I have read on building Indicators of Compromise (IOCs) with Windows Event IDs, plus a SANS series on Windows event logs for forensics.

This paper is the best I have ever read on how to build IOCs (Indicators of Compromise) with Windows Event IDs. I highly recommend you read it: it contains very useful information and some very interesting behavioral examples of attacker activity. If you are looking to enhance detection in your core network, this is the document!

Virus signatures, IP addresses and domains alone are not enough to detect an intrusion. Windows event logs record what actually happens on a system, and you can turn specific Event IDs into Indicators of Compromise for faster incident response and forensic analysis.

Intrusion Detection Using Indicators of Compromise Based on Best Practices and Windows Event Logs

This is a paper by María del Carmen Prudente Tixteco, Lidia Prudente Tixteco, Gabriel Sánchez Pérez and Linda Karina Toscano Medina (keywords: indicators of compromise; windows event logs; intrusion detection), for the Eleventh International Conference on Internet Monitoring and Protection (ICIMP 2016).

IOCs can be generated using Windows event logs for intrusion detection, improving Incident Response (IR) and forensic analysis processes.

In short, the authors explain that attacks have become more sophisticated, and that the usual IOCs (virus signatures, IP addresses, URLs and domains) are not sufficient to detect an intrusion or malicious activity. Windows event logs register the activities on a Windows system, which makes them valuable for forensic analysis. The paper presents a procedure to generate IOCs from Windows event logs, for a more efficient diagnosis during incident response.

The paper is available from ThinkMind, and you can download the PDF directly: https://www.thinkmind.org/download.php?articleid=icimp_2016_2_20_30032.

Windows Events log for IR/Forensics, Part 1

The SANS Internet Storm Center Handler's Diary runs a series "Windows Events log for IR/Forensics":

In the time of incidents, Windows Event logs provide a plenty of useful information for the Incident responder.

Because Windows can generate thousands of events in a few minutes, part 1 lists some of the most useful events for forensics and incident response, and the follow-up explains how to search for them with PowerShell. Read the full post (part 1) here: Windows Events log for IR/Forensics, Part 1.

Learn how to use grep for forensic log parsing and analysis on Windows Server IIS. And make sure you have the basics covered: 4 important security measures for Windows Server & IIS.

Source: found via cyber-ir.com (Wayback Machine).

I write these posts in my spare time, based on real problems from my day job as a sysadmin. If this one saved you some debugging time, a small donation is much appreciated. Thanks! 🙏

Leave a Comment