← Back to SOC Analyst - Blue Team Operations

Lesson 3 of 10

Log Analysis - Windows, Linux, Firewall

Windows: Event IDs 4624,4625,4672,4688, 7045 (service install)

Linux: auth.log, syslog, auditd, journalctl

Firewall/Proxy: Suricata EVE JSON, Zeek logs

  • Timeline creation