Back to all postsTag 

#windows-event-logs
2 articles

Tutorials
NTLM vs Kerberos: How to Tell Which One Your Logs Are Showing You
NTLM vs Kerberos for SOC analysts: the 4624, 4776 and 4769 fields that name the protocol, why Windows falls back to NTLM, and queries that catch a downgrade.

Tutorials
How to Read Windows Event Logs: A SOC Analyst Guide
How to read Windows event logs in Event Viewer: pick the right channel, decode the XML view, and triage the Security events analysts see every shift.