Skip to content

Guides tagged

#detection

← Back to all guides
Auditing, Logging & Detection

Windows Event Forwarding for domain controllers

Build a Windows Event Forwarding pipeline for DCs: source-initiated subscriptions, GPO, log access, XPath queries, collector sizing and health checks.

Intermediate
Auditing, Logging & Detection

Active Directory security event IDs: a DC reference

Every AD security event ID worth collecting on domain controllers: logon, Kerberos, NTLM, account, group, directory and AD CS events, with fields to hunt.

Foundation