Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.


S. NoDevice TypeThreat Indicators generated
 1.
 
 
        
Windows OS/Windows AD


         
Window Defender
Suspicious Windows Event
Host Login Success / Host Login Failure
Object Access Status
 Host Login
Account Lockout
 Suspicious Service / Process
 Suspicious Process 
 Account Created / Enabled
 Account Deleted / Disabled
 Privilege Change
 Network Logout
 Directory Service Status
 System Time
 Group Policy Object
 Password Change / Reset
 2.    MSSQL   Login Success
 Login Failure
 Application
Object Access Status
 3.Windows IIS Web Exploit
 4. Windows DNS   
Suspicious Port Activity
 Suspicious Domain
 5. Windows DHCP Application
 6. Windows SMTPEmail Info
 7. MS ExchangeEmail Info