In looking into compromised systems, often what is needed by incident responders and investigators is not enabled or configured when it comes to logging. To help get system logs properly Enabled and Configured, below are some cheat sheets to help you do logging well and so the needed data we all need is there when we look.
Cheat Sheets to help you in configuring your systems:
This Markdown cheat sheet provides a quick overview of all the Markdown syntax elements. It can’t cover every edge case, so if you need more information about any of these elements, refer to the reference guides for basic syntax and extended syntax. Get Started Cheat Sheet Basic Syntax Extended Syntax Tools Book. The Markdown Guide is a free and open-source reference guide that explains how to use Markdown, the simple and easy-to-use markup language you can use to format virtually any document. Beat Triplebyte's online coding quiz. Get offers from top companies. Annotation Cheat-Sheet for CAP CDS Requirements Each vocabulary in this repository is described by three files: the.xml source file, an auto-generated equivalent.json representation, and a.md Markdown description, also auto-generated from the.xml source.
The Windows Logging Cheat SheetUpdated Feb 2019
The Windows Advanced Logging Cheat SheetUpdated Feb 2019
The Windows HUMIO Logging Cheat Sheet Released June 2018
The Windows Splunk Logging Cheat Sheet Updated Sept 2019
The Windows File Auditing Logging Cheat Sheet Updated Nov 2017
The Windows Registry Auditing Logging Cheat Sheet Updated Aug 2019
The Windows PowerShell Logging Cheat Sheet Updated Sept 2018
The Windows Sysmon Logging Cheat Sheet Updated Jan 2020
MITRE ATT&CK Cheat Sheets
The Windows ATT&CK Logging Cheat Sheet Released Sept 2018
The Windows LOG-MD ATT&CK Cheat Sheet Released Sept 2018
The MITRE ATT&CK Logging Cheat Sheets are available in Excel spreadsheet form on the following Github:
----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
Update Log:
SysmonLCS:Jan 2020 ver 1.1
Fixed GB to Kb on log size
WSplunkLCS:Sept 2019 ver 2.22
Minor code tweaks, conversion
WSysmonLCS:Aug 2019 ver 1.0
Initial release
WRACS:Aug 2019 ver 2.5
Md File Cheat Sheet
Added a few more items
WSLCS:Feb 2019 ver 2.21
Fixed shifted box, cleanup only
Github Readme Cheat Sheet
WLCS:Feb 2018 ver 2.3
Added a couple items from Advanced
Adjust a couple settings
General Clean up
Referenced the Windows Advanced Logging Cheat Sheet
WALCS: Feb 2019 ver 1.2
Updated and added several items
WHLCS:June 2018 ver 1.0
Initial release
WFACS: Oct 2016 ver 1.2
Added a few new locations
WRACS: oct 2016 ver 1.2
Added many autorun keys
Sorted the keys better
WSLCS:Mar 2018 ver 2.1.1
Fixed shifted box, cleanup only
WLCS:Jan 2016 ver 2.0
Added Event code 4720 - New user account created
Changed references to File and Registry auditing to point to the new File and Registry auditing Cheat Sheets
Expanded info on Command Line Logging
WRACS: Jan 2016 ver 1.1
Sort HKLM Keys
Added keys to monitor PowerShell and Command Line log settings
Updated HKCU and USERs.DEFAULT info
Added info about HKCU unable to be set in Security Templates
Added PowerShell script to set HKCU Registry Auditing