Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

1 Commit
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

πŸ›‘οΈ Windows Audited Events Analysis Lab (SOC Investigation)

Field Focus Tool Level MITRE Status


πŸ‘©πŸ½β€πŸ’» Author

Mozella L. McCoy-Flowers Cybersecurity & Digital Forensics | SOC Analyst Path


🎯 Project Overview

This project simulates a Security Operations Center (SOC) investigation using Windows Event Viewer to analyze audited security events. The focus is on identifying privileged logon activity, correlating authentication events, and determining whether activity is legitimate or suspicious.


🚨 Simulated Incident Scenario

A Windows endpoint generated a privileged logon event (Event ID 4672).

As a SOC analyst, the objective is to:

  • Identify the event
  • Analyze account activity
  • Correlate authentication logs
  • Determine if the behavior is suspicious

🧰 Tools & Environment

  • Windows Virtual Machine
  • Event Viewer
  • Windows Security Logs

🧠 Skills Demonstrated

  • πŸ” Log Analysis & Event Investigation
  • πŸ” Privileged Access Monitoring
  • πŸ”— Event Correlation & Timeline Analysis
  • πŸ›‘οΈ Host-Based Threat Detection
  • πŸ“Š SOC Triage Methodology

🧬 MITRE ATT&CK Mapping

Technique Description
T1078 Valid Accounts
T1068 Privilege Escalation

πŸš€ Investigation Walkthrough (SOC Analysis)


πŸ” Opening Event Viewer

Event Viewer

πŸ“Œ What This Shows

The Event Viewer interface, which provides access to system and security logs on a Windows endpoint.

🧠 Why It Matters

Event Viewer is the primary tool used by analysts to investigate host-based activity and identify potential security events.

πŸ› οΈ Analyst Interpretation

A SOC analyst begins investigations by accessing Event Viewer to establish visibility into system activity. This step confirms access to the endpoint’s logging infrastructure and ensures logs are available for analysis.

🚨 Security Insight

If logging is disabled or inaccessible, it may indicate:

  • Log tampering
  • Defense evasion techniques
  • Misconfigured audit policies

πŸ” Navigating to Security Logs

Security Logs

πŸ“Œ What This Shows

Navigation to Windows Logs β†’ Security, where audited events are stored.

🧠 Why It Matters

The Security log contains critical data related to:

  • Authentication attempts
  • Privilege usage
  • Account activity

πŸ› οΈ Analyst Interpretation

An analyst targets the Security log to begin reviewing authentication and access-related events. This is the primary data source for identifying suspicious user behavior.

🚨 Security Insight

A lack of expected events or unusual gaps in logging may indicate:

  • Audit policy misconfiguration
  • Log deletion
  • Potential attacker activity

πŸ” Reviewing Security Log Entries

Security Log

πŸ“Œ What This Shows

A list of security events with key attributes such as Event ID, timestamps, and sources.

🧠 Why It Matters

This dataset represents all recorded security-relevant activity on the system.

πŸ› οΈ Analyst Interpretation

Analysts scan logs for high-value Event IDs and anomalies. They prioritize:

  • Authentication events
  • Privilege-related activity
  • Unusual patterns or spikes

🚨 Security Insight

Large volumes of failed logins or irregular patterns may indicate:

  • Brute-force attacks
  • Credential stuffing
  • Unauthorized access attempts

πŸ” Identifying Privileged Logon Activity (Event ID 4672)

Event 4672

πŸ“Œ What This Shows

Event ID 4672, indicating that special privileges were assigned during a successful logon.

🧠 Why It Matters

Privileged logons grant elevated access and are high-value targets for attackers.

πŸ› οΈ Analyst Interpretation

A SOC analyst correlates Event ID 4672 with Event ID 4624 to validate the session.

Key steps:

  • Match account name
  • Match Logon ID
  • Review logon type
  • Analyze timestamp sequence

🚨 Security Insight

Unexpected privileged logons may indicate:

  • Credential compromise
  • Privilege escalation
  • Lateral movement

πŸ” Analyzing Event Details (General View)

Event General

πŸ“Œ What This Shows

The General tab confirming that elevated privileges were assigned during logon.

🧠 Why It Matters

This verifies the nature of the event and confirms it is security-relevant.

πŸ› οΈ Analyst Interpretation

Analysts validate:

  • Whether the account should have elevated privileges
  • Whether the event aligns with expected activity

🚨 Security Insight

Unexpected privilege assignments may indicate:

  • Misuse of admin accounts
  • Unauthorized access

πŸ” Deep Dive into Event Metadata

Event Details

πŸ“Œ What This Shows

Detailed event metadata including account name, SID, and Logon ID.

🧠 Why It Matters

This information enables correlation and forensic analysis.

πŸ› οΈ Analyst Interpretation

Analysts use:

  • Logon ID to track sessions across events
  • SID to uniquely identify accounts
  • Metadata to validate activity

🚨 Security Insight

Unknown or suspicious account identifiers may indicate:

  • Rogue accounts
  • Persistence mechanisms
  • Unauthorized access

πŸ” Filtering Security Logs

Filter Logs

πŸ“Œ What This Shows

The use of filtering to isolate specific Event IDs.

🧠 Why It Matters

Security logs are large; filtering improves efficiency and accuracy.

πŸ› οΈ Analyst Interpretation

Analysts filter for:

  • 4672 β†’ Privileged logon
  • 4624 β†’ Successful logon
  • 4625 β†’ Failed logon

This allows targeted investigation.

🚨 Security Insight

Failure to filter effectively may result in:

  • Missed threats
  • Slower response times

πŸ” Reviewing Filtered Results

Filtered Results

πŸ“Œ What This Shows

A refined list of relevant security events after filtering.

🧠 Why It Matters

Reduces noise and highlights actionable data.

πŸ› οΈ Analyst Interpretation

Analysts review filtered results to:

  • Identify patterns
  • Detect anomalies
  • Prioritize investigation

🚨 Security Insight

Clusters of suspicious events may indicate:

  • Ongoing attacks
  • Automated intrusion attempts

πŸ” Correlating Authentication Events

Correlation Correlation

πŸ“Œ What This Shows

This view displays multiple authentication-related events within the Windows Security log, including:

  • 4625 β†’ Failed logon attempts (Audit Failure)
  • 4624 β†’ Successful logon
  • 4672 β†’ Privileged logon

The screenshot highlights Event ID 4625, indicating unsuccessful login attempts.


🧠 Why It Matters

Authentication event correlation is critical for identifying attack patterns.

By analyzing sequences of events, analysts can detect:

  • Brute-force attacks
  • Credential stuffing
  • Unauthorized access attempts

πŸ› οΈ Analyst Interpretation

A SOC analyst would correlate these events to reconstruct a timeline:

  1. Multiple 4625 events β†’ Repeated failed login attempts
  2. 4624 event β†’ Successful login after failures
  3. 4672 event β†’ Privileged access assigned

Key analysis steps:

  • Compare timestamps to identify rapid login attempts
  • Match account names across events
  • Use Logon ID to link sessions
  • Determine logon type (remote, local, service)

🚨 Security Insight

This pattern is a strong indicator of:

  • Brute-force attack success
  • Credential compromise
  • Unauthorized privilege escalation

⚠️ If failed logons (4625) are immediately followed by a successful privileged logon (4672), this should be treated as a high-priority security alert.


🎯 SOC Detection Insight (Advanced)

In a real SOC environment, this pattern would trigger:

  • SIEM alerts (Splunk, Sentinel, etc.)

  • Automated detection rules such as:

    • β€œMultiple failed logins followed by success”
    • β€œPrivileged logon after authentication anomalies”

This type of behavior is commonly mapped to:

  • MITRE ATT&CK T1110 (Brute Force)
  • MITRE ATT&CK T1078 (Valid Accounts)

🧠 Interview-Ready Explanation

β€œI identified multiple failed authentication attempts (Event ID 4625) followed by a successful login (4624) and a privileged logon (4672). This pattern is consistent with a potential brute-force attack leading to credential compromise and elevated access.”


πŸ” Investigation Context

Final View

πŸ“Œ What This Shows

A complete view of the investigation within Event Viewer.

🧠 Why It Matters

Represents the full SOC workflow from detection to analysis.

πŸ› οΈ Analyst Interpretation

Analysts combine:

  • Log review
  • Filtering
  • Correlation to reach a conclusion.

🚨 Security Insight

Failure to correlate events may result in:

  • Misinterpretation
  • Missed indicators of compromise

πŸ”Ž Findings

  • Identified Event ID 4672 indicating privileged logon
  • Verified privilege assignment through event details
  • Used filtering to isolate relevant logs
  • Correlated authentication events for context
  • Applied SOC investigation methodology

πŸ›‘οΈ Incident Response Relevance

This lab demonstrates how analysts:

  • Monitor endpoint logs
  • Detect privilege escalation
  • Investigate authentication anomalies
  • Use logs as forensic evidence

🧠 Security+ / CySA+ Takeaways

  • Security logs are the primary source of audited events
  • Event ID 4672 indicates privileged access
  • Event correlation is essential
  • Filtering improves efficiency
  • Logs provide evidence, not conclusions

πŸ’Ό How This Applies to Cybersecurity Roles

This project demonstrates skills used by:

  • SOC Analysts
  • Incident Responders
  • Threat Analysts

Used to detect:

  • Credential compromise
  • Privilege escalation
  • Unauthorized access

πŸ“‚ Repository Structure

windows-audited-events-lab/
β”‚
β”œβ”€β”€ README.md
β”œβ”€β”€ incident-report.md
β”œβ”€β”€ cysaplus-takeaways.md
└── /screenshots

🏁 Final Thoughts

This project demonstrates the ability to analyze Windows security logs, identify privileged activity, and apply structured SOC investigation techniques.

Understanding audited events is a foundational cybersecurity skill and essential for detecting real-world threats.

πŸ“„ Project Documentation

Releases

Packages

Contributors