// Nach Log-Kanal
- Alle
- AppLocker
- Aufgabenplanung
- BITS
- Defender
- Directory Service
- NTLM
- PowerShell
- Remote-Zugriff
- Security
- Sysmon
- System
- WMI
// Nach MITRE-Taktik
- Initial Access
- Execution
- Persistence
- Privilege Escalation
- Stealth
- Defense Impairment
- Credential Access
- Discovery
- Lateral Movement
- Collection
- Exfiltration
- Command and Control
- Impact
| ID | Bedeutung | Kanal | Relevanz | MITRE |
|---|---|---|---|---|
| 3 | Netzwerkverbindung | Sysmon | mittel | T1071.001, T1105, T1021.001 |
| 59 | BITS-Auftrag erstellt und Übertragung gestartet | BITS | mittel | T1197, T1105 |
| 4663 | Zugriff auf ein Objekt | Security | mittel | T1555.003, T1005, T1486 |
| 5145 | Detaillierter Zugriff auf Dateifreigabe | Security | hoch | T1021.002, T1570, T1569.002 |
| 5156 | Netzwerkverbindung erlaubt oder blockiert | Security | mittel | T1071, T1021, T1046 |
// Artikel zum Thema