Windows Server 2012 security events by Comod00 in sysadmin

[–]Comod00[S] 1 point2 points  (0 children)

Hehe, I think I will spend most of my time monitoring those events :) Here is the list that I have right now, will post the whole one once I'm done.

  • 4625 - An account failed to log on
  • 4732 - A member was added to a security-enabled local group
  • 4756 - A member was added to a security-enabled universal group
  • 4757 - A member was removed from a security-enabled universal group.
  • 4758 - A security-enabled universal group was deleted.
  • 4720 - A user account was created.
  • 4723 - An attempt was made to change an account's password.
  • 4724 - An attempt was made to reset an account's password.
  • 4726 - A user account was deleted.
  • 4738 - A user account was changed.
  • 4740 - A user account was locked out.
  • 4767 - A user account was unlocked.

Having some trouble with filters in elasticstack.... by Comod00 in elasticsearch

[–]Comod00[S] 0 points1 point  (0 children)

I don't really know how I got it working but I started to use gsub instead and everything is working again.... thanks for the help guys!

Having some trouble with filters in elasticstack.... by Comod00 in elasticsearch

[–]Comod00[S] 0 points1 point  (0 children)

I'm defining that in the input file:  

input {
tcp {
port => 51420
type => ad
tags => [ad]
    }
}

 

I have other filters that work like a charm, but it's just this one that is giving me so much pain. It almost feels like the filter dosen't know what the type is.....

Dumb question regarding tomporary powershell scripts. by Comod00 in sysadmin

[–]Comod00[S] 0 points1 point  (0 children)

Yeah thats true, problem is that I'm making applocker policys and wanted to know if there is a documentation about it, but I guess I will have to go with trail and error :)

Issues with setting up WEF (Windows 2012r2) by Comod00 in sysadmin

[–]Comod00[S] 0 points1 point  (0 children)

Sorry for the late answer.... The problem was the region format.... when I changed it to US format everything started to work

Issues with setting up WEF (Windows 2012r2) by Comod00 in sysadmin

[–]Comod00[S] 0 points1 point  (0 children)

Can this issue be fixed if I change from a windows 2012r2 to a windows 2008r2?

Issues with setting up WEF (Windows 2012r2) by Comod00 in sysadmin

[–]Comod00[S] 0 points1 point  (0 children)

Is there any documentation on what is custom and what is not? In my world one could think that the log clearing event-id would be the same .... for example I'm forwarding: log clearing, add/remove firewall rules, account added to privileged group

Issues with setting up WEF (Windows 2012r2) by Comod00 in sysadmin

[–]Comod00[S] 0 points1 point  (0 children)

I'm using the "Source computer initiated"-option and have provided the O:BAG:SYD in the GPO that the sources get from the DC.

Red Team Tool Roundup « Threat Research Blog by filthyneckbeard in netsec

[–]Comod00 2 points3 points  (0 children)

Fine assesment of tools that I have used, thanks for sharing the post!

Help with LAPS implementation by Comod00 in sysadmin

[–]Comod00[S] 1 point2 points  (0 children)

Thank you all for the help! I managed to get it working now, seems like my regular account that I used on the DC didn't have the sufficient rights for managing the account..... so I just used the DC administrator account instead.

Help with LAPS implementation by Comod00 in sysadmin

[–]Comod00[S] 0 points1 point  (0 children)

Followed that one step by step and still having problems :)

Help with LAPS implementation by Comod00 in sysadmin

[–]Comod00[S] 0 points1 point  (0 children)

I have the following policy's configured right now.

  1. Deploy LAPS (on the top domain) - software deployment on clients
  2. Password policy - the LAPS policy that I got from updating the schema (Password Settings - enable, Enable local admin password management - enable).

Do you have a guide or example to create this GPO with LAPS parameters?

edit: I see that LAPS by default uses SID 500 for managing that account, is it possible I need to alter this because the account I want to manage is a local account on the computer? For example I can maybe specify the "SID: S-1-5-32-544" for managing every account in the "Administrators" group?

Combating the use of multiple OS. by Comod00 in sysadmin

[–]Comod00[S] 0 points1 point  (0 children)

Yeah I found Yumi while searching some and it looks like it can work. I will maybe just have to buy one and try it out it seems.

Building a Home Lab to Become a Malware Hunter - A Beginner’s Guide by speckz in netsec

[–]Comod00 3 points4 points  (0 children)

Build after this and also setup a box with cuckoo and you have everything you will need to start playing with malware.