Log - Lateral Movement - Logging required eventID's ?

Written by Admin | Dec 20, 2016 5:00:00 AM

This is a helper report for the lateral movement report pack and alerting capability that was released a while back.

This will query for the eventID's that are required to trip the alerting and reporting that were released, to make it easier to understand if the required data is available for the content that was published.

https://community.rsa.com/community/products/netwitness/blog/2016/03/09/lateral-movementwindows

Contents:

1 report

8 rules

Imports into Threats - Windows Lateral Movement