“The consultancy Forela-Security would like to gauge your knowledge of Windows Event Log Analysis.”
You have been presented with the opportunity to work as a junior DFIR consultant for a big consultancy. However, they have provided a technical assessment for you to complete. The consultancy Forela-Security would like to gauge your knowledge of Windows Event Log Analysis. Please analyse and report back on the questions they have asked.
Easy - DFIR
Inside the provided archive, there are some Windows Event Log files:
- When did the cyberjunkie user first successfully log into his computer? (UTC)
Login events are usually stored in the Security log within Windows Event Logs with an Event Code of 4624. By opening the Security.evtx file on Event Viewer, filtering for this specific event code, sorting by ascending timestamp, and searching for the cyberjunkie user, we will find the first login instance of that user:
- The user tampered with firewall settings on the system. Analyze the firewall event logs to find out the Name of the firewall rule added?
There is a .evtx file containing firewall event logs called Windows Firewall-Firewall, let's read that. Knowing that the Event ID 2004 means that A rule was added inside Windows Firewall logs, let's filter the logs using that Event ID and look for events after the user login timestamp. The last log, speaking chronologically, contains the name of the suspicious firewall rule added by cyberjunkie:
- Whats the direction of the firewall rule?
Looking at the General tab > Direction, we can see that direction of the previous firewall rule:
- The user changed audit policy of the computer. Whats the Subcategory of this changed policy?
We need to find logs containing information about changing audit policy. By returning to the Security.evtx logs and filtering for the Event ID 4719 (System audit policy was changed), we will be able to find relevant information about the changed policy:
- The user "cyberjunkie" created a scheduled task. Whats the name of this task?
The Event ID 4698 is related with the creation of a scheduled task. We can filter for events with this ID and find information about the new scheduled task:
- Whats the full path of the file which was scheduled for the task?
Scrolling down the General tab of the same event displayed in the previous question, we can find the full path of the file:
- What are the arguments of the command?
They are right below the <Command> field, inside the <Arguments> tag in the photo above.
- The antivirus running on the system identified a threat and performed actions on it. Which tool was identified as malware by antivirus?
Reading the Windows Defender-Operations logs for events related to the Windows antivirus should show us malware-related logs. By using Event ID 1116 (Microsoft Defender Antivirus has detected malware or other potentially unwanted software.), we can find a pentesting tool detected as malware:
- Whats the full path of the malware which raised the alert?
Looking deeper into this alert, we can find that the file that raised the alert was a .zip file that contained the malware itself:
- What action was taken by the antivirus?
Looking at the logs that came right after the Event ID 1116 log, we can see a log with Event ID 1117 (Microsoft Defender Antivirus has taken action to protect this machine from malware or other potentially unwanted software.) that displays what the antivirus did to the malware:
- The user used Powershell to execute commands. What command was executed by the user?
Using the Event ID 4104 for command execution in the PowerShell logs, we can see the command executed by cyberjunkie.
- We suspect the user deleted some event logs. Which Event log file was cleared?
The System event logs should contain our answer. Looking at events after the cyberjunkie login, we can see that the latest event describes a log file being cleared: