Monitoring Active Directory & Windows: Indications you are Under Attack

No ratings

Presented at InfoSecurityEurope 2019 by

Most attackers will take the path of least resistance when trying to breach your environment. It makes sense that monitoring the common attack paths could result in detecting a potential breach. The issue is that monitoring all of the attack paths can be overwhelming if done manually or even with most solutions. In this session, Derek Melber will guide you through methods and solutions that allow you to focus on indicators that tie back to an attack.Learning Outcomes:The common attack paths for Windows environmentsWhich groups to monitor How logon behaviour can indicate an attackHow to monitor privileged access