The rise in ransomware attacks and third-party breach notifications has contributed to reducing the global mean time to detection (MTTD). So, adversary dwell time is likely much higher than perceived. We must also consider the "unknowns unknowns" that allow attackers to lurk casually on our networks like silent ghosts. In this talk, we will look at a blue team tactic for Microsoft Windows environments that will help reduce the dwell time of ghouls feeding on our sensitive data and the ghosts haunting our networks. A demo at the end will showcase one way to operationalize the information presented using a custom tool.