
Adversary Emulation w/ Carlos Perez - PSW #789
Security Weekly Podcast Network (Audio)
00:00
How to Configure an Event Log in MSDN
MSDN gives you all of the properties and methods of what you can do here. So if I'm local admin on the machine, which happens way too often still. Here's my log. Microsoft Windows, double my activity operational. Sorry. To clarify, Carla, are you talking if your admin is the attacker or the defender? I see attacker.
Play episode from 55:45
Transcript


