UAL
Shows potential lateral movement to servers with UAL logging (all servers).
File Location:
C:\Windows\System32\LogFiles\Sum
Parsing Data
Considerations
Detail_Clients_Output
Sever of the UAL logs will be server the clients are connecting to.
Artifact will show lateral movement of known compromised account.
Shows list of authenticated user names and what they auth'd to.
Shows total accesses and last accessed by user and Role GUID.
Source IP addresses and client names.
Anti-Forensics
Delete logs
Logs last for to 3 years
Last updated