UAL

Shows potential lateral movement to servers with UAL logging (all servers).

File Location:

  • C:\Windows\System32\LogFiles\Sum

Parsing Data

Considerations

Detail_Clients_Output

  • Sever of the UAL logs will be server the clients are connecting to.

  • Artifact will show lateral movement of known compromised account.

  • Shows list of authenticated user names and what they auth'd to.

  • Shows total accesses and last accessed by user and Role GUID.

  • Source IP addresses and client names.

Anti-Forensics

  • Delete logs

  • Logs last for to 3 years

Last updated