Rocking your Windows EventID with ELK Stack - SANS DFIR Summit 2016

Опубликовано: 20 Март 2026
на канале: SANS Digital Forensics and Incident Response
7,258
47

We have thousands of possible windows events id, split into 9 categories and 50+ subcategories that logs all actions in a windows machine as login/logoff, process creation, modifications, packet filtering and so on. By default Windows only holds those events for a short period (depends on configurations) which makes some aspects forensics impossible. In our deployment, we used the ELK stack and some custom Python scripts in order to optimize data aggregation into a strucured index. This custom process generates revelant intelligence that can be used for historical analysis and telemetry of those millions of daily events.

In this presentation we will share how to configure your Windows Audit policy, ELK stack to process/archive all information and share some tools to analyze your data based on an infection demo and incident case sample. Rodrigo Ribeiro Montoro (@spookerlabs), Security Researcher, Clavis Security Brazil

Rodrigo Ribeiro Montoro
(@spookerlabs), Security Researcher, Clavis Security Brazil
Rodrigo “Sp0oKeR” Montoro has 15 years experience deploying opensource security software (firewalls, IDS, IPS, HIDS, log management) and hardening systems. Currently he is security researcher/SOC at Clavis. Before that he worked as a senior security administrator at Sucuri, Spiderlabs Researcher where he focuses on IDS/IPS signatures, modsecurity rules, and new detection researches. Author of two patented technologies involving discovery of malicious digital documents and analyzing malicious HTTP traffic. He is currently coordinator and snort evangelist for the Brazilian Snort Community. Rodrigo has spoken at a number of open-source and security conferences (OWASP AppSec, Toorcon (USA), H2HC (São Paulo and Mexico), SecTor (Canada), CNASI, SOURCE Boston & Seatle, ZonCon (Amazon Internal Conference), BSides (Las Vegas e São Paulo), and Blackhat Brazil) and serves as a coordinator for the creation of new snort rules, specifically for Brazilian malware.