In this cybersecurity lab, we investigate Windows 10 Security Event Logs to detect suspicious login activity and brute-force attacks.
This video demonstrates how digital forensic investigators analyze Windows Security Event Logs to identify failed login attempts and suspicious activity using Event IDs. Using tools such as Event Viewer, the tutorial explains how security analysts perform Windows log analysis to detect brute-force attack patterns and investigate authentication activity.
Topics covered in this digital forensics tutorial include:
• Understanding Windows Security Event Logs
• Detecting brute-force login attempts (Event ID 4625)
• Identifying successful login events (Event ID 4624)
• Monitoring process execution events (Event ID 4688)
• Using Windows Event Viewer for security log analysis
• Extracting and analyzing Windows Security logs using EvtxECmd
• Investigating suspicious activity in Windows 10 systems
This cybersecurity lab is useful for students learning digital forensics, incident response, and Windows security monitoring.
#CyberSecurity
#DigitalForensics
#WindowsEventLogs
#EventID4625
#Windows10
#EvtxECmd