Open cardosec

Case 3229F7 · Blue team / DFIR · L1 Foundations

Essential Log Sources

Practise as: Explain it
  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Endpoint: Windows Security log, Sysmon (process create, network, image loads), EDR telemetry, PowerShell logs.
  2. Identity: domain controller auth events, Entra ID / Okta sign-in logs, VPN and MFA logs.
  3. Network: firewall, DNS query logs, proxy/web gateway, NetFlow, and Zeek for protocol metadata.
  4. Cloud and SaaS: AWS CloudTrail, Azure Activity, M365 Unified Audit Log; check retention and licensing tiers.
  5. Retention and time sync (NTP, UTC) matter as much as collection; gaps kill investigations.

If the interviewer pushes back

  • You can afford only three log sources for a 500-person company. Which do you pick and why?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.