Case 3229F7 · Blue team / DFIR · L1 Foundations
Essential Log Sources
Practise as: Explain it
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- Endpoint: Windows Security log, Sysmon (process create, network, image loads), EDR telemetry, PowerShell logs.
- Identity: domain controller auth events, Entra ID / Okta sign-in logs, VPN and MFA logs.
- Network: firewall, DNS query logs, proxy/web gateway, NetFlow, and Zeek for protocol metadata.
- Cloud and SaaS: AWS CloudTrail, Azure Activity, M365 Unified Audit Log; check retention and licensing tiers.
- Retention and time sync (NTP, UTC) matter as much as collection; gaps kill investigations.
If the interviewer pushes back
- You can afford only three log sources for a 500-person company. Which do you pick and why?
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.