investigation 13
- Remote Login From Different Geolocation
- AntiVirus Alerts Investigation
- IPS/IDS Alerts Investigation
- Web Server & WAF Logs
- IP and Port Scanning
- Network Attacks:DOS Attacks
- Firewall logs Analysis
- Microsoft Events Log Analysis:Windows Account & Group Management Events
- Microsoft Events Log Analysis:Object, Scheduled tasks and Process
- Microsoft Events Log Analysis:Logon And Logoff Events Analysis
- Email Flow and what is the SPF & DKIM
- Phishing and Email Attack Types And Mail gateway Log Analysis
- Investigating Suspicious Outbound Traffic(Proxy Logs)