Log Enumeration T1654
Tactic: Discovery
Adversaries may enumerate system and service logs to find useful data. These logs may highlight various types of valuable insights for an adversary, such as user authentication records (Account Discovery), security or vulnerable software (Software Discovery), or hosts within a compromised network (Remote System Discovery).
Events covered
2 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| Sysmon | Event ID 1 | Process creation |
| Security-Auditing | Event ID 4688 | A new process has been created. |
Authoring guide
These 3 rules share fields, values, and exclusions.
Fields filtered most (12 distinct)
These fields appear most often in rule filters.
Top indicator values (30 distinct)
These values appear most often in rule predicates.
Rules under this technique
These vendors publish rules tagged with this technique.
Splunk 2 rules
- Splunk Authentication Token Exposure in Debug Log
- Windows EventLog Recon Activity Using Log Query Utilities