Japan Computer Emergency Response Team Coordination Center (JPCERT/CC) Tool Analysis Result Sheet and Detecting Lateral Movement through Tracking Event Logs

Absolutely love this resource 💙
Just came across this gem from JPCERT 👉https://lnkd.in/ew3wG6DN
It documents the forensic artifacts left behind when tools typically used for lateral movement or credential dumping are executed.
It has dedicated sections for
➡️ Artifacts left by the threat actor (file writes, registry changes, USN Journal entries)
➡️ Event logs across Sysmon, Security, BITS-Client, etc.
➡️ Source and destination host activity
➡️ Even has a packet capture session flow for some of those tools🤯
Now, yeah… it’s a bit old. But from what I’ve seen, the artifacts it references still hold up 💪 Most of this telemetry hasn’t changed.
It’s a goldmine if you’re doing:
• Threat hunting
• DFIR
• Lab-based TTP testing
• Detection rule development
One of the better reference sheets I’ve seen in a while. Bookmark it. Use it. Share it.
- Detecting Lateral Movement through Tracking Event Logs – https://www.jpcert.or.jp/english/pub/sr/ir_research.html