{"id":363,"date":"2024-12-06T20:32:28","date_gmt":"2024-12-06T20:32:28","guid":{"rendered":"https:\/\/letsdefend.ch\/?p=363"},"modified":"2024-12-06T20:36:24","modified_gmt":"2024-12-06T20:36:24","slug":"rapid-eventlog-analyse","status":"publish","type":"post","link":"https:\/\/letsdefend.ch\/index.php\/2024\/12\/06\/rapid-eventlog-analyse\/","title":{"rendered":"Rapid Eventlog Analyse \ud83e\udd85"},"content":{"rendered":"\n<p>Auf deinem Windowsrechner haben sich seltsame Dinge zugetragen oder dein Ger\u00e4t ist m\u00f6glicherweise infiziert? Du hast zuwenig Anhaltspunkte um dir einen Reim daraus zu machen wie das ganze passiert sein k\u00f6nnte, oder was \u00fcberhaupt genau los ist?<\/p>\n\n\n\n<p>Mit dem Tool <strong>&#171;<a href=\"https:\/\/www.magnetforensics.com\/blog\/magnet-response-new-free-tool-for-ir-investigations\/\">Magnet Response<\/a>&#171;<\/strong> welches kostenlos erh\u00e4ltlich ist, kannst du alle relevanten Artekfakte deines Computers einfach mit wenigen Klicks zusammentragen und auf einem sicheren Medium f\u00fcr eine gr\u00fcndliche Analyse abspeichern. Es wird sogar ein Abbild deines Arbeitsspeichers mitgezogen, was f\u00fcr versiertere IT-Spezialisten ebenfalls wertvoll sein wird.<\/p>\n\n\n\n<p>In den Artefakten sind nun auch alle Windows Eventlogs (*.evtx) enthalten, die mittels dem Tool <strong>&#171;<a href=\"https:\/\/github.com\/Yamato-Security\/hayabusa\">Hayabusa<\/a>&#171;<\/strong> auf verd\u00e4chtige Indikatoren durchsucht werden k\u00f6nnen.<\/p>\n\n\n\n<p>Grundlegend werden bestimmte Stichw\u00f6rter (Patterns in den sogenannten Sigma Rules) in den Logdateien gesucht die als relevant erachtet werden. Somit schaffst du es in wenigen Minuten einen groben \u00dcberblich \u00fcber verd\u00e4chtige Aktivit\u00e4ten zu gewinnen.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"713\" height=\"396\" src=\"https:\/\/letsdefend.ch\/wp-content\/uploads\/2024\/12\/image.png\" alt=\"\" class=\"wp-image-364\" srcset=\"https:\/\/letsdefend.ch\/wp-content\/uploads\/2024\/12\/image.png 713w, https:\/\/letsdefend.ch\/wp-content\/uploads\/2024\/12\/image-300x167.png 300w\" sizes=\"auto, (max-width: 713px) 100vw, 713px\" \/><\/figure>\n\n\n\n<p>Falls du fragen oder Tipps ben\u00f6tigst, schreibe gerne eine Mail an info@letsdefend.ch <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Auf deinem Windowsrechner haben sich seltsame Dinge zugetragen oder dein Ger\u00e4t ist m\u00f6glicherweise infiziert? Du hast zuwenig Anhaltspunkte um dir einen Reim daraus zu machen wie das ganze passiert sein k\u00f6nnte, oder was \u00fcberhaupt genau los ist? Mit dem Tool &#171;Magnet Response&#171; welches kostenlos erh\u00e4ltlich ist, kannst du alle relevanten Artekfakte deines Computers einfach mit [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_themeisle_gutenberg_block_has_review":false,"footnotes":""},"categories":[11],"tags":[],"class_list":["post-363","post","type-post","status-publish","format-standard","hentry","category-level-5"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.0 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Rapid Eventlog Analyse \ud83e\udd85 - \u2694\ufe0f Lets Defend your KMU<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/letsdefend.ch\/index.php\/2024\/12\/06\/rapid-eventlog-analyse\/\" \/>\n<meta property=\"og:locale\" content=\"de_DE\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Rapid Eventlog Analyse \ud83e\udd85 - \u2694\ufe0f Lets Defend your KMU\" \/>\n<meta property=\"og:description\" content=\"Auf deinem Windowsrechner haben sich seltsame Dinge zugetragen oder dein Ger\u00e4t ist m\u00f6glicherweise infiziert? Du hast zuwenig Anhaltspunkte um dir einen Reim daraus zu machen wie das ganze passiert sein k\u00f6nnte, oder was \u00fcberhaupt genau los ist? Mit dem Tool &#171;Magnet Response&#171; welches kostenlos erh\u00e4ltlich ist, kannst du alle relevanten Artekfakte deines Computers einfach mit [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/letsdefend.ch\/index.php\/2024\/12\/06\/rapid-eventlog-analyse\/\" \/>\n<meta property=\"og:site_name\" content=\"\u2694\ufe0f Lets Defend your KMU\" \/>\n<meta property=\"article:published_time\" content=\"2024-12-06T20:32:28+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-12-06T20:36:24+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/letsdefend.ch\/wp-content\/uploads\/2024\/12\/image.png\" \/>\n\t<meta property=\"og:image:width\" content=\"713\" \/>\n\t<meta property=\"og:image:height\" content=\"396\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Verfasst von\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Gesch\u00e4tzte Lesezeit\" \/>\n\t<meta name=\"twitter:data2\" content=\"2\u00a0Minuten\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/letsdefend.ch\/index.php\/2024\/12\/06\/rapid-eventlog-analyse\/\",\"url\":\"https:\/\/letsdefend.ch\/index.php\/2024\/12\/06\/rapid-eventlog-analyse\/\",\"name\":\"Rapid Eventlog Analyse \ud83e\udd85 - \u2694\ufe0f Lets Defend your KMU\",\"isPartOf\":{\"@id\":\"https:\/\/letsdefend.ch\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/letsdefend.ch\/index.php\/2024\/12\/06\/rapid-eventlog-analyse\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/letsdefend.ch\/index.php\/2024\/12\/06\/rapid-eventlog-analyse\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/letsdefend.ch\/wp-content\/uploads\/2024\/12\/image.png\",\"datePublished\":\"2024-12-06T20:32:28+00:00\",\"dateModified\":\"2024-12-06T20:36:24+00:00\",\"author\":{\"@id\":\"https:\/\/letsdefend.ch\/#\/schema\/person\/2d871c6c818adffab5612edd5b6e98a6\"},\"breadcrumb\":{\"@id\":\"https:\/\/letsdefend.ch\/index.php\/2024\/12\/06\/rapid-eventlog-analyse\/#breadcrumb\"},\"inLanguage\":\"de-CH\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/letsdefend.ch\/index.php\/2024\/12\/06\/rapid-eventlog-analyse\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"de-CH\",\"@id\":\"https:\/\/letsdefend.ch\/index.php\/2024\/12\/06\/rapid-eventlog-analyse\/#primaryimage\",\"url\":\"https:\/\/letsdefend.ch\/wp-content\/uploads\/2024\/12\/image.png\",\"contentUrl\":\"https:\/\/letsdefend.ch\/wp-content\/uploads\/2024\/12\/image.png\",\"width\":713,\"height\":396},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/letsdefend.ch\/index.php\/2024\/12\/06\/rapid-eventlog-analyse\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Startseite\",\"item\":\"https:\/\/letsdefend.ch\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Rapid Eventlog Analyse \ud83e\udd85\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/letsdefend.ch\/#website\",\"url\":\"https:\/\/letsdefend.ch\/\",\"name\":\"\u2694\ufe0f Lets Defend your KMU\",\"description\":\"Besch\u00fctze deine Firma vor Cyberangriffen\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/letsdefend.ch\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"de-CH\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/letsdefend.ch\/#\/schema\/person\/2d871c6c818adffab5612edd5b6e98a6\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"de-CH\",\"@id\":\"https:\/\/letsdefend.ch\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/4138dddbb1995429676fe73f759109cffb89530d5795201eb84d6000593045f7?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/4138dddbb1995429676fe73f759109cffb89530d5795201eb84d6000593045f7?s=96&d=mm&r=g\",\"caption\":\"admin\"},\"sameAs\":[\"https:\/\/letsdefend.ch\"],\"url\":\"https:\/\/letsdefend.ch\/index.php\/author\/info_0d01s92g\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Rapid Eventlog Analyse \ud83e\udd85 - \u2694\ufe0f Lets Defend your KMU","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/letsdefend.ch\/index.php\/2024\/12\/06\/rapid-eventlog-analyse\/","og_locale":"de_DE","og_type":"article","og_title":"Rapid Eventlog Analyse \ud83e\udd85 - \u2694\ufe0f Lets Defend your KMU","og_description":"Auf deinem Windowsrechner haben sich seltsame Dinge zugetragen oder dein Ger\u00e4t ist m\u00f6glicherweise infiziert? Du hast zuwenig Anhaltspunkte um dir einen Reim daraus zu machen wie das ganze passiert sein k\u00f6nnte, oder was \u00fcberhaupt genau los ist? Mit dem Tool &#171;Magnet Response&#171; welches kostenlos erh\u00e4ltlich ist, kannst du alle relevanten Artekfakte deines Computers einfach mit [&hellip;]","og_url":"https:\/\/letsdefend.ch\/index.php\/2024\/12\/06\/rapid-eventlog-analyse\/","og_site_name":"\u2694\ufe0f Lets Defend your KMU","article_published_time":"2024-12-06T20:32:28+00:00","article_modified_time":"2024-12-06T20:36:24+00:00","og_image":[{"width":713,"height":396,"url":"https:\/\/letsdefend.ch\/wp-content\/uploads\/2024\/12\/image.png","type":"image\/png"}],"author":"admin","twitter_card":"summary_large_image","twitter_misc":{"Verfasst von":"admin","Gesch\u00e4tzte Lesezeit":"2\u00a0Minuten"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/letsdefend.ch\/index.php\/2024\/12\/06\/rapid-eventlog-analyse\/","url":"https:\/\/letsdefend.ch\/index.php\/2024\/12\/06\/rapid-eventlog-analyse\/","name":"Rapid Eventlog Analyse \ud83e\udd85 - \u2694\ufe0f Lets Defend your KMU","isPartOf":{"@id":"https:\/\/letsdefend.ch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/letsdefend.ch\/index.php\/2024\/12\/06\/rapid-eventlog-analyse\/#primaryimage"},"image":{"@id":"https:\/\/letsdefend.ch\/index.php\/2024\/12\/06\/rapid-eventlog-analyse\/#primaryimage"},"thumbnailUrl":"https:\/\/letsdefend.ch\/wp-content\/uploads\/2024\/12\/image.png","datePublished":"2024-12-06T20:32:28+00:00","dateModified":"2024-12-06T20:36:24+00:00","author":{"@id":"https:\/\/letsdefend.ch\/#\/schema\/person\/2d871c6c818adffab5612edd5b6e98a6"},"breadcrumb":{"@id":"https:\/\/letsdefend.ch\/index.php\/2024\/12\/06\/rapid-eventlog-analyse\/#breadcrumb"},"inLanguage":"de-CH","potentialAction":[{"@type":"ReadAction","target":["https:\/\/letsdefend.ch\/index.php\/2024\/12\/06\/rapid-eventlog-analyse\/"]}]},{"@type":"ImageObject","inLanguage":"de-CH","@id":"https:\/\/letsdefend.ch\/index.php\/2024\/12\/06\/rapid-eventlog-analyse\/#primaryimage","url":"https:\/\/letsdefend.ch\/wp-content\/uploads\/2024\/12\/image.png","contentUrl":"https:\/\/letsdefend.ch\/wp-content\/uploads\/2024\/12\/image.png","width":713,"height":396},{"@type":"BreadcrumbList","@id":"https:\/\/letsdefend.ch\/index.php\/2024\/12\/06\/rapid-eventlog-analyse\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Startseite","item":"https:\/\/letsdefend.ch\/"},{"@type":"ListItem","position":2,"name":"Rapid Eventlog Analyse \ud83e\udd85"}]},{"@type":"WebSite","@id":"https:\/\/letsdefend.ch\/#website","url":"https:\/\/letsdefend.ch\/","name":"\u2694\ufe0f Lets Defend your KMU","description":"Besch\u00fctze deine Firma vor Cyberangriffen","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/letsdefend.ch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"de-CH"},{"@type":"Person","@id":"https:\/\/letsdefend.ch\/#\/schema\/person\/2d871c6c818adffab5612edd5b6e98a6","name":"admin","image":{"@type":"ImageObject","inLanguage":"de-CH","@id":"https:\/\/letsdefend.ch\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/4138dddbb1995429676fe73f759109cffb89530d5795201eb84d6000593045f7?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4138dddbb1995429676fe73f759109cffb89530d5795201eb84d6000593045f7?s=96&d=mm&r=g","caption":"admin"},"sameAs":["https:\/\/letsdefend.ch"],"url":"https:\/\/letsdefend.ch\/index.php\/author\/info_0d01s92g\/"}]}},"_links":{"self":[{"href":"https:\/\/letsdefend.ch\/index.php\/wp-json\/wp\/v2\/posts\/363","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/letsdefend.ch\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/letsdefend.ch\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/letsdefend.ch\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/letsdefend.ch\/index.php\/wp-json\/wp\/v2\/comments?post=363"}],"version-history":[{"count":2,"href":"https:\/\/letsdefend.ch\/index.php\/wp-json\/wp\/v2\/posts\/363\/revisions"}],"predecessor-version":[{"id":367,"href":"https:\/\/letsdefend.ch\/index.php\/wp-json\/wp\/v2\/posts\/363\/revisions\/367"}],"wp:attachment":[{"href":"https:\/\/letsdefend.ch\/index.php\/wp-json\/wp\/v2\/media?parent=363"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/letsdefend.ch\/index.php\/wp-json\/wp\/v2\/categories?post=363"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/letsdefend.ch\/index.php\/wp-json\/wp\/v2\/tags?post=363"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}