This page is a consolidation of all of the items discussed in the Graylog Go 2024 talk From Hidden to Exposed: Advanced Graylog Alerts for Malicious Activity. This is placed here so you can quickly get straight to the individual guides to each section and see more of the research towards each of them.
- NTLM (NTLMv1 –> NTLMv2)
- LDAP Signing (beginning to solve PetitPotam)
- SMB Signing
- Broadcast (LLMNR, mDNS, NetBIOS)
- WPAD
The Bonus content is:
- AD Enumeration Detection
- RC4 (Kerberoast) detections
- Advanced Backups Alerting (Baselining and alerting)
- Advanced (Account) Alerting (Baselining and alerting)
- PhantaByte GPO PowerShell Script for helping to automate remediation
- NetBait Multicast / Broadcast honey pot script