ISC StormCast for Wednesday, September 18th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 18 September 2019
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, September 18th, 2019 edition of the Sansonet Storm Center's Stormcast. |
| 0:07.9 | My name is Johannes Ulrich, and I'm recording from Stockholm, Germany. |
| 0:13.2 | One way an attacker is able to hide their activity is by either stopping or manipulating system logs. This of course is also possible on |
| 0:24.1 | Windows and Rob looked in today's diary into how to figure out if your Windows event logs have |
| 0:32.0 | been manipulated. One way to do this is to look for gaps in the log ID sequence, which should be sequential, |
| 0:40.3 | but if someone removed log entries, then of course you will find gaps. |
| 0:45.3 | Now, you can do this via the GUI tools that sort of come with Windows, but that's a very labor-intensive |
| 0:51.3 | process, in particular, since it takes two or three mouse clicks for |
| 0:55.5 | each individual log invent to actually get to the ID that you need to compare. |
| 1:01.4 | So he wrote a PowerShell script to accomplish this, and you can use this to verify your logs. |
| 1:08.6 | If you're interested, you can download the script from Rob's GitHub repository. |
| 1:14.4 | Now, he warns that the script isn't very fast. |
| 1:17.0 | It took him about three minutes to load the logs into a variable in the script. |
| 1:23.6 | So may take a little bit longer on a busy server. |
| 1:27.3 | But yeah, let him know how it works and if you find any interesting gaps in your logs. |
| 1:33.3 | And back in 2013, independent security evaluators, Baltimore Security Consulting Company, took a look at various small office, home office, so Soho |
| 1:48.1 | routers and NASDA devices. And well, back in 2013, they found 52 vulnerabilities in them. |
| 1:55.0 | So no real big surprise to anybody listening to this podcast. But recently they actually redid the study. |
| 2:04.1 | They took, again, 13 different routers and NAS devices. |
| 2:08.8 | They're typically used sort of in these smaller networks. |
| 2:12.3 | And, well, no, it didn't get better. |
| 2:14.7 | And that's in line with other studies that I've talked about |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

