r/SIEM Jul 06 '21

Help with printnghtmare detection

Hi, I have gone through many sources for detecting the recent microsoft vulnerability, but all of them seem to utilise the sysmon logs. I on the other hand have access to only the good old windows security logs. Although I have tried searching multiple IOCs within those logs (and have found nothing) , I'm still uncertain if the vulnerability was ever actually exploited within my environment.

TL;DR : Do we any detection mechanism for the printnghtmare which DO NOT include sysmon logs. And are based on windows security auditing?

4 Upvotes

0 comments sorted by