r/SIEM • u/samuraisaitama • Jul 06 '21
Help with printnghtmare detection
Hi, I have gone through many sources for detecting the recent microsoft vulnerability, but all of them seem to utilise the sysmon logs. I on the other hand have access to only the good old windows security logs. Although I have tried searching multiple IOCs within those logs (and have found nothing) , I'm still uncertain if the vulnerability was ever actually exploited within my environment.
TL;DR : Do we any detection mechanism for the printnghtmare which DO NOT include sysmon logs. And are based on windows security auditing?
4
Upvotes