1 May 2020

Active Directory: Group and Membership Changes – Windows Event IDs, Auditing, Splunk (Bonus: Security Events for Investigation, Audit)

By |2025-05-10T16:53:50-07:00May 1, 2020 - Friday|Security, Technology|

Read: 13 mins.How do you find out who made a change to an Active Directory or Builtin Local Group? Which users were added to or removed from a group? When was a group deleted? In this post, we look at Group and Membership change Event IDs, and explore how to use Splunk to find relevant information to aid in your investigations.

14 Apr 2020

MS Teams: Who Recorded The Meeting? Who Downloaded a Copy of The Recording?

By |2021-05-18T21:30:26-07:00Apr 14, 2020 - Tuesday|Microsoft 365, Security, Technology|

Read: 3 mins.A sensitive, internal meeting was held within Microsoft Teams, and someone had accidentally recorded it. The organizer was extremely unhappy when nobody admitted to it, particularly since any attendee was able to download a copy of the recording. An urgent request to the Office 365 and Information Security teams was put out to investigate. How did we go about in doing so?

27 Aug 2019

Google Chrome: Revoked Web Certificates

By |2023-04-28T23:47:46-07:00Aug 27, 2019 - Tuesday|Security, Technology|

Read: 2 mins.Did you know that Google's Chrome browser trusts the majority of revoked web certificates? While the other major browsers support the industry standard, Google continues to pave its own path at the risk of making users of their popular browser vulnerable to attacks.

Go to Top