1
00:00:06,540 --> 00:00:07,890
- So in this segment,

2
00:00:07,890 --> 00:00:11,190
we're gonna take a
closer look at log files.

3
00:00:11,190 --> 00:00:13,350
I love logs, I said that in the lesson

4
00:00:13,350 --> 00:00:14,940
I'm gonna say it again here in this lab.

5
00:00:14,940 --> 00:00:16,140
I absolutely love logs,

6
00:00:16,140 --> 00:00:19,770
because logs are just
a wealth of information

7
00:00:19,770 --> 00:00:22,720
that mining and monitoring
the information generated

8
00:00:23,852 --> 00:00:26,288
by the logs of your hosts connectivity

9
00:00:26,288 --> 00:00:28,200
and digital devices really just offers you

10
00:00:28,200 --> 00:00:32,250
such great information to help
protect your organization.

11
00:00:32,250 --> 00:00:34,470
Now our log data offers clues

12
00:00:34,470 --> 00:00:36,630
about activities that may result

13
00:00:36,630 --> 00:00:40,773
in unexpected and possibly
harmful consequences.

14
00:00:41,700 --> 00:00:45,090
Now, most organizations use their logs

15
00:00:45,090 --> 00:00:47,700
to be looking at at-risk events.

16
00:00:47,700 --> 00:00:51,000
At-risk events include
unauthorized access,

17
00:00:51,000 --> 00:00:55,710
malware data leakage,
and suspicious activity.

18
00:00:55,710 --> 00:00:57,010
But I would suggest to you

19
00:00:57,880 --> 00:00:59,070
that you should also be using your logs

20
00:00:59,070 --> 00:01:02,040
for oversight and for security related

21
00:01:02,040 --> 00:01:04,200
operational activities.

22
00:01:04,200 --> 00:01:06,210
So let's talk about oversight.

23
00:01:06,210 --> 00:01:09,930
Oversight includes reporting
on administrative activity

24
00:01:09,930 --> 00:01:13,170
user management, policy changes,

25
00:01:13,170 --> 00:01:16,860
remote desktop sessions,
configuration changes,

26
00:01:16,860 --> 00:01:18,780
and unexpected access.

27
00:01:18,780 --> 00:01:21,874
Now all of that activity
might be legitimate,

28
00:01:21,874 --> 00:01:24,930
but it also might be questionable.

29
00:01:24,930 --> 00:01:29,250
And then we have security
related operational activities.

30
00:01:29,250 --> 00:01:31,170
Now these are operational activities

31
00:01:31,170 --> 00:01:34,440
which include things like
reporting on patch installation,

32
00:01:34,440 --> 00:01:37,320
software installation, service management,

33
00:01:37,320 --> 00:01:40,230
reboots, bandwidth utilization,

34
00:01:40,230 --> 00:01:44,520
DNS and DHCP traffic, which
at first don't really sound

35
00:01:44,520 --> 00:01:47,793
like they're security
related, but they are right?

36
00:01:49,042 --> 00:01:50,250
Knowing that a patch
actually was installed

37
00:01:51,085 --> 00:01:52,861
perhaps there's something

38
00:01:52,861 --> 00:01:53,694
in the log that says patch installed

39
00:01:53,694 --> 00:01:54,840
but you have to reboot
for it to take effect.

40
00:01:54,840 --> 00:01:56,610
That's very important.

41
00:01:56,610 --> 00:02:00,720
Software installation, should
that software been installed?

42
00:02:00,720 --> 00:02:03,540
Service management, who
maybe is making changes

43
00:02:03,540 --> 00:02:05,850
to some of the services on the device?

44
00:02:05,850 --> 00:02:08,460
Why did the machine reboot?

45
00:02:08,460 --> 00:02:10,260
Bandwidth utilization,

46
00:02:10,260 --> 00:02:13,350
is that out of the
ordinary and that any DNS

47
00:02:13,350 --> 00:02:16,500
or DHCP traffic that's
trying to be resolved?

48
00:02:16,500 --> 00:02:19,530
So our log datas offer
clues about all of this kind

49
00:02:19,530 --> 00:02:23,730
of activity at risk, oversight
and security related.

50
00:02:23,730 --> 00:02:25,560
Let's look at a couple of
different log extracts,

51
00:02:25,560 --> 00:02:27,160
so I can give you some examples.

52
00:02:28,824 --> 00:02:30,540
First up, we're gonna
look at a firewall log.

53
00:02:30,540 --> 00:02:33,480
So our first entry is about a download

54
00:02:33,480 --> 00:02:36,810
and the question really
is legitimate download

55
00:02:36,810 --> 00:02:39,510
or a nefarious activity.

56
00:02:39,510 --> 00:02:43,950
What we're seeing is a
local host, 192.168.1.3

57
00:02:43,950 --> 00:02:48,570
access URL 69.4.231.52,

58
00:02:48,570 --> 00:02:51,660
and we can see that they
actually did a download.

59
00:02:51,660 --> 00:02:54,270
So they went out to a wire shark download,

60
00:02:54,270 --> 00:02:59,270
and they downloaded
Wireshark-win64-1.6.6.exe.

61
00:03:01,020 --> 00:03:04,920
Now, that could be
perfectly legitimate or not,

62
00:03:04,920 --> 00:03:06,630
but don't you wanna know, right?

63
00:03:06,630 --> 00:03:09,362
Wireshark is a packet capture application.

64
00:03:09,362 --> 00:03:11,460
Is there a reason?

65
00:03:11,460 --> 00:03:12,810
Who's at that address?

66
00:03:12,810 --> 00:03:15,750
Who is at 192.168.1.3?

67
00:03:15,750 --> 00:03:18,330
Was it a network admin
who's going to do Wireshark

68
00:03:18,330 --> 00:03:20,220
for some troubleshooting?

69
00:03:20,220 --> 00:03:24,150
Or perhaps is it an insider
who maybe is going to

70
00:03:24,150 --> 00:03:27,630
do something not quite
what we want them to do?

71
00:03:27,630 --> 00:03:30,150
So being able to look at an entry like

72
00:03:30,150 --> 00:03:34,293
this and say legitimate or
nefarious, that's important.

73
00:03:35,370 --> 00:03:37,050
Here's another firewall entry.

74
00:03:37,050 --> 00:03:40,650
And our question this time
is legitimate modification

75
00:03:40,650 --> 00:03:42,210
or rogue action.

76
00:03:42,210 --> 00:03:46,230
What we're looking at here is
we've got a 40 gate firewall.

77
00:03:46,230 --> 00:03:49,620
We can see that our admin
or root user J Miles

78
00:03:49,620 --> 00:03:53,040
has logged in from 10.104.1.103

79
00:03:53,040 --> 00:03:57,390
and made a change to the
IP four firewall policy

80
00:03:57,390 --> 00:03:58,323
from the GUI.

81
00:03:59,250 --> 00:04:02,820
Could be perfectly legitimate or not.

82
00:04:02,820 --> 00:04:04,290
How would you know if it's legitimate?

83
00:04:04,290 --> 00:04:07,710
Well, you could compare it
against your change request.

84
00:04:07,710 --> 00:04:10,230
There should be a change
request for doing that

85
00:04:10,230 --> 00:04:13,410
Firewall change again, could be just fine

86
00:04:13,410 --> 00:04:16,863
or could be a rogue action,
and we really wanna know that.

87
00:04:17,970 --> 00:04:20,520
So this extract is from a Windows log,

88
00:04:20,520 --> 00:04:23,430
and what we're seeing here is the success

89
00:04:23,430 --> 00:04:28,430
of adding a new user Epires
to the domain admin account.

90
00:04:28,980 --> 00:04:32,070
Now, it was added by Gpontes,

91
00:04:32,070 --> 00:04:33,570
Could be a legitimate ad,

92
00:04:33,570 --> 00:04:35,370
you know, that we wanna add somebody

93
00:04:36,376 --> 00:04:37,313
to our domain admins account,

94
00:04:38,224 --> 00:04:42,540
or is this maybe infiltration
or the start of an attack?

95
00:04:42,540 --> 00:04:44,626
So important, right?

96
00:04:44,626 --> 00:04:46,290
This is the domain admins group,

97
00:04:46,290 --> 00:04:49,020
now the group that holds
the keys to the kingdom.

98
00:04:49,020 --> 00:04:52,380
So we see the success
of a user being added,

99
00:04:52,380 --> 00:04:53,670
we wanna question it.

100
00:04:53,670 --> 00:04:57,813
Is this a legitimate ad or
potentially infiltration?

101
00:04:58,770 --> 00:05:02,580
And last, let's look at a
question about data exfiltration.

102
00:05:02,580 --> 00:05:05,430
Are we sending data up to
the cloud appropriately

103
00:05:05,430 --> 00:05:07,020
or is there a problem?

104
00:05:07,020 --> 00:05:09,990
What we're looking at here is connection

105
00:05:09,990 --> 00:05:13,069
to an an outside address,

106
00:05:13,069 --> 00:05:15,420
which happens to be a
a cloud service on 443.

107
00:05:15,420 --> 00:05:18,840
So TLS, so it's all encrypted,

108
00:05:18,840 --> 00:05:21,330
but we can see that a connection was made.

109
00:05:21,330 --> 00:05:25,620
We can see that the duration
was about a minute and a half,

110
00:05:25,620 --> 00:05:30,270
and we can see the amount of
data that would've been sent.

111
00:05:30,270 --> 00:05:33,150
Now again, could be perfectly legitimate

112
00:05:33,150 --> 00:05:34,923
sending data up to the cloud,

113
00:05:35,910 --> 00:05:39,990
or it could be a sign
of data exfiltration.

114
00:05:39,990 --> 00:05:41,310
So in all of these cases,

115
00:05:41,310 --> 00:05:44,100
what we were looking at
was successful actions

116
00:05:44,100 --> 00:05:46,200
could be legit or not,

117
00:05:46,200 --> 00:05:48,550
but we wanna be able
to have this knowledge

118
00:05:49,544 --> 00:05:51,510
use this information to really assess

119
00:05:51,510 --> 00:05:53,763
the security of our organization.

120
00:05:55,380 --> 00:05:57,360
So this is just a a brief example

121
00:05:57,360 --> 00:06:00,777
of some of the great information
you can find in your logs.

122
00:06:00,777 --> 00:06:03,210
You know, things may look normal,

123
00:06:03,210 --> 00:06:06,180
none of these were abnormal activities

124
00:06:06,180 --> 00:06:07,500
in and of itself, right?

125
00:06:07,500 --> 00:06:09,858
None of these things that we looked

126
00:06:09,858 --> 00:06:11,686
at appeared to violate any rules.

127
00:06:11,686 --> 00:06:14,400
There wasn't any denied activity

128
00:06:14,400 --> 00:06:16,590
and all of this was allowed activity,

129
00:06:16,590 --> 00:06:19,380
and could have been perfectly legitimate.

130
00:06:19,380 --> 00:06:21,000
But don't you wanna know?

131
00:06:21,000 --> 00:06:24,660
So using your logs for at risk operational

132
00:06:24,660 --> 00:06:27,970
and oversight, as well
as having good log data

133
00:06:29,282 --> 00:06:31,350
in case you ever have to do
a forensic investigation.

134
00:06:31,350 --> 00:06:35,073
Well, that my friends is a
closer look at the power of logs.
