Nenhuma Descrição

appendix-c-production-samples.log 1.6KB

12345678910111213141516171819202122232425262728
  1. # Appendix C1-C3 - production-style sample logs
  2. # C1-01 candidate impossible travel (FortiGate VPN success with geo context fields)
  3. date=2026-03-09 time=10:31:00 devname="FGT80F-Branch01" devid="FGT80FTK20000001" eventtime=1773081060 vd="root" logid="0101037135" type="event" subtype="vpn" tunneltype="ssl" action="ssl-login-success" user="analyst01" srcip=203.0.113.71 previous_country=TH current_country=US
  4. # C1-01 confirmed impossible travel from SOC Integrator correlation
  5. soc_event=correlation event_type=c1_impossible_travel user="analyst01" src_ip=203.0.113.71 prev_ip=203.0.113.11 prev_country=TH current_country=US distance_km=13890 travel_minutes=18
  6. # C2-01 privileged account auth success
  7. {"win":{"system":{"eventID":"4624"},"eventdata":{"targetUserName":"admin.soc","logonType":"10"}}}
  8. # C2-02 dormant account activation
  9. {"win":{"system":{"eventID":"4624"},"eventdata":{"targetUserName":"legacy_user01","logonType":"2"}}}
  10. # C2-03 service account remote interactive logon
  11. {"win":{"system":{"eventID":"4624"},"eventdata":{"targetUserName":"svc_dbbackup$","logonType":"10"}}}
  12. # C2-04 privilege escalation via local group change
  13. {"win":{"system":{"eventID":"4732"},"eventdata":{"targetUserName":"john.ops","groupName":"Administrators"}}}
  14. # C3-01 lateral movement indicator (RDP type 10)
  15. {"win":{"system":{"eventID":"4624"},"eventdata":{"targetUserName":"helpdesk01","logonType":"10"}}}
  16. # C3-02 lateral movement indicator (SMB type 3)
  17. {"win":{"system":{"eventID":"4624"},"eventdata":{"targetUserName":"helpdesk01","logonType":"3"}}}
  18. # C3-03 admin account moving laterally
  19. {"win":{"system":{"eventID":"4624"},"eventdata":{"targetUserName":"admin-core","logonType":"3"}}}