Index
As this ebook edition doesn't have fixed pagination, the page numbers below are hyperlinked for reference only, based on the printed edition of this book.
A
AbuseIPDB 150, 250
URL 251
used, for investigating suspicious inbound IPs 251, 252
accessed URL (cs-uri) field 184
account and group management tracking 73
account creation, tracking 74, 75
account deletion, tracking 74, 75
adding, to security groups 75-77
change activities, tracking 74, 75
account login tracking logs 59
failed logins, tracking 67-71
logon sessions, tracking 66, 67
successful administrator logins, tracking 64, 65
successful logins, tracking 62-64
Windows accounts 60
anti-debug techniques 269
ANY.RUN sandbox 22, 256
for file analysis 24, 25
URL 24
application event log types 51
application layer DoS attacks 168
APT3 group 119
attacker techniques
to evade email security detection 10-12
Autoruns 255, 258,...