Summary
In this chapter, we covered a range of topics related to Windows account management and tracking. We began by discussing the different types of Windows accounts and how to track login activities, including successful and failed logins, as well as admin logins. We also explored how to track account activities during a given logon session and determine session length. Finally, we delved into the topic of account and security group management and learned how to track activities such as creation, deletion, changes, and member additions or removals.
In the next chapter, we will investigate suspicious Windows process executions by utilizing Windows logs and gaining knowledge of the common Windows process characteristics and certain characteristics of suspicious processes.