7MS #296: WEFFLES - Windows Event Logging Forensic Logging Enhancement Services

Below are show notes for an episode of the 7 Minute Security podcast, a weekly podcast I publish that focuses on topics such as penetration testing, network configuration, blue-teaming and career advice. I welcome you to subscribe in your favorite podcast app so you don't miss an episode!

Intro

WEFFLES are delicious!

WEFFLES stands for Windows Event Logging Forensic Logging Enhancement Services and is Microsoft's cool (and free!) console for responding to incidents and hunting threats. I had a chance to play with it in the lab this week and for the most part, the install of WEFFLES went well, but I had one minor issue that was cleared up easily.

As I went through the MS TechNet article, I wrote a full install write-up on my BPATTY site.

So go gobble up some WEFFLES and let me know how it goes!

Audio