
Mar 08, 2015 · Basic snort run:8. Find unique events:8. Look for high-priority events8. Extracting files from network traffic:8. P0f8. Memory analysis10. EventIDs: (most of the below are in the security log, service events are in the system log)10. Powershell: (if looking in Security log, must run as admin)10. Windows Net commands10. iptables (/etc/sysconfig ... ................