Skip to content

ryanrios-cyber/windows-server-attack-detection-lab

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

12 Commits
 
 
 
 
 
 
 
 

Repository files navigation

🖥️ Windows Server Attack Detection & Incident Investigation Lab

Overview

This project demonstrates hands-on experience detecting and investigating security incidents within a Windows Server environment using system logs and event analysis.

Tools Used

  • Windows Server
  • Event Viewer
  • Log analysis techniques

Skills Demonstrated

  • Security event analysis
  • Incident detection and investigation
  • Log correlation
  • Threat identification

Project Structure

  • screenshots/ → Event logs and detection evidence
  • logs/ → Sample Windows security logs
  • reports/ → Incident investigation report

Investigation Highlights

  • Identified repeated failed login attempts
  • Detected account lockout events
  • Analyzed suspicious process execution
  • Correlated multiple log sources to identify attack pattern

Outcome

Successfully investigated simulated attack activity, demonstrating real-world incident response and Windows security monitoring skills.

Key Takeaway

This project highlights the ability to monitor Windows environments, detect suspicious activity, and perform structured incident investigations using system-level logs.

About

Hands-on Windows Server security lab analyzing attack activity and performing incident investigation using system logs and security tools

Topics

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors