QuestionQ321

Logs and Network Forensics

During an after-hours investigation at a healthcare provider in Phoenix, Arizona, analysts examine Security log entries for group-membership changes to determine who initiated access expansion and which account was actually added. When focusing on the event-description fields without modifying the original .evtx, which field specifically identifies the account added to or removed from the group?

  • A Caller User Name
  • B Member ID
  • C First line of the description
  • D Target Account Name
Explanation

The Member ID field contains the security identifier (SID) of the account that was added to or removed from the group. The caller/subject fields identify the account that performed the operation, while the target account field identifies the group being changed.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!