BluSapphire
⌘Ctrlk
BluSapphire
    • Release Notes 6.0
    • 01_Unified Platform Architecture
    • 02_What is OnePlatform?
    • 03_DataStreamer
    • 04_AR2 Agentic AI
    • 05_OneAgent
    • 06_What is SIEMless ?
    • BluSapphire User Interface Login Guide
    • Proof-Of-Concept / Pilot Guide
    • M-SOC_Self Service Portal
    • M-SOC | Architecture & Workflow
    • 01_List of Supported Log Sources
    • 02_Average LogSize by LogSource
    • 03_Log Forwarding Guide
    • 04_Mirror / SPAN port configuration
    • 99_retired
    • Categories
    • Active Defence (Deception)
    • Auth (IDAM)
    • Alert Data
    • Cloud AWS
    • Cloud AWS
    • DHCP
    • Email Gateway Security
    • Endpoint Detection
    • Endpoint Protection
    • Linux
    • Linux
    • Load Balancers (LB)
    • NGFW (Firewalls)
    • Network Access Control
    • Windows
    • Windows
    • Web Security Gateway
    • Web Security Gateway
    • Wireless Access Controllers
    • 01_Introduction
    • 02_Unified Cyber Defense Platform
    • 03_The Stack
    • 04_Features and capabilities
    • 05_Operations
    • 06_Architecture
    • 07_Integration
    • 08_Use cases
    • 09_CaseHub
    • 10_Active-Defense-Services
    • 11_1 Data-Pipeline-Manager (DPM)
    • 13_MITRE ATT&CK
  • 16_Best Practices
    • Windows Logging Recommendations
    • Lateral Movement Logging Recommendations
    • Best Data Sources for Detection
    • Cloud Incident Readiness
  • 17_Threat Hunt
  • 19_Product Videos
  • 20_M-SOC_Self Service Portal
  • Customer Self Service Portal
  • Appendix A
  • 21_Incident Response
  • 22_Release 6
Powered by GitBook
For the complete documentation index, see llms.txt. This page is also available as Markdown.

16_Best Practices

Windows Logging RecommendationsLateral Movement Logging RecommendationsBest Data Sources for DetectionCloud Incident Readiness
PreviousRules mapping - MITRE ATT&CKNextWindows Logging Recommendations