> For the complete documentation index, see [llms.txt](https://docs.blusapphire.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.blusapphire.io/older-releases/16_best-practices.md).

# 16\_Best Practices

- [Windows Logging Recommendations](https://docs.blusapphire.io/older-releases/16_best-practices/windows-logging-recommendations.md): Windows Event Log Recommendations By Log Source
- [Windows Security Log recommendations](https://docs.blusapphire.io/older-releases/16_best-practices/windows-logging-recommendations/windows-security-log-recommendations.md)
- [Windows General Log Recommendations](https://docs.blusapphire.io/older-releases/16_best-practices/windows-logging-recommendations/windows-general-log-recommendations.md)
- [Windows Advanced Auditing Recommendations](https://docs.blusapphire.io/older-releases/16_best-practices/windows-logging-recommendations/windows-advanced-auditing-recommendations.md): Advanced Audit Logging for better visibility using Domain Group Policy (Preferred)
- [Lateral Movement Logging Recommendations](https://docs.blusapphire.io/older-releases/16_best-practices/lateral-movement-logging-recommendations.md): Windows Event IDs to monitor
- [Best Data Sources for Detection](https://docs.blusapphire.io/older-releases/16_best-practices/best-data-sources-for-detection.md): This page attempts to provide the reader an understanding of the best data sources that provide detection based on Mitre ATT\&CK framework
- [Cloud Incident Readiness](https://docs.blusapphire.io/older-releases/16_best-practices/cloud-incident-readiness.md): Key logs for cloud incidents
