Windows Event Log Threat Hunting Starter Kit
A cheat sheet bundle and detection runbook that teaches sysadmins to hunt real threats using native Windows Event Log IDs — no SIEM required.
- ▸Priority Event ID Reference — 30+ Event IDs across 7 threat categories (credential attacks, lateral movement, ransomware precursors, persistence indicators, and more), each with a copy-paste PowerShell pull command
- ▸28 PowerShell Investigation Queries — organized by 5 real incident scenarios with output interpretation guidance
- ▸Audit Policy Baseline Checklist — which subcategories to enable, Group Policy steps, and a 2-command verification sequence
- ▸5-Scenario Incident Runbook — step-by-step triage for credential attacks, account manipulation, ransomware precursors, lateral movement, and insider threat — with incident log templates
## goes-well-with
From the same shelf
Active Directory Security Audit Kit for Solo IT Teams
A fillable AD audit checklist covering privileged access, stale accounts, GPO hygiene, MFA gaps, and event log review — everything an auditor expects, packaged for the sysadmin who has no security team.
Agent Memory Architecture Part 2: Episodic vs Semantic vs Procedural Memory
The three agent memory types — episodic, semantic, and procedural — explained through the real production code of ClaudeClaw, a 24/7 multi-agent system, so your agents stop starting from scratch every session.
AI Chatbot Account Recovery: Security Audit Checklist for Developers
A developer's guide to designing safe AI chatbot account recovery flows, using the Meta/Instagram breach as a live case study.
## not-ready-to-buy
Take the field notes instead
One practical write-up a week from the same workbench these kits come from — plus reader pricing when new kits ship.