Hello All,
Greetings!!!
In our environment we monitor windows events 4624 and 4625 on AD for other workstations as all workstations can not integrated in a SIEM.
However, in event 4624 and 4625, we are not getting any type 10 or type 2 logon type that could tell us the interactive logon has...
activity
credentials
detection
eventevent4624event 4625
guidance
interactive
logon
malicious software
monitoring
policy
security
siem
type 10
type 2
type 3
windows ad
workstation