Abstract:
The objectives of this research were: 1) to explore
about Lateral Movement analysis from windows security event log
2) to develop the program for Lateral Movement analysis from windows
security event log 3) to evaluate the usage of satisfaction of program for
Lateral Movement analysis from windows security event log. The type
of events that can be use for Lateral Movement analysis were Event ID
4624, 4648, 4688, 5140, and 5145. The analysis model varies according
to the data fields in each type of event. The program developed are
divided into 4 main parts: part 1 for checking the file format of windows
event log; part 2 for file format transformation to readable format;
part 3 for Lateral Movement analysis; and part 4 for saving the Lateral
Movement analysis result to Microsoft Excel file by using python
language for programming. The evaluation of the usage of satisfaction
was evaluated by 10 trained experts in the use of program for Lateral
Movement analysis from windows security event log. The overall usage
of satisfaction results of the program was at a very high level (𝒙̅=4.63,
S.D.=0.51).