> For the complete documentation index, see [llms.txt](https://mahmoud-shaker.gitbook.io/dfir-notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://mahmoud-shaker.gitbook.io/dfir-notes/incident-response-eventhoods.md).

# Incident Response Eventhoods

The map organizes event codes into distinct categories, such as

* Network Activity
* initial access
* Privilege Escalation Detection
* Process Creation
* Persistence Detection - schedule task
* Persistence Registry Detection
* PowerShell Detection
* Buffer Overflow Detection
* lateral movement Detection
* DCSync Activity Detection
* Golden Ticket Detection
* Pass-the-Hash (PtH) Attack Detection
* Pass-the-Ticket (PtT) Attack Detection

Here is the HTML map with high quality &#x20;

{% embed url="<https://github.com/0Xdarkday/Investigator-Hand/blob/main/Eventcods.drawio.html>" %}

Here is a photo of the content above&#x20;

<figure><img src="/files/7spYm7QbBKJYjPzPYJIb" alt=""><figcaption></figcaption></figure>
