Computer on my network has been RATed. What do i do now?

Like at the moment my only thought is to monitor network usage on days off and see if anything stands out.

event logs? so its a windows machine? my bad.

you would have had to enabled user login and application logging before the event. they are off by default so the information your looking for may not have been logged.

run secpol.msc and check
local policies/audit policies go down the list an enable all the logs
you may want to have a quick scan through the other fields in the secpol database incase theres something else you want to log also.

1 Like