If you duplicate the attacker steps on the Cisco hack, you get a few interesting Windows event logs to be monitoring:

-New service installed
-New user created
-User added to admin group
-Event log cleared
-User deleted

Are you looking for those events on your logs?


