- Joined
- Mar 25, 2024
Claim one - "suspicious" remote logins contain no remote workstation name. Microsoft documentation states that's expected as that workstation name is not a required field. If they were logging into the server using a remote support application of some sort, it could proxy through the remote support servers and possibly not provide a workstation name. Very plausible, honestly.
Claim two - "suspicious" remote logins somehow didn't generate a credential validation event. This part comes off a lot more as "trust us, we looked" since they say they checked and every remote login had a corresponding credential validation event logged. They just say it always generates the paired events and they've never found a case where it didn't. It's unclear if they mean in general, or on that particular election log dump. But expert testimony really is just "trust me I'm an expert" in the end.