Event Logs
What Is?
Forensic Value:
File Location:
C:\Windows\System32\winevt\logs
Parse Data:
Offline:
Live PowerShell Cheatsheet
Considerations:
Example:
Analysis Tips:
Anti-Forensics:
Last updated