Event Logs

13cubed

What Is?

Forensic Value:

File Location:

  • C:\Windows\System32\winevt\logs

Parse Data:

Offline:

Live PowerShell Cheatsheet

Considerations:

Example:

Analysis Tips:

Anti-Forensics:

Last updated