DFIR
Search
Ctrl + K
Event Log IDs
SMB
4740 Account Lockout
4642 Logon
5156 Show App IP Connections
Previous
Event Logs
Next
SMB