📘
DFIR
Search...
Ctrl + K
Windows
Forensics
Event Logs
Event Log IDs
SMB
4740 Account Lockout
4642 Logon
5156 Show App IP Connections
Previous
Event Logs
Next
SMB