UAL
Shows potential lateral movement to servers with UAL logging (all servers).

Parsing Data
Considerations

Anti-Forensics
Last updated
Shows potential lateral movement to servers with UAL logging (all servers).


Last updated
#Parse DB directory
SumECmd.exe -d F:\Tools\Investigation\logs\ --csv F:\Tools\Investigation\logs\logs1
#repair dirty DB files
esentutl.exe /p Current.mdb
esentutl.exe /p SystemIdentity.mdb
esentutl.exe /p GUID.mdb