Windows EventViewer Analysis | DFIR
Last Activity View

Evtx analysis

Examples
ExamplesDeepBlueCLI: https://github.com/sans-blue-team/DeepBlueCLI

WELA (Windows Event Log Analyzer): https://github.com/Yamato-Security/WELA

EventID - Windows Events Search

Outlook files analysis

View .msg files (from Outlook)
LogonTracer

Import larger 'security.evtx' files and parse them before
Dump Security EVTX files from Collectors ZIP files
Import the XML into LogonTracer



Last updated
