Windows EventViewer Analysis | DFIR
In this article, we will show you some approaches to analyze some activity on Windows events.
- 1.Create a new filter with the type of event ID or events between a specific date.
2. After create it, click on context menu and "Save As ...".
- 3.Use a specific tool to analyze the logs.