πŸ”
Windows Forensic Handbook
search
Ctrlk
  • πŸ‘‹Welcome
  • Artifacts by Type
    • πŸ—„οΈRegistry Artifactschevron-right
    • πŸ“‚Filesystem Artifactschevron-right
    • πŸ“…Event Log Artifactschevron-right
  • Artifacts by Activity
    • πŸƒβ€β™‚οΈExecutionchevron-right
    • πŸ—’οΈFile Activitychevron-right
    • πŸ‘¨β€πŸ”§Account Activitychevron-right
      • Account Creation Time
      • Group Membership
      • Last Login
      • Login Historychevron-right
      • Logon IDchevron-right
      • Relative Identifier
      • Security Identifierchevron-right
        • Background Activity Montitorarrow-up-right-from-square
        • System Resource Usage Monitor (SRUM)arrow-up-right-from-square
        • Recycle Bin $I/$R Filesarrow-up-right-from-square
        • EventID 4688: A new process has been createdarrow-up-right-from-square
        • EventID 4624: An account was successfully logged onarrow-up-right-from-square
        • Event ID 7045: Service Installedarrow-up-right-from-square
        • EventID 1024: RDP ClientActiveX is trying to connect to the serverarrow-up-right-from-square
        • EventID 2004: Firewall Rule Addedarrow-up-right-from-square
        • EventID 2005: Firewall Rule Modifiedarrow-up-right-from-square
        • EventID 2006: Firewall Rule Deletedarrow-up-right-from-square
        • EventID 2071: Firewall Rule Addedarrow-up-right-from-square
        • EventID 2073: Firewall Rule Modifiedarrow-up-right-from-square
        • EventID 2052: Firewall Rule Deletedarrow-up-right-from-square
        • EventID 9707: Command Execution Startedarrow-up-right-from-square
      • Usernamechevron-right
    • 🌎Network Activitychevron-right
    • πŸ”Browser Activitychevron-right
    • πŸ–₯️System Enumerationchevron-right
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
  1. Artifacts by Activitychevron-right
  2. πŸ‘¨β€πŸ”§Account Activity

Security Identifier

Background Activity Montitorchevron-rightSystem Resource Usage Monitor (SRUM)chevron-rightRecycle Bin $I/$R Fileschevron-rightEventID 4688: A new process has been createdchevron-rightEventID 4624: An account was successfully logged onchevron-rightEvent ID 7045: Service Installedchevron-rightEventID 1024: RDP ClientActiveX is trying to connect to the serverchevron-rightEventID 2004: Firewall Rule Addedchevron-rightEventID 2005: Firewall Rule Modifiedchevron-rightEventID 2006: Firewall Rule Deletedchevron-rightEventID 2071: Firewall Rule Addedchevron-rightEventID 2073: Firewall Rule Modifiedchevron-rightEventID 2052: Firewall Rule Deletedchevron-rightEventID 9707: Command Execution Startedchevron-right

Last updated 2 years ago