Windows Forensic Handbook
Search
Ctrl + K
Command Line Options
Task Scheduler Files
Task Scheduler Operational Log
EventID 4688: A new process has been created
EventID 9707: Command Execution Started
Last updated
6 months ago