🔍
Windows Forensic Handbook
More
Search
Ctrl + K
Execution Account
Last updated
1 year ago
Background Activity Montitor
System Resource Usage Monitor (SRUM)
AutomaticDestinations Jumplists
Task Scheduler Files
EventID 4688: A new process has been created
EventID 2004: Firewall Rule Added
EventID 2005: Firewall Rule Modified
EventID 2006: Firewall Rule Deleted
EventID 2071: Firewall Rule Added
EventID 2073: Firewall Rule Modified
EventID 2052: Firewall Rule Deleted
EventID 9707: Command Execution Started