🔍
Windows Forensic Handbook
Search...
Ctrl + K
Artifacts by Activity
🏃♂️
Execution
Parent and Child Information
Last updated
1 year ago
EventID 4688: A new process has been created
EventID 1024: RDP ClientActiveX is trying to connect to the server
EventID 2004: Firewall Rule Added
EventID 2005: Firewall Rule Modified
EventID 2006: Firewall Rule Deleted
EventID 2071: Firewall Rule Added
EventID 2073: Firewall Rule Modified
EventID 2052: Firewall Rule Deleted
EventID 9707: Command Execution Started
EventID 4104: PowerShell Script Block Logging