π
Windows Forensic Handbook
Ctrl
K
Copy
Artifacts by Type
π
Event Log Artifacts
Microsoft Windows Shell Core
EventID 9707: Command Execution Started
Last updated
1 year ago