Windows Forensic Handbook
Search
Ctrl + K
Microsoft Windows Shell Core
EventID 9707: Command Execution Started
Last updated
6 months ago