πŸ”
Windows Forensic Handbook
CtrlK
  • πŸ‘‹Welcome
  • Artifacts by Type
    • πŸ—„οΈRegistry Artifacts
    • πŸ“‚Filesystem Artifacts
    • πŸ“…Event Log Artifacts
      • Task Scheduler Operational Log
      • TerminalServices-RDPClient
      • Security
        • EventID 4688: A new process has been created
        • EventID 4624: An account was successfully logged on
      • System
      • Microsoft Windows Windows Firewall With Advanced Security
      • TerminalServices-LocalSessionManager
      • TerminalServices-RemoteConnectionManager
      • Microsoft Windows Shell Core
      • Microsoft-Windows-PowerShell
  • Artifacts by Activity
    • πŸƒβ€β™‚οΈExecution
    • πŸ—’οΈFile Activity
    • πŸ‘¨β€πŸ”§Account Activity
    • 🌎Network Activity
    • πŸ”Browser Activity
    • πŸ–₯️System Enumeration
Powered by GitBook
On this page
  1. Artifacts by Type
  2. πŸ“…Event Log Artifacts

Security

EventID 4688: A new process has been createdEventID 4624: An account was successfully logged on

Last updated 1 year ago