Windows Forensic Handbook
Search
Ctrl + K
Security
EventID 4688: A new process has been created
EventID 4624: An account was successfully logged on
Last updated
6 months ago