πŸ”
Windows Forensic Handbook
search
Ctrlk
  • πŸ‘‹Welcome
  • Artifacts by Type
    • πŸ—„οΈRegistry Artifactschevron-right
    • πŸ“‚Filesystem Artifactschevron-right
    • πŸ“…Event Log Artifactschevron-right
      • Task Scheduler Operational Log
      • TerminalServices-RDPClientchevron-right
      • Securitychevron-right
        • EventID 4688: A new process has been created
        • EventID 4624: An account was successfully logged on
      • Systemchevron-right
      • Microsoft Windows Windows Firewall With Advanced Securitychevron-right
      • TerminalServices-LocalSessionManagerchevron-right
      • TerminalServices-RemoteConnectionManagerchevron-right
      • Microsoft Windows Shell Corechevron-right
      • Microsoft-Windows-PowerShellchevron-right
  • Artifacts by Activity
    • πŸƒβ€β™‚οΈExecutionchevron-right
    • πŸ—’οΈFile Activitychevron-right
    • πŸ‘¨β€πŸ”§Account Activitychevron-right
    • 🌎Network Activitychevron-right
    • πŸ”Browser Activitychevron-right
    • πŸ–₯️System Enumerationchevron-right
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
  1. Artifacts by Typechevron-right
  2. πŸ“…Event Log Artifacts

Security

EventID 4688: A new process has been createdchevron-rightEventID 4624: An account was successfully logged onchevron-right

Last updated 2 years ago