Bert-JanP / Incident-Response-Powershell

PowerShell Digital Forensics & Incident Response Scripts.
BSD 3-Clause "New" or "Revised" License
514 stars 73 forks source link

Added Get-EVTXFiles Function #3

Closed JakePeralta7 closed 1 year ago

JakePeralta7 commented 1 year ago

This function fetch all the important evtx files which can be cross-examined with sigma with the help of tools like Chainsaw - and manually of-course.

Bert-JanP commented 1 year ago

Great addition again! Thanks