Closed bmmojo closed 2 weeks ago
Honestly, I don't know. I've never run the tool via PowerShell, and I don't have a copy of the .evtx file to verify...
Hey @keydet89, I figured out the issue.
The .evtx
had an attribute of RA. I had to turn off the "Read-Only" attribute in the file. Now it works on both cmd.exe
and powershell.exe
.
Whenever I run the batch file, I will get an error:
I have tried this on command prompt and "as administrator". I have tried running the batch file to the specific evtx in the Windows\System32\winevt\logs.
Am I doing something wrong?