issues
search
libyal
/
winevt-kb
Windows Event Log Knowledge Base
Apache License 2.0
16
stars
5
forks
source link
add scripts
#9
Open
joachimmetz
opened
8 years ago
joachimmetz
commented
8 years ago
[x] script to read eventlogs and message strings directly from images
extract script
[ ] script to analyze logon/logoff (e.g. event id 4624)
http://social.technet.microsoft.com/wiki/contents/articles/17055.event-ids-when-a-new-user-account-is-created-on-active-directory.aspx
add Registry key access (id 4663)
[ ] script to analyze process start/stop