killchain-compendium/Forensics/Windows Event Logs.md

10 lines
163 B
Markdown
Raw Normal View History

2023-02-26 21:45:17 +01:00
# Windows Event Log
## Dump Logfile
Windows Event Logfiles can be dumped via
```sh
evtx_dump $EVENT_LOG > event.log
evtx_dump -o json $EVENT_LOG > event.log
```