killchain-compendium/Forensics/Windows Event Logs.md

163 B

Windows Event Log

Dump Logfile

Windows Event Logfiles can be dumped via

evtx_dump $EVENT_LOG > event.log
evtx_dump -o json $EVENT_LOG > event.log