Event logs

evtlogs is a plugin available for the Windows XP and Windows 2003 server operating systems. This plugin is able to extract and parse out the event logs that are currently in memory. Event logs in memory sometimes have evidentiary value, as they may indicate specific actions taken by the system during or after a compromise.

Get Digital Forensics and Incident Response now with O’Reilly online learning.

O’Reilly members experience live online training, plus books, videos, and digital content from 200+ publishers.