Windows Event Logs Analysis

Conduct comprehensive forensic analysis of Windows Event Logs (.evtx) to trace attacker activity including lateral movement, privilege escalation, credential dumping, persistence mechanisms, and remote code execution. Use this skill during incident response, threat hunting, or post-breach forensic investigations on Windows systems and Active Directory environments.

ShulkwiSEC d0eb69c 3 files · 23.5 KB Updated 21 repo stars

File contents

ShulkwiSEC/bb-huge/tree/main/skills/curated/windows-event-logs-analysis commit d0eb69c47c

Frequently asked questions

npx skillmds add shulkwisec/windows-event-logs-analysis