Looking for a good ...
 
Notifications
Clear all

Looking for a good tool to parse and search Windows EVT logs

12 Posts
8 Users
0 Reactions
1,968 Views
(@mobileforensicswales)
Reputable Member
Joined: 17 years ago
Posts: 274
 

Have a look at highlighter from Mandiant, that is very good, particularly when looking for time line paterns of activity )


   
ReplyQuote
ZambranaJ
(@zambranaj)
New Member
Joined: 16 years ago
Posts: 2
 

I have used EventRover from doriansoft in the past, this tool allows you to attach to a network PC or extracted log, and it also allows you to apply custom filters by POI or events.

Regards
😯


   
ReplyQuote
Page 2 / 2
Share: