Notifications
Clear all

Security.evtx

4 Posts
3 Users
0 Likes
1,529 Views
 dega
(@dega)
Posts: 263
Reputable Member
Topic starter
 

dear all,

I am analyzing two computer with windows 10.W suspect data exfiltration.

I extracted from both computer the file Security.evtx. One is empty and one is corrupted.

Can someone suggest me a tool for recover those files?

thanks in advance

 
Posted : 26/05/2020 5:52 pm
keydet89
(@keydet89)
Posts: 3568
Famed Member
 

I might help if you could describe a couple of things.

First, how did you extract the files?  What method did you use?

Second, if the issue is data exfiltration, what do you hope to find in the Security Event Log?  I ask, as if you're able to articulate what you're looking for, there may be alternate artifacts in the constellation that can be examined.

HTH

 
Posted : 01/06/2020 5:59 pm
Em-Belkasoft
(@em-belkasoft)
Posts: 33
Eminent Member
 
Posted by: @giandega

dear all,

I am analyzing two computer with windows 10.W suspect data exfiltration.

I extracted from both computer the file Security.evtx. One is empty and one is corrupted.

Can someone suggest me a tool for recover those files?

thanks in advance

I doubt you will be able to recover the data you need from those files. You may want to try carving the entries from the registry. 

 
Posted : 02/06/2020 8:24 pm
 dega
(@dega)
Posts: 263
Reputable Member
Topic starter
 

Thanks for answering me.

I solved the situation. opening the file with a log viewer gives the errors above. Opening it with the windows event viewer, there are no errors

thanks again

 
Posted : 03/06/2020 8:57 am
Share: