Notifications
Clear all

Window Forensics

4 Posts
3 Users
0 Reactions
1,895 Views
(@muzlee101)
New Member
Joined: 5 years ago
Posts: 2
Topic starter  

Hi, Any body please guide me where to track the date/time change information of window machine. what specific files record the event of date change in registry and event logs. please guide step by step.


   
Quote
(@p38cyq)
Trusted Member
Joined: 14 years ago
Posts: 44
 

You should familiarize yourself with the Windows Logbooks. 


   
ReplyQuote
(@lautarob)
Active Member
Joined: 9 years ago
Posts: 3
 

@p38cyq Hello, what you you mean by "Windows Logbooks"?. Are you referring to the logs stored under Windows\System32\Logs; the ones under Windows\System32\LogFiles or what else?

Thanks!

 


   
ReplyQuote
(@p38cyq)
Trusted Member
Joined: 14 years ago
Posts: 44
 

In the searchbox, lower left on your screen, type "eventvwr.msc"


   
ReplyQuote
Share: