How To Use The Windows Event Viewer For Cyber Security Audit

How To Use The Windows Event Viewer For Cyber Security Audit

Jon Good

4 года назад

99,964 Просмотров

Ссылки и html тэги не поддерживаются


Комментарии:

@sykanji9816
@sykanji9816 - 23.11.2023 19:55

my guy

Ответить
@user-xp4tw2ye8u
@user-xp4tw2ye8u - 31.10.2023 20:11

Why does security SPP will occur in windows 10 & why does it completely shuts down all the applications in my system at that moment

Ответить
@toukio_
@toukio_ - 15.10.2023 14:41

Very informative, thanks for sharing Jon.

Ответить
@Ash-vi8yr....
@Ash-vi8yr.... - 23.08.2023 15:48

I 💜 this videooo...

Ответить
@itumelengmaaboi8942
@itumelengmaaboi8942 - 13.08.2023 10:28

Can you also see who deleted files???

Ответить
@doctorsaikia4647
@doctorsaikia4647 - 06.08.2023 00:40

Hi Is there any way to know what files are being copied from my laptop to a USB drive. It's timestamp and what folder or file copied... OR If copy log present in the system.

Ответить
@ofek_11
@ofek_11 - 09.07.2023 14:02

Hope its still relevant,i have a question to disable real time protection and find the event id(sounds simple) but when i do that the event id doesnot appear.. even when im in the local(configuration) any suggestions?

Ответить
@johnvardy9559
@johnvardy9559 - 06.07.2023 18:18

Hi John great video,after 3 years need t know somebody all of these stuff ?

Ответить
@sonyi1967
@sonyi1967 - 30.05.2023 02:38

Q: I got a Kaspersky file on windows log and I cam get rid of it to install a different antivirus.

Ответить
@kenstart6
@kenstart6 - 22.05.2023 05:05

Can we get the Event Log of a computer remotely ?

Ответить
@puazuzu4958
@puazuzu4958 - 21.05.2023 07:01

Hi Jon, thank you for the video :)!
I have a question about this. The event ID 4698 and the events of schtasks i can't see them, ¿why is it not displayed in the event viewer?

Thank you!

Ответить
@tendimukhodobwane5915
@tendimukhodobwane5915 - 28.03.2023 00:23

brief and precise, i didint know how to use event viewer until i saw this video

Ответить
@teerich2011
@teerich2011 - 22.03.2023 03:30

Thank you Jon. That was Good!

Ответить
@invest_9361
@invest_9361 - 08.03.2023 19:27

Hey Jon, I suspected someone was on my PC uninvited. I went to look at my event viewer logs and they have been cleared! I did not do this, could you help me out? Trying to figure out when they where cleared and when someone was on my PC, gods knows whats been installed. Can anyone help?

Ответить
@dariowins
@dariowins - 03.03.2023 10:58

Can you tell us how can we convert the time format to UTC, for example, when we find a event Id and we have to write it in the forensic report it's very common to write the date and time in UTC format.

Ответить
@mrxenosith8023
@mrxenosith8023 - 27.02.2023 18:39

Hello Jon, i noticed that the event viewer no longer displays the username. how can we get the username for the event logon and logoff?

Ответить
@halfdemon88
@halfdemon88 - 01.02.2023 03:04

Also bears mentioning that you can add MMC snap-ins to view logs on remote computers in a domain. Super convenient as an admin

Ответить
@kwsrchoudhury
@kwsrchoudhury - 18.01.2023 08:29

Thanks! Gotta investigate a laptop tomorrow

Ответить
@SaiyanParmos
@SaiyanParmos - 10.12.2022 10:02

Thank you for this post. Some times if feels better to jump in as you just did but for trying Splunk or DeepBlueCLi

Ответить
@alqahtanirakan-cm5736
@alqahtanirakan-cm5736 - 20.10.2022 17:04

Explain the concept of logging? where are they located in windows and linux? sho b w an example of failed login logging in windows event viewer

Ответить
@waydownwergoing
@waydownwergoing - 05.10.2022 23:24

Hi my friend. I am trying write script for task scheduler for sending realtime all logs to telegram channel. can you help me?

Ответить
@Gnrl_Anesthesia
@Gnrl_Anesthesia - 30.08.2022 23:40

Hey jon,
Sorry i am learning about this but you are my best shot at getting the proof here. Long story short, some of the veryyy imp files have been deleted from google drive and even from trash. I know who did it from my laptop when i was away, it does say I deleted it because laptop had g-drive logged in. I am in reallll trouble now. All i want is a proof that my laptop was used between X-Y dates so that i can prove my innocence. I already am down the rabbit hole and i have reached here. Please guide me if this can be done from event viewer. All i want is confirmation that laptop was used during the dates when i wasn’t around. Even better if we can see someone opened g-drive.

Ответить
@paulobazzo5650
@paulobazzo5650 - 25.06.2022 18:44

Sorry but this video is a joke

Ответить
@interfuze9470
@interfuze9470 - 19.06.2022 10:17

I have a question and went to event viewer and few month ago I downloaded this application called solidworks. I deleted the application for solidworks but in the event viewer there is still a log file for SW any help? I just want to delete that log file. It’s under application and services 😭 I hate downloading school stuff on my personal gaming PC. I don’t want to clear the log I want to delete that log file***

Ответить
@shehzadarshad2000
@shehzadarshad2000 - 10.06.2022 17:04

Nice video bro i am also an IT guy

Ответить
@jibunorufoegbune9567
@jibunorufoegbune9567 - 01.05.2022 13:21

Thanks Jon Good

Ответить
@jswift5300
@jswift5300 - 30.04.2022 00:06

Sorry Jon, I like the way you present your videos I just assumed what you would be sharing would be more focused on what logs we would need to be investigating. For instance, the Firewall Log, the DNS log, obviously the Security log etc. Other than that, you present well, are clear and concise and can't fault you!

Ответить
@kcalderon03
@kcalderon03 - 28.04.2022 17:48

Hello. Do you have a reference you would recommend for looking up event ID’s? Thanks

Ответить
@MrSouthsideMuscle
@MrSouthsideMuscle - 07.04.2022 00:45

Onboard system software is dece enough

Ответить
@warronfrench8163
@warronfrench8163 - 29.03.2022 16:34

0% audio. I tried other videos and they worked.

Ответить
@karoz07
@karoz07 - 22.03.2022 20:21

Thank You very much for this grate information...!!! In my computer shows to many times the ID 4672 Special Logon and ID 4624 Logon and I don´t know if this means tha some from out side is looking my personal information or it is just a simple thing from Windows Event...!!! Will you be so nice just to let me know if this could be dangerous or not...!!! I will appreciate so mucho...!!! I send you a big hug from México City...!!! God Bless You Always...!!!

Ответить
@flittotech5280
@flittotech5280 - 13.03.2022 03:53

Thanks for this very interesting vidéo.

Ответить
@spitballproductions
@spitballproductions - 23.02.2022 00:52

how can you do this using Autopsy?

Ответить
@BrianThomas
@BrianThomas - 20.01.2022 21:34

Wow. You’re Good

Ответить
@GarageGuyCarl
@GarageGuyCarl - 25.12.2021 13:17

How can I filter logs by date(s)?

Ответить
@igcheaptrick7046
@igcheaptrick7046 - 12.12.2021 05:59

A hotspot showed up on my available networks does a laptop have a log of that hotspot even though i never connected to it???

Ответить
@abineshms3759
@abineshms3759 - 28.10.2021 07:16

how to display those security events using c or c++ program

Ответить
@vtcl1
@vtcl1 - 07.10.2021 14:41

I have come across some events that occurred during the wee hours of the morning while I was sleeping. Is there a way for me to find out its location?

Ответить
@vtcl1
@vtcl1 - 06.10.2021 20:32

I have another question, Jon: Under the Task Category, I don't see Logon or Special Logon. I'm only seeing User Account Man... Does this mean that no external individual has logged onto my system?

Ответить
@vtcl1
@vtcl1 - 06.10.2021 16:48

This is an excellent video. Is it a red flag to see several deleted events at the end of the list? My laptop is used only by me

Ответить
@kristinabrannon3693
@kristinabrannon3693 - 28.09.2021 22:04

Does event viewer clear it's own logons after so long or do you have to manually clear them out?

Ответить
@dbcnewstv
@dbcnewstv - 21.09.2021 14:19

Waste of my time

Ответить
@pidaparthysurya4373
@pidaparthysurya4373 - 16.09.2021 19:55

HOW TO TAKE AD AUDIT LOGS FOR 3-6 MONTHS

Ответить
@sampannashrestha973
@sampannashrestha973 - 29.06.2021 19:45

Good Content :)

Ответить
@mitchelllee6110
@mitchelllee6110 - 26.05.2021 13:30

How far back can event logs go as a maximum?

Ответить
@ruslanmamedaliyev3912
@ruslanmamedaliyev3912 - 07.05.2021 23:07

please tell me how can i see which files did my windows defender skip during the scan with the help of event viewer or with other ways?
please explain step by step

Ответить
@davidmanning1474
@davidmanning1474 - 30.04.2021 07:10

Do you have a brother that does vjdsa out air travel by any chance

Ответить
@petrmilota6398
@petrmilota6398 - 28.03.2021 11:54

completing case in Immersive Labs for Hafnium events.. well - we will see if this helps :D we can use only Event Viewer

Ответить