Windows Forensics
What is audit trail?
2
2
What are events?
3
3
Event Logs?
4
4
Examples of Windows Event Logs
5
5
Application (program) event logs
6
6
System events log
7
7
Setup event logs
8
8
Forwarded events log
9
9
Security-related events log
10
10
Domain Controller event logs
11
11
Event Viewer
12
12
Accessing Windows 7 Event Viewer
13
To view the details of an event double click it
13
Windows 7 Event Viewer
14
14
Event log format
15
15
Structure of event log header
16
16
An application program event log
17
17
IIS Logs
18
18
Virtual Servers in IIS
19
%WinDir%\System32\LogFiles
19
How to activate IIS
Before that you have to enable the IIS for windows by
20
20
Parsing Windows Firewall Logs
%SystemRoot%\pfirewall.log
21
21
Tasks
22
22
What is account auditing?
23
23
Examining auditing-policy change events
24
24
How do we enable Account Auditing Settings?�
25
25
26
26
Examining system log entries
27
27
Examining application log entries
28
28
Windows Event Log File Internals
29
29
What is Windows Event Log Parser?
30
30
Popular Windows forensic analysis tools: Word Extractor��
31
31
Thank You
32
32