EVTX
location:
3 options when max size is reached:
overwrite (default)
Archive
do not overwrite - error message appears
Powershell EVTX filtering:
Log
EventID
Info
System
7034
Service crashed unexpectedly
7035
Service sent a start/stop control
7036
service started or stopped
7040
start type changed (boot | On Request | Disabled)
7045
Service was installed on the system
7045
A new service was installed on the system (look for PSEXESVC)
Defender
1116
Detected Event
1117
Quarantined Event
TaskScheduler
106
Task creation
140
Task update
141
Task Deleted
200
Task Executed
Sysmon
sc.exe leaves nothing in EVTX
Parse:
apt-hunter
chainsaw
Eric Zimmerman:
Last updated