2024-10-03 Nightmare on Hunt Street (Forensics)

This is really just about parsing out the evtx logs and then reading them

the kali IP from the logs,

image.png

10.1.1.42

image.png

I got 32, I actually got 32 from running chainsaw on this

32
psexec

image.png

4
Susan123!

image.png

Extracting the logs wiht ZimmerEvtxECmd tool

GitHub - EricZimmerman/evtx: C# based evtx parser with lots of extras
C# based evtx parser with lots of extras. Contribute to EricZimmerman/evtx development by creating an account on GitHub.
https://github.com/EricZimmerman/evtx

image.png

image.png

image.png

image.png

image.png