<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>event log</title><link>https://evotec.xyz/es/tags/event-log</link><description>Evotec Main Website</description><atom:link href="https://evotec.xyz/es/tags/event-log/index.xml" rel="self" type="application/rss+xml" /><item><title>Restoring (Recovering) PowerShell Scripts from Event Logs</title><link>https://evotec.xyz/es/blog/restoring-recovering-powershell-scripts-from-event-logs</link><description>A few days ago, I was asked to take a look at PowerShell Malware. While I don’t know much about malware, my curiosity didn’t let me skip on this occasion, and I was handed over WindowsPowerShell.evtx file. Ok, that’s not what I expected! I wanted PowerShell .ps1 files that I can read and assess? Well, you play with the cards you were dealt with. What I was handed over was PowerShell Event Log. PowerShell writes whatever you execute, and it thinks it is risky, to Windows PowerShell Operation Event Log.</description><pubDate>Fri, 28 Aug 2020 15:39:28 GMT</pubDate><guid>https://evotec.xyz/es/blog/restoring-recovering-powershell-scripts-from-event-logs</guid><category>event log</category><category>get-events</category><category>powershell</category><category>powershellmanager</category><category>pseventviewer</category><category>Windows</category></item><item><title>PSWinReporting – Forwarders, Microsoft Teams, Slack, Microsoft SQL and more</title><link>https://evotec.xyz/es/blog/pswinreporting-forwarders-microsoft-teams-slack-microsoft-sql-and-more</link><description>It’s been a while since PSWinReporting has been updated, or rather since I’ve written a blog post about it since it’s always…</description><pubDate>Sun, 16 Sep 2018 17:59:28 GMT</pubDate><guid>https://evotec.xyz/es/blog/pswinreporting-forwarders-microsoft-teams-slack-microsoft-sql-and-more</guid><category>active directory</category><category>event log</category><category>events</category><category>microsoft teams</category><category>ms sql</category><category>powershell</category><category>slack</category><category>sql</category><category>teams</category><category>Windows</category></item><item><title>Monitoring Active Directory Changes on Users and Groups with PowerShell</title><link>https://evotec.xyz/es/blog/monitoring-active-directory-changes-on-users-and-groups-with-powershell</link><description>Working as Administrator with Active Directory can be rewarding. You can easily deploy new settings, make changes to users even…</description><pubDate>Fri, 23 Mar 2018 10:01:43 GMT</pubDate><guid>https://evotec.xyz/es/blog/monitoring-active-directory-changes-on-users-and-groups-with-powershell</guid><category>active directory</category><category>event id</category><category>event log</category><category>event viewer</category><category>events</category><category>group membership</category><category>groups</category><category>monitoring</category><category>powershell</category><category>security events</category><category>user changes</category><category>Windows</category></item></channel></rss>