WEVTUTIL
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Windows Event Log Utility. Query, export, archive, and clear Windows event logs.
LOG INFORMATION#
LIST LOGS#
wevtutil el # List all log names wevtutil el | find "Security" # Filter by name wevtutil el | findstr /i "powershell"
LOG INFO#
wevtutil gl Security # Log configuration wevtutil gl System # System log info wevtutil gli Security # Log statistics # Shows: enabled, retention, max size, log path
QUERY EVENTS#
BASIC QUERY#
wevtutil qe Security # Query Security log wevtutil qe System # Query System log wevtutil qe Application # Query Application log
OPTIONS#
/c:n # Count (max events) /rd:true # Reverse direction (newest first) /f:text # Format: xml, text, renderedxml /e:root # Root element for XML
EXAMPLES#
wevtutil qe Security /c:10 /rd:true /f:text wevtutil qe System /c:50 /rd:true /f:text wevtutil qe Application /c:100 /f:xml > events.xml
XPATH QUERIES#
wevtutil qe Security /q:"*[System[EventID=4624]]" /f:text wevtutil qe Security /q:"*[System[EventID=4625]]" /c:10 /f:text wevtutil qe System /q:"*[System[Level=2]]" /f:text # Event Levels # 1 = Critical # 2 = Error # 3 = Warning # 4 = Information # 5 = Verbose
QUERY BY TIME#
wevtutil qe Security /q:"*[System[TimeCreated[@SystemTime>='2024-01-01T00:00:00.000Z']]]" /f:text
QUERY BY EVENT ID#
wevtutil qe Security /q:"*[System[EventID=4624 or EventID=4625]]" /f:text wevtutil qe Security /q:"*[System[(EventID>=4624 and EventID<=4634)]]" /f:text
QUERY BY PROVIDER#
wevtutil qe Security /q:"*[System[Provider[@Name='Microsoft-Windows-Security-Auditing']]]"
COMMON SECURITY EVENT IDS#
# Logon Events 4624 # Successful logon 4625 # Failed logon 4634 # Logoff 4647 # User initiated logoff 4648 # Logon with explicit credentials 4672 # Special privileges assigned # Account Management 4720 # User account created 4722 # User account enabled 4723 # Password change attempt 4724 # Password reset attempt 4725 # User account disabled 4726 # User account deleted 4728 # Member added to security group 4732 # Member added to local group # Process Events 4688 # New process created 4689 # Process exited # Object Access 4663 # Access to object 4656 # Handle to object requested # Policy Changes 4719 # System audit policy changed 4739 # Domain policy changed
LOGON TYPES#
# Type 2 - Interactive (console) # Type 3 - Network (SMB, shares) # Type 4 - Batch (scheduled task) # Type 5 - Service # Type 7 - Unlock # Type 8 - NetworkCleartext # Type 9 - NewCredentials (runas) # Type 10 - RemoteInteractive (RDP) # Type 11 - CachedInteractive
USEFUL QUERIES#
# Failed logins wevtutil qe Security /q:"*[System[EventID=4625]]" /c:50 /rd:true /f:text # Successful logins wevtutil qe Security /q:"*[System[EventID=4624]]" /c:50 /rd:true /f:text # RDP logins (Type 10) wevtutil qe Security /q:"*[System[EventID=4624] and EventData[Data[@Name='LogonType']='10']]" /f:text # New processes wevtutil qe Security /q:"*[System[EventID=4688]]" /c:100 /rd:true /f:text # Services installed wevtutil qe System /q:"*[System[EventID=7045]]" /f:text # PowerShell execution wevtutil qe "Microsoft-Windows-PowerShell/Operational" /c:50 /rd:true /f:text # Scheduled tasks wevtutil qe "Microsoft-Windows-TaskScheduler/Operational" /c:50 /rd:true /f:text
EXPORT LOGS#
wevtutil epl Security C:\security.evtx wevtutil epl System C:\system.evtx wevtutil epl Application C:\app.evtx # Export with query wevtutil epl Security C:\failed_logins.evtx /q:"*[System[EventID=4625]]" # Archive and clear wevtutil al C:\archive\security.evtx wevtutil cl Security /bu:C:\backup\security.evtx
CLEAR LOGS#
wevtutil cl Security # Clear Security log
wevtutil cl System # Clear System log
wevtutil cl Application # Clear Application log
# Backup before clear
wevtutil cl Security /bu:C:\backup\security.evtx
# Clear all logs (admin required)
for /f %x in ('wevtutil el') do wevtutil cl "%x"
LOG CONFIGURATION#
wevtutil sl Security /e:true # Enable log wevtutil sl Security /e:false # Disable log wevtutil sl Security /ms:20971520 # Max size (bytes) wevtutil sl Security /rt:true # Retention (don't overwrite)
PUBLISHERS#
wevtutil ep # List publishers wevtutil gp Microsoft-Windows-Security-Auditing
REMOTE QUERIES#
wevtutil qe Security /r:COMPUTER /u:DOMAIN\User /p:Password /c:10 /f:text wevtutil gl Security /r:COMPUTER wevtutil epl Security \\COMPUTER\C$\security.evtx /r:COMPUTER
SYSMON EVENTS#
# If Sysmon is installed wevtutil qe "Microsoft-Windows-Sysmon/Operational" /c:100 /rd:true /f:text # Sysmon Event IDs # 1 - Process creation # 2 - File creation time changed # 3 - Network connection # 5 - Process terminated # 6 - Driver loaded # 7 - Image loaded # 8 - CreateRemoteThread # 10 - ProcessAccess # 11 - FileCreate # 12-14 - Registry events # 22 - DNS query
SECURITY ANALYSIS#
# Recent logon failures wevtutil qe Security /q:"*[System[EventID=4625]]" /c:100 /rd:true /f:text | findstr /i "TargetUserName" # Admin logons wevtutil qe Security /q:"*[System[EventID=4672]]" /c:50 /rd:true /f:text # Account creation wevtutil qe Security /q:"*[System[EventID=4720]]" /c:20 /f:text # Service installations wevtutil qe System /q:"*[System[EventID=7045]]" /c:20 /f:text # Clear events (track attackers clearing logs) wevtutil qe Security /q:"*[System[EventID=1102]]" /f:text
INCIDENT RESPONSE#
# Export all important logs wevtutil epl Security C:\IR\security.evtx wevtutil epl System C:\IR\system.evtx wevtutil epl Application C:\IR\application.evtx wevtutil epl "Microsoft-Windows-PowerShell/Operational" C:\IR\powershell.evtx wevtutil epl "Microsoft-Windows-TaskScheduler/Operational" C:\IR\taskscheduler.evtx
QUICK REFERENCE#
# List logs wevtutil el # Query events wevtutil qe Security /c:50 /rd:true /f:text wevtutil qe Security /q:"*[System[EventID=4624]]" /f:text # Export logs wevtutil epl Security C:\security.evtx # Clear logs wevtutil cl Security wevtutil cl Security /bu:C:\backup.evtx # Log info wevtutil gl Security wevtutil gli Security # Common Event IDs # 4624 - Successful logon # 4625 - Failed logon # 4688 - Process created # 4720 - User created # 7045 - Service installed