โ† All cheat sheets

WEVTUTIL

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Windows Event Log Utility.
Query, export, archive, and clear Windows event logs.

LOG INFORMATION#


    

LIST LOGS#

wevtutil el                          # List all log names
wevtutil el | find "Security"        # Filter by name
wevtutil el | findstr /i "powershell"

LOG INFO#

wevtutil gl Security                 # Log configuration
wevtutil gl System                   # System log info
wevtutil gli Security                # Log statistics

# Shows: enabled, retention, max size, log path

QUERY EVENTS#


    

BASIC QUERY#

wevtutil qe Security                 # Query Security log
wevtutil qe System                   # Query System log
wevtutil qe Application              # Query Application log

OPTIONS#

/c:n                                 # Count (max events)
/rd:true                             # Reverse direction (newest first)
/f:text                              # Format: xml, text, renderedxml
/e:root                              # Root element for XML

EXAMPLES#

wevtutil qe Security /c:10 /rd:true /f:text
wevtutil qe System /c:50 /rd:true /f:text
wevtutil qe Application /c:100 /f:xml > events.xml

XPATH QUERIES#

wevtutil qe Security /q:"*[System[EventID=4624]]" /f:text
wevtutil qe Security /q:"*[System[EventID=4625]]" /c:10 /f:text
wevtutil qe System /q:"*[System[Level=2]]" /f:text

# Event Levels
# 1 = Critical
# 2 = Error
# 3 = Warning
# 4 = Information
# 5 = Verbose

QUERY BY TIME#

wevtutil qe Security /q:"*[System[TimeCreated[@SystemTime>='2024-01-01T00:00:00.000Z']]]" /f:text

QUERY BY EVENT ID#

wevtutil qe Security /q:"*[System[EventID=4624 or EventID=4625]]" /f:text
wevtutil qe Security /q:"*[System[(EventID>=4624 and EventID<=4634)]]" /f:text

QUERY BY PROVIDER#

wevtutil qe Security /q:"*[System[Provider[@Name='Microsoft-Windows-Security-Auditing']]]"

COMMON SECURITY EVENT IDS#

# Logon Events
4624                                 # Successful logon
4625                                 # Failed logon
4634                                 # Logoff
4647                                 # User initiated logoff
4648                                 # Logon with explicit credentials
4672                                 # Special privileges assigned

# Account Management
4720                                 # User account created
4722                                 # User account enabled
4723                                 # Password change attempt
4724                                 # Password reset attempt
4725                                 # User account disabled
4726                                 # User account deleted
4728                                 # Member added to security group
4732                                 # Member added to local group

# Process Events
4688                                 # New process created
4689                                 # Process exited

# Object Access
4663                                 # Access to object
4656                                 # Handle to object requested

# Policy Changes
4719                                 # System audit policy changed
4739                                 # Domain policy changed

LOGON TYPES#

# Type 2  - Interactive (console)
# Type 3  - Network (SMB, shares)
# Type 4  - Batch (scheduled task)
# Type 5  - Service
# Type 7  - Unlock
# Type 8  - NetworkCleartext
# Type 9  - NewCredentials (runas)
# Type 10 - RemoteInteractive (RDP)
# Type 11 - CachedInteractive

USEFUL QUERIES#

# Failed logins
wevtutil qe Security /q:"*[System[EventID=4625]]" /c:50 /rd:true /f:text

# Successful logins
wevtutil qe Security /q:"*[System[EventID=4624]]" /c:50 /rd:true /f:text

# RDP logins (Type 10)
wevtutil qe Security /q:"*[System[EventID=4624] and EventData[Data[@Name='LogonType']='10']]" /f:text

# New processes
wevtutil qe Security /q:"*[System[EventID=4688]]" /c:100 /rd:true /f:text

# Services installed
wevtutil qe System /q:"*[System[EventID=7045]]" /f:text

# PowerShell execution
wevtutil qe "Microsoft-Windows-PowerShell/Operational" /c:50 /rd:true /f:text

# Scheduled tasks
wevtutil qe "Microsoft-Windows-TaskScheduler/Operational" /c:50 /rd:true /f:text

EXPORT LOGS#

wevtutil epl Security C:\security.evtx
wevtutil epl System C:\system.evtx
wevtutil epl Application C:\app.evtx

# Export with query
wevtutil epl Security C:\failed_logins.evtx /q:"*[System[EventID=4625]]"

# Archive and clear
wevtutil al C:\archive\security.evtx
wevtutil cl Security /bu:C:\backup\security.evtx

CLEAR LOGS#

wevtutil cl Security                 # Clear Security log
wevtutil cl System                   # Clear System log
wevtutil cl Application              # Clear Application log

# Backup before clear
wevtutil cl Security /bu:C:\backup\security.evtx

# Clear all logs (admin required)
for /f %x in ('wevtutil el') do wevtutil cl "%x"

LOG CONFIGURATION#

wevtutil sl Security /e:true         # Enable log
wevtutil sl Security /e:false        # Disable log
wevtutil sl Security /ms:20971520    # Max size (bytes)
wevtutil sl Security /rt:true        # Retention (don't overwrite)

PUBLISHERS#

wevtutil ep                          # List publishers
wevtutil gp Microsoft-Windows-Security-Auditing

REMOTE QUERIES#

wevtutil qe Security /r:COMPUTER /u:DOMAIN\User /p:Password /c:10 /f:text
wevtutil gl Security /r:COMPUTER
wevtutil epl Security \\COMPUTER\C$\security.evtx /r:COMPUTER

SYSMON EVENTS#

# If Sysmon is installed
wevtutil qe "Microsoft-Windows-Sysmon/Operational" /c:100 /rd:true /f:text

# Sysmon Event IDs
# 1  - Process creation
# 2  - File creation time changed
# 3  - Network connection
# 5  - Process terminated
# 6  - Driver loaded
# 7  - Image loaded
# 8  - CreateRemoteThread
# 10 - ProcessAccess
# 11 - FileCreate
# 12-14 - Registry events
# 22 - DNS query

SECURITY ANALYSIS#

# Recent logon failures
wevtutil qe Security /q:"*[System[EventID=4625]]" /c:100 /rd:true /f:text | findstr /i "TargetUserName"

# Admin logons
wevtutil qe Security /q:"*[System[EventID=4672]]" /c:50 /rd:true /f:text

# Account creation
wevtutil qe Security /q:"*[System[EventID=4720]]" /c:20 /f:text

# Service installations
wevtutil qe System /q:"*[System[EventID=7045]]" /c:20 /f:text

# Clear events (track attackers clearing logs)
wevtutil qe Security /q:"*[System[EventID=1102]]" /f:text

INCIDENT RESPONSE#

# Export all important logs
wevtutil epl Security C:\IR\security.evtx
wevtutil epl System C:\IR\system.evtx
wevtutil epl Application C:\IR\application.evtx
wevtutil epl "Microsoft-Windows-PowerShell/Operational" C:\IR\powershell.evtx
wevtutil epl "Microsoft-Windows-TaskScheduler/Operational" C:\IR\taskscheduler.evtx

QUICK REFERENCE#

# List logs
wevtutil el

# Query events
wevtutil qe Security /c:50 /rd:true /f:text
wevtutil qe Security /q:"*[System[EventID=4624]]" /f:text

# Export logs
wevtutil epl Security C:\security.evtx

# Clear logs
wevtutil cl Security
wevtutil cl Security /bu:C:\backup.evtx

# Log info
wevtutil gl Security
wevtutil gli Security

# Common Event IDs
# 4624 - Successful logon
# 4625 - Failed logon
# 4688 - Process created
# 4720 - User created
# 7045 - Service installed