Windows Event Logs

Windows Event Logs

One-liner: Built-in Windows logging subsystem capturing system, security, application, and application-specific provider events.

🎯 What Is It?

Event Logs store structured records from the OS and applications. Key channels include System, Application, Security, and provider logs like Microsoft-Windows-Sysmon/Operational.

🤔 Why It Matters

🔬 How It Works

Core Principles

  1. Channels/providers emit events with IDs and fields.
  2. Event Log service controls collection and persistence.
  3. Forwarding (WEF) centralises logs for analysis.

Technical Deep-Dive

🛡️ Detection & Prevention

How to Detect

How to Prevent / Mitigate