A FORENSIC PERSPECTIVE ON THE USE OF EVENT VIEWER FOR DETECTING MALICIOUS ACTIVITIES AND ENSURING SYSTEM INTEGRITY

  • Patel P
  • Bhatt P
  • Parmar U
  • et al.
N/ACitations
Citations of this article
5Readers
Mendeley users who have this article in their library.

Abstract

Event Viewer is a vital tool embedded within Microsoft Windows that records a wide range of system, security, and application-related events. For forensic investigators, these logs are crucial in identifying signs of malicious activities, reconstructing timelines, and maintaining system integrity. This paper highlights the role of Event Viewer in digital forensics, discussing how specific logs from various categories—Application, Security, Setup, System, and Forwarded Events—can be extracted, parsed, and stored in XML format for in-depth analysis. Furthermore, the paper proposes a structured XML-based data model for efficient forensic storage and analysis, compares it with other log management approaches, and demonstrates its effectiveness in digital investigations.

Cite

CITATION STYLE

APA

Patel, P., Bhatt, P. M., Parmar, U., & Keval Bhavsar. (2024). A FORENSIC PERSPECTIVE ON THE USE OF EVENT VIEWER FOR DETECTING MALICIOUS ACTIVITIES AND ENSURING SYSTEM INTEGRITY. ShodhKosh: Journal of Visual and Performing Arts, 5(1). https://doi.org/10.29121/shodhkosh.v5.i1.2024.5975

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free