{"id":531,"date":"2022-05-17T22:15:49","date_gmt":"2022-05-17T22:15:49","guid":{"rendered":"https:\/\/eventlogxp.com\/blog\/?p=531"},"modified":"2022-05-18T08:41:05","modified_gmt":"2022-05-18T08:41:05","slug":"files-in-event-log-explorer-forensic-edition-searching-for-removed-events","status":"publish","type":"post","link":"https:\/\/eventlogxp.com\/blog\/files-in-event-log-explorer-forensic-edition-searching-for-removed-events\/","title":{"rendered":"Files in Event Log Explorer Forensic Edition. Searching for removed events"},"content":{"rendered":"<p>Although Standard Edition of Event Log Explorer works with event log files perfectly, you may need more functionality when analyzing damaged or intentionally modified event log files. I\u2019m starting a series of articles about the advanced use of Event Log Explorer Forensic Edition with files.<\/p>\n<p>Let\u2019s imagine that you examine an event log with removed events. If you believe that it\u2019s impossible to remove events from an event log, I will show how to do it.<\/p>\n<p>I will remove logon events from Security event log as follows:<\/p>\n<p>Start Windows Event Viewer.<\/p>\n<p>Open a log file (I take Security.evtx from my old archive, but you can use it even with the live Security log).<\/p>\n<p>Set Filter in Event Viewer to exclude events 4624 (of course you can set any filter you want).<\/p>\n<p><a href=\"http:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2022\/05\/EventViewer-Hide-Logon-4624.png\" data-rel=\"lightbox-gallery-eBNUAqOD\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" class=\"alignnone size-medium wp-image-532\" src=\"http:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2022\/05\/EventViewer-Hide-Logon-4624-300x292.png\" alt=\"\" width=\"300\" height=\"292\" srcset=\"https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2022\/05\/EventViewer-Hide-Logon-4624-300x292.png 300w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2022\/05\/EventViewer-Hide-Logon-4624.png 620w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>Click \u201cSave Filtered Log File As\u201d and save it as EVTX file.<\/p>\n<p>Voila, you have a new event log file with removed events. You can open it with Event Viewer or Event Log Explorer and don\u2019t even expect that it\u2019s not an authentic event log. Of course, a real malefactor should replace a live event log with the forged one, but it\u2019s not an impossible task. If s\/he has a physical access to the computer, it\u2019s possible to replace C:\\Windows\\System32\\WinEvt\\Logs\\Security.evtx by loading the computer in recovery console. It\u2019 much harder to forge the log remotely, but still possible by exploiting system vulnerabilities (e.g \u201cVault 7\u201d hacking tool set lets you exploit such vulnerabilities and remove events).<\/p>\n<p>And how can we detect if the examined event log file misses events? We discovered that Event Viewer (more accurately Event Log API) just copies the events into a new file as is. So, all events in the new log file will have the same record number as they had in the original event log. If we scan all the events, we can easily detect missed record numbers.<\/p>\n<p>This functionality is implemented in Event Log Explorer Forensic Edition. Select Forensics from the main menu, click Forensic Open File, add your files by clicking Add button and enable option \u201cCheck log files for deleted events\u201d. You will have the list of potentially deleted events.<\/p>\n<p><a href=\"http:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2022\/05\/EventLog-detection-of-removed-records.png\" data-rel=\"lightbox-gallery-eBNUAqOD\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" class=\"alignnone size-medium wp-image-533\" src=\"http:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2022\/05\/EventLog-detection-of-removed-records-300x232.png\" alt=\"\" width=\"300\" height=\"232\" srcset=\"https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2022\/05\/EventLog-detection-of-removed-records-300x232.png 300w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2022\/05\/EventLog-detection-of-removed-records-768x594.png 768w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2022\/05\/EventLog-detection-of-removed-records-660x510.png 660w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2022\/05\/EventLog-detection-of-removed-records.png 942w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>You may be wondering if it is possible to forge an event log in such a way that it will fix the record numbers making it indistinguishable from non-edited log. It was easy for legacy evt logs, but very hard for the modern evtx event logs. I cannot state that it\u2019s impossible, however I never seen any tools or a sample code that can do such tricks. That\u2019s why I believe that Event Log Explorer can detect events deletion in event logs.<\/p>\n<p><a href=\"https:\/\/eventlogxp.com\/download.php\">Download Event Log Explorer Forensic Edition<\/a> and check if your log files have no deleted events!<\/p>\n<a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-facebook nolightbox\" data-provider=\"facebook\" target=\"_blank\" rel=\"nofollow\" title=\"Share on Facebook\" href=\"https:\/\/www.facebook.com\/sharer.php?u=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F531&#038;t=Files%20in%20Event%20Log%20Explorer%20Forensic%20Edition.%20Searching%20for%20removed%20events&#038;s=100&#038;p&#091;url&#093;=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F531&#038;p&#091;images&#093;&#091;0&#093;=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-content%2Fuploads%2F2022%2F05%2Fdeleted-events.png&#038;p&#091;title&#093;=Files%20in%20Event%20Log%20Explorer%20Forensic%20Edition.%20Searching%20for%20removed%20events\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px;margin-right:5px\"><img alt=\"Facebook\" title=\"Share on Facebook\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/facebook.png\" \/><\/a><a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-twitter nolightbox\" data-provider=\"twitter\" target=\"_blank\" rel=\"nofollow\" title=\"Share on Twitter\" href=\"https:\/\/twitter.com\/intent\/tweet?url=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F531&#038;text=Check%20this%20Event%20Log%20Explorer%20blog%20post\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px;margin-right:5px\"><img alt=\"twitter\" title=\"Share on Twitter\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/twitter.png\" \/><\/a><a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-reddit nolightbox\" data-provider=\"reddit\" target=\"_blank\" rel=\"nofollow\" title=\"Share on Reddit\" href=\"https:\/\/www.reddit.com\/submit?url=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F531&#038;title=Files%20in%20Event%20Log%20Explorer%20Forensic%20Edition.%20Searching%20for%20removed%20events\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px;margin-right:5px\"><img alt=\"reddit\" title=\"Share on Reddit\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/reddit.png\" \/><\/a><a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-pinterest nolightbox\" data-provider=\"pinterest\" target=\"_blank\" rel=\"nofollow\" title=\"Pin it with Pinterest\" href=\"https:\/\/pinterest.com\/pin\/create\/button\/?url=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F531&#038;media=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-content%2Fuploads%2F2022%2F05%2Fdeleted-events.png&#038;description=Files%20in%20Event%20Log%20Explorer%20Forensic%20Edition.%20Searching%20for%20removed%20events\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px;margin-right:5px\"><img alt=\"pinterest\" title=\"Pin it with Pinterest\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/pinterest.png\" \/><\/a><a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-linkedin nolightbox\" data-provider=\"linkedin\" target=\"_blank\" rel=\"nofollow\" title=\"Share on Linkedin\" href=\"https:\/\/www.linkedin.com\/shareArticle?mini=true&#038;url=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F531&#038;title=Files%20in%20Event%20Log%20Explorer%20Forensic%20Edition.%20Searching%20for%20removed%20events\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px;margin-right:5px\"><img alt=\"linkedin\" title=\"Share on Linkedin\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/linkedin.png\" \/><\/a><a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-mail nolightbox\" data-provider=\"mail\" rel=\"nofollow\" title=\"Share by email\" href=\"mailto:?subject=Files%20in%20Event%20Log%20Explorer%20Forensic%20Edition.%20Searching%20for%20removed%20events&#038;body=Check%20this%20Event%20Log%20Explorer%20blog%20post:%20https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F531\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px\"><img alt=\"mail\" title=\"Share by email\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/mail.png\" \/><\/a>","protected":false},"excerpt":{"rendered":"<p>Although Standard Edition of Event Log Explorer works with event log files perfectly, you may need more functionality when analyzing damaged or intentionally modified event log files. I\u2019m starting a series of articles about the advanced use of Event Log Explorer Forensic Edition with files. Let\u2019s imagine that you examine an event log with removed events. If you believe that it\u2019s impossible to remove events\u2026 <span class=\"read-more\"><a href=\"https:\/\/eventlogxp.com\/blog\/files-in-event-log-explorer-forensic-edition-searching-for-removed-events\/\">Read More &raquo;<\/a><\/span><\/p>\n","protected":false},"author":2,"featured_media":534,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[40,7],"tags":[51,67,49],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/posts\/531"}],"collection":[{"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/comments?post=531"}],"version-history":[{"count":3,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/posts\/531\/revisions"}],"predecessor-version":[{"id":537,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/posts\/531\/revisions\/537"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/media\/534"}],"wp:attachment":[{"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/media?parent=531"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/categories?post=531"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/tags?post=531"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}