Incident Response with EZTools - Event Logs Parsing
EvtxECmd is bundled with EZTools. A short word for Event Log Parser.
From an incident response perspective, it is necessary for the responder to have the ability and skill to quickly triage to patient zero and identify the cause or action performed before the incident was detected.
During an incident, an action may be performed which causes our system to behave in an odd way. Getting an evidence of these actions on the system through event logs can aid the responders to follow the breadcrumbs that can be used to timeline an event.