Windows Event Logs record operating system activity, including PowerShell use, event-log deletion, service starts and stops, and RDP activity. Each record has an Event ID that distinguishes the event type.

Log Types

LogDescription
ApplicationEvents relating to applications on the system.
SystemEvents relating to basic system components.
SecuritySecurity events.

Event Viewer

Open Windows + R, then enter eventvwr.

Windows security event log cheatsheet.

Query Events

OptionDescription
query-eventsQuery events from a log or log file.
/rdReverse direction.
/countLog count.
/formatOutput format.
/qXPath query.
# query the most recent Security event with Event ID 4625
wevtutil query-events Security /rd:true /count:1 /format:text /q:"Event[System[(EventID=4625)]]"