Sysmon

Windows Privesc

Windows Event Logs and Forensic Artifacts: Tracking and Tampering

How Windows Security event logs record attacker activity, how adversaries clear them, and how defenders detect tampering.