I have a very specific question. I'm in the middle of an assignment for school and my team is stuck at a part where we need to recover a password from the Event Logs that was purposely placed in there. He said there should be logs that have the password included in them that were man-made but we have no idea where to look. We've looked through the 4688, 4723, 4724 event logs, as well as the rest of them even though they don't apply much to this situation, to see if maybe there is custom information that's placed that includes a password but we can't find anything. There are logs where we can see that users were made and changes were made to their accounts/passwords and then one user was disabled and deleted but is there a way to actually get more information from an event log using PowerShell? We've been using MyEventViewer for the event logs but are really lost at this point. Our teacher said that he was able to get the password by using PowerShell. Does anyone have any idea as to how we could go about getting the password for a user like that going through PowerShell? It's the Domain Admin accounts password that we're looking for and it's also the same password for a KeePass database file that we need to unlock and then perform a live response after. Even if anyone knew how you can input your password into an event log, that would also really help so we can backtrack to see about exporting it. Any information would be greatly appreciated, thanks!
How to find a password that was purposely recorded in Event Logs with PowerShell?
957 views Asked by Pacman12312 At
0
There are 0 answers
Related Questions in POWERSHELL
- PowerShell Linphone Configuration
- How avoid \t being converted to Tab in Powershell
- How do I get my terminal to work in VS Code? Exit Code:2, doesn't allow me to type anything
- Npm command not working in powershell but works in cmd
- Issue with path not being treated as encapsulated when calling cmd /C
- Native command throws error only when I redirect to a variable
- Logic Apps and long running Azure Function (Powershell)
- April fools - PsExec (PsTools)
- How to use nested ForEach-Object
- Batch Script-Powershell MessageBox | How do I set TopMost within PS command line of Batch?
- Execution Stuck at Get-PnPPage if function executed on Button Click
- How can I expand a column from group output?
- How to use expression in regex -replace with capturing group in powershell
- powershell where-object -cnotmatch filter unwanted lines
- How to make Visual Studio 2022 project launch Windows Terminal instead of PowerShell?
Related Questions in EVENT-LOG
- c++ read windows's event log by source
- How do I log the actual SOAP requests in XML format
- Not getting event data from windows 10 in rsyslog, using NXLog-CE as log forwarding agent
- R bupar: Get trace for each case
- WMI with Python
- Reading and formatting events from Windows Event Log
- Quickest way to get the event log description using EventRecord object, FormatDescription takes longer causing the delay in searching in description
- Converting a log.txt file to JSON using python
- Zabbix - Filter log based on contents
- Windows Event Viewer: filter for specific file extension with wildcard in xPath
- How to connect to a specific nested event log in a C# program?
- MongoDB: conditional updates to array fields in a single document
- Containers - Writing to Windows Event log from Containers throwing error "Inaccessible logs"
- Get last Windows/PC shutdown time with VBA
- Strings won't write to the console together in C#
Related Questions in PASSWORD-ENCRYPTION
- Encrypt data in flutter with a public key
- I am encrypting password using SHA2_256 hashbytes converter in SQL; now I want to see the orginal data
- Hoa can I get the session id and pass it to an encryption function?
- DB2 encrypt() problem with PHP and parameterised query
- JSR223 Pre Password Encryption database connection errors
- Problem in JSR223 script JSR223 Sampler:javax.script.ScriptException: groovy.lang.MissingMethodException: No signature of method:
- How to store key from an encrypted prepopulated db in an Android App
- EDR Detection For A Clear Password For Websphere Password
- App's PIN code resistance against Android's root user
- Should a password salt be stored in a database
- need help decoding using cryptography fernet
- How to Improve a Password Validation Function in PHP: Ensuring Strong Security and Proper Function Typing
- User Validation Node.js/MySql
- JMeter Password Encryption
- Laravel - Login Laravel - Passowrd HashBytes ('mD5')
Related Questions in KEEPASS
- Creating DB of Keepass returns Error InvalidArg: data using kdbxweb Library
- Cannot invoke "de.slackspace.openkeepass.domain.CrsAlgorithm.ordinal()" because "algorithm" is null - KeePassXC 2.7.4 with Spring Boot - stoped work
- Need Script for Deploying KeePass to my Users Share Drives
- My Keepass file .kdbx is impossible to open or repair because of corrupted header
- Batch. How to define the first line of command output into a variable?
- Flask app fails to load keepass file after a certain amount of time, when deployed as a service on centos7
- Hand Masterpassword to keepassxc-cli (or retrieve entry from keepassxc by vba)
- kdbxweb usage for creating dbs, storing and retrieving passwords for use in scripts/jobs
- Why is shadowRoot null?
- How to prevent mouse-leave for plugin icon?
- How to create kdbx file in python
- Use KEE PASS in Powershell Script to pass Username and Password
- Bash script using Expect working fine locally but fails in a gitlab-ci job
- Python. How to deal with No module named 'construct' when installing pykeepass?
- Accessing keepass databass returns KdbxError: Error BadSignature
Popular Questions
- How do I undo the most recent local commits in Git?
- How can I remove a specific item from an array in JavaScript?
- How do I delete a Git branch locally and remotely?
- Find all files containing a specific text (string) on Linux?
- How do I revert a Git repository to a previous commit?
- How do I create an HTML button that acts like a link?
- How do I check out a remote Git branch?
- How do I force "git pull" to overwrite local files?
- How do I list all files of a directory?
- How to check whether a string contains a substring in JavaScript?
- How do I redirect to another webpage?
- How can I iterate over rows in a Pandas DataFrame?
- How do I convert a String to an int in Java?
- Does Python have a string 'contains' substring method?
- How do I check if a string contains a specific word?
Trending Questions
- UIImageView Frame Doesn't Reflect Constraints
- Is it possible to use adb commands to click on a view by finding its ID?
- How to create a new web character symbol recognizable by html/javascript?
- Why isn't my CSS3 animation smooth in Google Chrome (but very smooth on other browsers)?
- Heap Gives Page Fault
- Connect ffmpeg to Visual Studio 2008
- Both Object- and ValueAnimator jumps when Duration is set above API LvL 24
- How to avoid default initialization of objects in std::vector?
- second argument of the command line arguments in a format other than char** argv or char* argv[]
- How to improve efficiency of algorithm which generates next lexicographic permutation?
- Navigating to the another actvity app getting crash in android
- How to read the particular message format in android and store in sqlite database?
- Resetting inventory status after order is cancelled
- Efficiently compute powers of X in SSE/AVX
- Insert into an external database using ajax and php : POST 500 (Internal Server Error)