from sysinternals pstool
examples:
C:\pstools>psloglist -a 1/09/07 app -f error >c:\error.txt
-a=from a date app=application log -f=filter by first letter
CODE
usage: psloglist [[\\computer[,computer[,..] | @file [-u user [-p psswd]]] [-s [-t delimiter]] [-n #|-h#|-d #] [-x] [-c][-r][-a mm/dd/yy][-b mm/dd/yy][-f filter] [-i ID[,ID[,..]] [-o event source] [-l event log file] [eventlog]
computer Perform the command on the remote computer or computers specified. If you omit the computer name the command runs on the local system, and if you specify a wildcard (\\*), the command runs on all computers in the current domain.
@file Run the command on each computer listed in the text file specified.
-u Specifies optional user name for login to remote computer.
-p Specifies optional password for user name. If you omit this you will be prompted to enter a hidden password.
-s This switch has PsLogList print Event Log records one-per-line, with delimited fields. This format is convenient for text searches, e.g. psloglist | findstr /i text, and for importing the output into a spreadsheet.
-t The default delimeter for the -s option is a comma, but can be overriden with the specified character.
-n # Only display n most recent records.
-h # Only display records from previous n hours.
-d # Only display records from previous n days.
-c Clear the event log after displaying.
-x Dump extended data.
-r Dump log from least recent to most recent.
-a Dump records timestamped after specified date.
-b Dump records timestamped before specified date.
-f Filter event types with filter string (e.g. "-f w" to filter warnings).
-i Show only events with the specified ID or IDs (up to 10).
-o Show only records from the specified event source (e.g. "-o cdrom").
-l Dump the contents of the specified saved event log file.
eventlog By default PsLogList shows the contents of the System Event Log. Specify a different Event Log by typing in the first few letters of the log name, application, system, or security. If the -l switch is present then the event log name specifies how to interpret the event log file.
Latest Security News
-
-
Windows 11 24H2 Home and Pro reach end of support in 2 months - Microsoft has reminded customers that systems running Home and Pro editions of Windows 11 24H2 will stop receiving updates in two months. [...]21 hours ago
-
ClickFix on Steam forums: how malicious PowerShell commands install a crypto miner | Kaspersky official blog - Attackers are targeting Steam forums with malicious PowerShell commands disguised as fixes for game launch issues. Here’s how this version of the ClickFix ...2 days ago
-
GeoServer Zero-Day Is Already Being Probed. That’s the Problem - GeoServer faces an unpatched zero-day enabling SQL injection and potentially RCE, with attackers already probing exposed systems. A newly disclosed GeoServ...4 days ago
-
The controls your developers never see - The controls your developers never see Elusive Thoughts // AppSec The controls your developers never see We rebuilt the SDLC for agent-assisted engineer...5 days ago
-
Who’s Tracking You? Use This New Service to Find Out - It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every day....5 days ago
-
Cybercrime Forum .SQL Dumps - 2009-2024 - An Analysis - Part Two - Dear blog readers, The following is a set of private messages exports for RAMP, XSS, Breached Forums, Carder Pro and Verified cybercrime forums. *Sample ...1 week ago
-
Overview of Content Published in July - Here is an overview of content I published in July: SANS ISC Diary entries: Wireshark 4.6.7 Released zipdump.py: Metadata Encoding2 weeks ago
-
הגליון המאה שמונים ושמונה של DigitalWhisper שוחרר! - הגליון המאה שמונים ושמונה של DigitalWhisper שוחרר!פורסם ב- July 31, 2026 03:38:26, על ידי- sapirxfed ברוכים הבאים לדברי הפתיחה של הגליון ה-188 של Digital...2 weeks ago
-
FreeBSD Released the Most Security Advisories in Project History in June 2026 - On average, the FreeBSD security team releases about 2 security advisories per month. AI has changed this. In April, the project released 8 advisories, w...4 weeks ago
-
Recommended: MCP Is Broken and Anthropic Just Admitted It - I recommended MCP Is Broken and Anthropic Just Admitted It on TysonRhame. About me: http://www.chuvakin.org8 months ago
-
BestAV (Fake Antispyware affiliate) exposed - Hello everyone, it's been a while. One of the first affiliate systems I ever infiltrated was BestAV, back in 2011, the same year I started XyliBox. Over...11 months ago
-
רעיון לשיפור אבטחת SSL VPN – צמצום משטח התקיפה של ה-Gateway על ידי מתן גישה רק ללקוחות DDNS שאושרו מראש - (שלום רב קוראים יקרים – אם אתם מכירים מישהו שעובד עבור יצרנית של SSL VPN – בפיתוח תוכנה, ניהול מוצר וכדומה, אנא שלחו לו או לה קישור לפוסט הזה, בתקווה שהר...1 year ago
-
Readying hospital defenses for the AI-powered phishing surge - Artificial Intelligence Privacy & Security Workforce As phishing tactics evolve, healthcare organizations need to act quickly to shore up defenses and close...1 year ago
-
How Security and Privacy Teams Break Barriers Together - While cybersecurity and data privacy leaders have distinct expertise, our fundamental goals are aligned. By understanding each other’s perspectives and pri...1 year ago
-
Shodan-Dorks - Dorks for Shodan; a powerful tool used to search for Internet-connected devices - This GitHub repository provides a range of search queries, known as "dorks," for Shodan, a powerful tool used to search for Internet-connected devices. T...1 year ago
-
Andrew Hay’s 2025 Cybersecurity Predictions - As we approach 2025, the ever-evolving landscape of cybersecurity continues to challenge professionals and organizations alike. Based on observed trends an...1 year ago
-
North Korean hackers posing as IT workers steal over $1B in cyberattack - North Korean hackers posing as IT workers steal over $1B in cyberattack l33tdawg Fri, 11/29/2024 - 10:311 year ago
-
-
Strengthening Security: ToolsWatch Welcomes Dr. Magda Lilia Chelly and Vivek Ramachandran to Black Hat Arsenal’s Board of Review - In the ever-evolving landscape of cybersecurity, staying ahead of the curve is paramount. As digital2 years ago
-
What a lovely sunset - Oh, hi. Long time no blog, eh? Well, it is time to sunset this blog, I will be deleting it in the next few weeks. So long, and thanks for all the fis...3 years ago
-
Simple PHP webshell with php filter chains - Recently found an LFI in a PHP application and one of the cool things I learned about recently was PHP filter chains. More info here: https://www.synacktiv...3 years ago
-
A Scam in the Family—How a Close Relative Lost $100,000 to an Elder Scam - Written by James Schmidt Editor’s Note: We often speak of online scams in our blogs, ones that cost victims hundreds... The post A Scam in the Family—Ho...3 years ago
-
Symantec Identity: Stepping Up to Meet the COVID-19 Crisis - COVID-19 confronted healthcare providers and governments with unprecedented requests for access, aid, and assistance. Here’s how one team at Symantec is ri...6 years ago
-
Getting DNS Client Cached Entries with CIM/WMI - What is DNS Cache The DNS cache maintains a database of recent DNS resolution in memory. This allows for faster resolution of hosts that have been queried ...6 years ago
-
How Reverse Engineering (and Cyber-Criminals’ Mistakes) Can Help You When You’ve Been a Ransomware Victim - Ransomware is a type of malware that threatens to publish the victim’s data or perpetually block access to it unless a ransom is paid. In the last two year...7 years ago
-
Tencent Shuts Down PUBG Mobile in China For Patriotic Alternative - Slashdot - Full Abbreviated Hidden /Sea Score: 5 4 3 2 1 0 -17 years ago
-
Random CSO Musing - One of the biggest challenges of running a security organization is balancing the ongoing efforts, with strategic directions, all while keeping the “pressu...7 years ago
-
Lucky Break - One of the things I do from time to time is throw out an open ended question on Twitter. Sometimes I’m making a point, sometimes I just want to amuse myse...7 years ago
-
Indonesian Spam Communities - In our last post we tried to shed some light at what seemed to appear as a very common PayPal phishing email at first glance, but evidently turned out to b...7 years ago
-
TekThing 161 – Bitcoin Sucks For Gaming PCs!!! Our Video Gear, Fingbox Home Network Security - —— Thank You Patrons! Without your support via patreon.com/tekthing, we wouldn’t be able to make the show for you every week! https://www.patreon.com/tekth...8 years ago
-
Romania is vice-champion at the European Cyber Security - CERT-RO The National Response Center for Cyber Security Incidents affirmed on Friday that Romania, for the second consecutive year, has become the European...8 years ago
-
CoalaBot : http Ddos Bot - CoalaBot appears to be build on August Stealer code (Panel and Traffic are really alike) I found it spread as a tasks in a Betabot and in an Andromeda sp...8 years ago
-
Social-Engineer Toolkit (SET) v7.7 “Blackout” Released - TrustedSec is proud to announce a major release of the Social-Engineer Toolkit (SET) v7.7. This version incorporates support for hostnames in the HTA att...9 years ago
-
Big Changes Around the Corner for the IoT - The IoT is transforming before our eyes due to increasing regulations, growing demand for security standards and advancements in the telecom industry. T...9 years ago
-
ClearEnergy ransomware can destroy process automation logics in critical infrastructure, SCADA and industrial control systems. - Schneider Electric, Allen-Bradley, General Electric (GE) and more vendors are vulnerable to ClearEnergy ransomware. Researchers at CRITIFENCE® Critical I...9 years ago
-
ROOTCON 10 Capture The Flag Statistics - During ROOTCON 10, we introduced a new dedicated track for our Capture The Flag, with the comfortable CTF tables and chairs the game was well participated ...9 years ago
-
קיר הבושה: מחצית ראשונה של שנת 2016 - מגמות בפגיעה במידע רפואי בארה"ב - תרגום מאמר : http://www.healthcareinfosecurity.com/wall-shame-mid-year-2016-breach-trends-a-9245 שני דברים שאני, יאיר, לוקח מהמאמר הזה כלקחים נכון להיום:1....10 years ago
-
The ‘Compliance Only / CISSP / Minimum Viable Product / HR firewall’ infosec trapezoid of fuck - Yesterday (thurs, 3/24/16) I went on a tirade on twitter, regarding an experience I had in San Francisco during RSA week, while at a vendor party. I’ll let...10 years ago
-
Dridex Down Under - Raytheon | Websense® Security Labs™ has been tracking malicious email campaigns associated with the Dridex banking Trojan since 2014. An interesting deve...10 years ago
-
[Updated] Nurturing JavaScript Obfuscation and Fast Flux DNS - "Whats App Voicemail Spamming" for Russian Online Pharmacies! - Recently, we analyzed that spammers are doing "Whats App Fake Voicemail" spamming to trick end-users to visit online pharmacies' websites. There are high...10 years ago
-
What Verizon Missed in the Latest Threat Reports - * By: Zuk Avraham, Joshua Drake, Yaniv Karta, Jimmy Sha * * Read the full report - here Recently, Veriz...11 years ago
-
Forensic - אחת מהבעיות העיקריות בביצוע תהליך FORENSIC הוא לאחר ביצוע תהליך שיכפול ה - Harddisk (על פי כל התקנים של שיכפול ביט אחרי ביט), היא לבצע מחקר על *מחשב חי...11 years ago
-
-
TrustKeeper Scan Engine Update – February 4, 2015 - The latest update to the TrustKeeper scan engine that powers our Trustwave Vulnerability Management product (including both internal and external vulnerabi...11 years ago
-
RSA Announces End of RSA Security Conference - Aims to bring clarity to cloudy marketing messages through exhibit hall chotskies Bedford, MA., – April 1, 2014 – RSA, the security division of EMC, today ...12 years ago
-
botCloud – an emerging platform for cyber-attacks - Hosting network services on Cloud platforms is getting more and more popular. It is not in the scope of this article to elaborate the advantage of using Cl...13 years ago
-
mimikatz: Tool To Recover Cleartext Passwords From Lsass - I meant to blog about this a while ago, but never got round to it. Here’s a brief post about very cool feature of a tool called mimikatz. I’m very grateful...14 years ago
-
-
-
-
-
-
-
-
-
-