User Actions and Events List
Created by using LastActivityView
File
Action Exte
Description Filename Full Path More Information
Time nsio
n
07/05/20
CreateObjectTask,
21 Task Run [Link] C:\Windows\system32\[Link] dll
\Microsoft\Windows\Shell\CreateObjectTask
[Link]
07/05/20
21 User Logon WORKGROUP\Administrador
[Link]
07/05/20
Open file or C:\Users\Administrador\Desktop\mimikatz_t
21 mimikatz_trunk.zip zip
folder [Link]
[Link]
07/05/20
View Folder in
21 Z:\
Explorer
[Link]
07/05/20
C:\Program Files
21 Task Run [Link] GoogleUpdateTaskMachineUA, \GoogleUpdateTaskMachineUA exe
(x86)\Google\Update\[Link]
[Link]
07/05/20
wuautoappupdate. Automatic App Update,
21 Task Run C:\Windows\System32\[Link] dll
dll \Microsoft\Windows\WindowsUpdate\Automatic App Update
[Link]
07/05/20
Open file or C:\Users\Administrador\Desktop\gentilkiwi-
21 mimikatz
folder mimikatz-09fb1f6\mimikatz
[Link]
07/05/20
Open file or C:\Users\Administrador\Desktop\gentilkiwi-
21 [Link] ico
folder mimikatz-09fb1f6\mimikatz\[Link]
[Link]
07/05/20
21 User Logon WORKGROUP\DWM-3
[Link]
07/05/20
21 User Logon WORKGROUP\Administrador
[Link]
07/05/20
21 User Logon WORKGROUP\DWM-2
[Link]
07/05/20
21 User Logon WORKGROUP\Administrador
[Link]
07/05/20 USO_UxBroker_Display,
[Link]
21 Task Run C:\Windows\system32\[Link] \Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_Dis exe
e
[Link] play
07/05/20
Open file or
21 curriculum C:\curriculum
folder
[Link]
07/05/20
Open file or
21 [Link] C:\curriculum\[Link] pdf
folder
[Link]
07/05/20 Select file in
21 open/save [Link] C:\curriculum\[Link] pdf
[Link] dialog-box
07/05/20 Select file in
21 open/save [Link] C:\curriculum\[Link] pdf
[Link] dialog-box
07/05/20
Open file or
21 C:\
folder
[Link]
07/05/20
Open file or
21 C:\
folder
[Link]
07/05/20
21 Task Run [Link] C:\Windows\system32\[Link] Proxy, \Microsoft\Windows\Autochk\Proxy exe
[Link]
07/05/20
Open file or
21 Desktop C:\Users\Administrador\Desktop
folder
[Link]
07/05/20 2.2.0 20200918
Open file or C:\Users\Administrador\Downloads\2.2.0
21 Zerologon zip
folder 20200918 Zerologon [Link]
[Link] [Link]
07/05/20
C:\Program Files GoogleUpdateTaskMachineCore,
21 Task Run [Link] exe
(x86)\Google\Update\[Link] \GoogleUpdateTaskMachineCore
[Link]
07/05/20 C:\Program
Software
21 [Link] Files\Google\Chrome\Application\[Link] Google Chrome exe
Installation
[Link] e
07/05/20 Installation,
LanguageCompone C:\Windows\System32\LanguageComponent
21 Task Run \Microsoft\Windows\LanguageComponentsInstaller\Installatio dll
[Link] [Link]
[Link] n
07/05/20
Scheduled Start,
21 Task Run [Link] C:\Windows\system32\[Link] exe
\Microsoft\Windows\WindowsUpdate\Scheduled Start
[Link]
07/05/20
Consolidator, \Microsoft\Windows\Customer Experience
21 Task Run [Link] C:\Windows\System32\[Link] exe
Improvement Program\Consolidator
[Link]
07/05/20
XblGameSaveTask. XblGameSaveTaskLogon,
21 Task Run C:\Windows\System32\[Link] exe
exe \Microsoft\XblGameSave\XblGameSaveTaskLogon
[Link]
07/05/20
SilentCleanup,
21 Task Run [Link] C:\Windows\system32\[Link] exe
\Microsoft\Windows\DiskCleanup\SilentCleanup
[Link]
07/05/20
XblGameSaveTask. XblGameSaveTask,
21 Task Run C:\Windows\System32\[Link] exe
exe \Microsoft\XblGameSave\XblGameSaveTask
[Link]
07/05/20
Schedule Scan,
21 Task Run [Link] C:\Windows\system32\[Link] exe
\Microsoft\Windows\UpdateOrchestrator\Schedule Scan
[Link]
07/05/20
QueueReporting, \Microsoft\Windows\Windows Error
21 Task Run [Link] C:\Windows\system32\[Link] exe
Reporting\QueueReporting
[Link]
07/05/20
Configuration, \Microsoft\Windows\Software Inventory
21 Task Run [Link] C:\Windows\system32\[Link] exe
Logging\Configuration
[Link]
07/05/20
21 Task Run [Link] C:\Windows\system32\[Link] CacheTask, \Microsoft\Windows\Wininet\CacheTask dll
[Link]
07/05/20
MsCtfMonitor,
21 Task Run [Link] C:\Windows\system32\[Link] dll
\Microsoft\Windows\TextServicesFramework\MsCtfMonitor
[Link]
07/05/20
ServerManagerLau C:\Windows\system32\ServerManagerLaunc ServerManager, \Microsoft\Windows\Server
21 Task Run exe
[Link] [Link] Manager\ServerManager
[Link]
07/05/20
UserTask,
21 Task Run [Link] C:\Windows\system32\[Link] dll
\Microsoft\Windows\CertificateServicesClient\UserTask
[Link]
07/05/20
21 User Logon WORKGROUP\Administrador
[Link]
07/05/20
SystemTask,
21 Task Run [Link] C:\Windows\system32\[Link] dll
\Microsoft\Windows\CertificateServicesClient\SystemTask
[Link]
07/05/20
Tpm-Maintenance, \Microsoft\Windows\TPM\Tpm-
21 Task Run [Link] C:\Windows\system32\[Link] dll
Maintenance
[Link]
07/05/20
21 System Started
[Link]
07/05/20
21 Task Run [Link]" "C:\Program Files\Npcap\[Link]" npcapwatchdog, \npcapwatchdog bat"
[Link]
07/05/20
21 Task Run [Link] C:\Windows\system32\[Link] Device, \Microsoft\Windows\Device Information\Device exe
[Link]
07/05/20
21 User Logon WORKGROUP\DWM-1
[Link]
07/05/20
System
21
Shutdown
[Link]
07/05/20
21 User Logoff WIN-SF01JTM2DHI\Administrador
[Link]
07/05/20
21 User Logon WORKGROUP\Administrador
[Link]
07/05/20
21 System Started
[Link]
07/05/20
21 User Logon WORKGROUP\DWM-1
[Link]
07/05/20
System
21
Shutdown
[Link]
07/05/20
21 User Logoff WIN-SF01JTM2DHI\Administrador
[Link]
07/05/20
21 User Logon WORKGROUP\Administrador
[Link]
07/05/20
21 System Started
[Link]
07/05/20
21 User Logon WORKGROUP\DWM-1
[Link]
07/05/20
System
21
Shutdown
[Link]
07/05/20
21 User Logoff WIN-SF01JTM2DHI\Administrador
[Link]
07/05/20
SmartScreenSpecific,
21 Task Run [Link] C:\Windows\system32\[Link] dll
\Microsoft\Windows\AppID\SmartScreenSpecific
[Link]
07/05/20
21 User Logon WORKGROUP\Administrador
[Link]
07/05/20
21 System Started
[Link]
07/05/20
21 User Logon WORKGROUP\DWM-1
[Link]
07/05/20
System
21
Shutdown
[Link]
07/05/20
21 User Logoff WIN-SF01JTM2DHI\Administrador
[Link]
07/05/20
Refresh Settings,
21 Task Run [Link] C:\Windows\system32\[Link] exe
\Microsoft\Windows\UpdateOrchestrator\Refresh Settings
[Link]
07/05/20
21 Task Run [Link] C:\Windows\System32\[Link] sih, \Microsoft\Windows\WindowsUpdate\sih exe
[Link]
07/05/20
21 User Logon WORKGROUP\Administrador
[Link]
07/05/20
21 System Started
[Link]
07/05/20
21 User Logon WORKGROUP\DWM-1
[Link]
07/05/20
System
21
Shutdown
[Link]
07/05/20
21 User Logoff WIN-SF01JTM2DHI\Administrador
[Link]
07/05/20
NetworkStateChangeTask,
21 Task Run [Link] C:\Windows\system32\[Link] dll
\Microsoft\Windows\SettingSync\NetworkStateChangeTask
[Link]
07/05/20
SpeechModelDow C:\Windows\system32\speech_onecore\com SpeechModelDownloadTask,
21 Task Run exe
[Link] mon\[Link] \Microsoft\Windows\Speech\SpeechModelDownloadTask
[Link]
07/05/20
SetupCleanupTask. C:\Windows\system32\oobe\SetupCleanupTa SetupCleanupTask,
21 Task Run dll
dll [Link] \Microsoft\Windows\Setup\SetupCleanupTask
[Link]
07/05/20 Pre-staged app cleanup,
21 Task Run [Link] C:\Windows\system32\[Link] \Microsoft\Windows\AppxDeploymentClient\Pre-staged app exe
[Link] cleanup
07/05/20
AppHostRegistratio C:\Windows\system32\AppHostRegistrationV appuriverifierdaily,
21 Task Run exe
[Link] [Link] \Microsoft\Windows\ApplicationData\appuriverifierdaily
[Link]
07/05/20 Microsoft Compatibility Appraiser,
compattelrunner.e
21 Task Run C:\Windows\system32\[Link] \Microsoft\Windows\Application Experience\Microsoft exe
xe
[Link] Compatibility Appraiser
06/05/20
21 User Logon WORKGROUP\Administrador
[Link]
06/05/20
21 User Logon WORKGROUP\DWM-1
[Link]
06/05/20
21 System Started
[Link]
06/05/20
System
21
Shutdown
[Link]
06/05/20
21 User Logoff WIN-SF01JTM2DHI\Administrador
[Link]
06/05/20
View Folder in CarpetaCompartid
21 \\VBOXSVR\CarpetaCompartida
Explorer a
[Link]
06/05/20
Software
21 [Link] C:\Program Files\Wireshark\[Link] Wireshark 3.4.5 64-bit exe
Installation
[Link]
06/05/20
Software
21 [Link] C:\Program Files\Npcap\[Link] Npcap exe
Installation
[Link]
06/05/20 C:\ProgramData\Package Cache\{53f1dc9d-
Software Microsoft Visual C++ 2015-2019 Redistributable (x64) -
21 VC_redist.[Link] ed94-4650-a079- exe
Installation 14.28.29910
[Link] 129785ce7905}\VC_redist.[Link]
06/05/20
Windows
21
Installer Ended
[Link]
06/05/20
Windows
21
Installer Started
[Link]
06/05/20
Windows
21
Installer Ended
[Link]
06/05/20
Windows
21
Installer Started
[Link]
06/05/20
Open file or
21 [Link] C:\Users\Administrador\Desktop\[Link] txt
folder
[Link]
06/05/20 .NET Framework NGEN v4.0.30319 Critical,
21 Task Run [Link] C:\Windows\System32\[Link] \Microsoft\Windows\.NET Framework\.NET Framework NGEN dll
[Link] v4.0.30319 Critical
06/05/20 .NET Framework NGEN v4.0.30319 64 Critical,
21 Task Run [Link] C:\Windows\System32\[Link] \Microsoft\Windows\.NET Framework\.NET Framework NGEN dll
[Link] v4.0.30319 64 Critical
06/05/20 SvcRestartTaskNetwork,
21 Task Run [Link] C:\Windows\System32\[Link] \Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartT dll
[Link] askNetwork
06/05/20 SvcRestartTaskLogon,
21 Task Run [Link] C:\Windows\System32\[Link] \Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartT dll
[Link] askLogon
06/05/20
21 User Logon WORKGROUP\Administrador
[Link]
06/05/20
21 System Started
[Link]
06/05/20
21 User Logon WORKGROUP\DWM-1
[Link]
06/05/20
21 User Logon WORKGROUP\Administrador
[Link]
06/05/20
21 System Started
[Link]
06/05/20
21 User Logon WORKGROUP\DWM-1
[Link]
06/05/20
System
21
Shutdown
[Link]
06/05/20
21 User Logoff WIN-SF01JTM2DHI\Administrador
[Link]
06/05/20
View Folder in
21 D:\
Explorer
[Link]
06/05/20
ForceSynchronizeTime, \Microsoft\Windows\Time
21 Task Run [Link] C:\Windows\system32\[Link] dll
Synchronization\ForceSynchronizeTime
[Link]
06/05/20
Calibration Loader,
21 Task Run [Link] C:\Windows\System32\[Link] dll
\Microsoft\Windows\WindowsColorSystem\Calibration Loader
[Link]
06/05/20
21 User Logon WORKGROUP\Administrador
[Link]
06/05/20
21 System Started
[Link]
06/05/20
21 User Logon WORKGROUP\DWM-1
[Link]
06/05/20
System
21
Shutdown
[Link]
06/05/20
21 System Started
[Link]
06/05/20
Software
21 IE40
Installation
[Link]
06/05/20
Software
21 SchedulingAgent
Installation
[Link]
06/05/20
Software
21 Fontcore
Installation
[Link]
06/05/20
Software
21 WIC
Installation
[Link]
06/05/20
Software
21 IE4Data
Installation
[Link]
06/05/20
Software
21 DirectDrawEx
Installation
[Link]
06/05/20
Software
21 MobileOptionPack
Installation
[Link]
06/05/20
Software
21 IEData
Installation
[Link]
06/05/20
Software
21 Connection Manager
Installation
[Link]
06/05/20
Software
21 AddressBook
Installation
[Link]
06/05/20
Software
21 MPlayer2
Installation
[Link]
06/05/20
Software
21 DXM_Runtime
Installation
[Link]
06/05/20
Software
21 IE5BAKEX
Installation
[Link]
06/05/20
21 User Logon \DWM-1
[Link]