0% found this document useful (0 votes)
75 views16 pages

IT Admin Activity Log

Uploaded by

cpmpert
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
75 views16 pages

IT Admin Activity Log

Uploaded by

cpmpert
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

User Actions and Events List

Created by using LastActivityView

File
Action Exte
Description Filename Full Path More Information
Time nsio
n

07/05/20
CreateObjectTask,
21 Task Run [Link] C:\Windows\system32\[Link] dll
\Microsoft\Windows\Shell\CreateObjectTask
[Link]

07/05/20
21 User Logon WORKGROUP\Administrador
[Link]

07/05/20
Open file or C:\Users\Administrador\Desktop\mimikatz_t
21 mimikatz_trunk.zip zip
folder [Link]
[Link]

07/05/20
View Folder in
21 Z:\
Explorer
[Link]

07/05/20
C:\Program Files
21 Task Run [Link] GoogleUpdateTaskMachineUA, \GoogleUpdateTaskMachineUA exe
(x86)\Google\Update\[Link]
[Link]

07/05/20
wuautoappupdate. Automatic App Update,
21 Task Run C:\Windows\System32\[Link] dll
dll \Microsoft\Windows\WindowsUpdate\Automatic App Update
[Link]
07/05/20
Open file or C:\Users\Administrador\Desktop\gentilkiwi-
21 mimikatz
folder mimikatz-09fb1f6\mimikatz
[Link]

07/05/20
Open file or C:\Users\Administrador\Desktop\gentilkiwi-
21 [Link] ico
folder mimikatz-09fb1f6\mimikatz\[Link]
[Link]

07/05/20
21 User Logon WORKGROUP\DWM-3
[Link]

07/05/20
21 User Logon WORKGROUP\Administrador
[Link]

07/05/20
21 User Logon WORKGROUP\DWM-2
[Link]

07/05/20
21 User Logon WORKGROUP\Administrador
[Link]

07/05/20 USO_UxBroker_Display,
[Link]
21 Task Run C:\Windows\system32\[Link] \Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_Dis exe
e
[Link] play

07/05/20
Open file or
21 curriculum C:\curriculum
folder
[Link]
07/05/20
Open file or
21 [Link] C:\curriculum\[Link] pdf
folder
[Link]

07/05/20 Select file in


21 open/save [Link] C:\curriculum\[Link] pdf
[Link] dialog-box

07/05/20 Select file in


21 open/save [Link] C:\curriculum\[Link] pdf
[Link] dialog-box

07/05/20
Open file or
21 C:\
folder
[Link]

07/05/20
Open file or
21 C:\
folder
[Link]

07/05/20
21 Task Run [Link] C:\Windows\system32\[Link] Proxy, \Microsoft\Windows\Autochk\Proxy exe
[Link]

07/05/20
Open file or
21 Desktop C:\Users\Administrador\Desktop
folder
[Link]

07/05/20 2.2.0 20200918


Open file or C:\Users\Administrador\Downloads\2.2.0
21 Zerologon zip
folder 20200918 Zerologon [Link]
[Link] [Link]
07/05/20
C:\Program Files GoogleUpdateTaskMachineCore,
21 Task Run [Link] exe
(x86)\Google\Update\[Link] \GoogleUpdateTaskMachineCore
[Link]

07/05/20 C:\Program
Software
21 [Link] Files\Google\Chrome\Application\[Link] Google Chrome exe
Installation
[Link] e

07/05/20 Installation,
LanguageCompone C:\Windows\System32\LanguageComponent
21 Task Run \Microsoft\Windows\LanguageComponentsInstaller\Installatio dll
[Link] [Link]
[Link] n

07/05/20
Scheduled Start,
21 Task Run [Link] C:\Windows\system32\[Link] exe
\Microsoft\Windows\WindowsUpdate\Scheduled Start
[Link]

07/05/20
Consolidator, \Microsoft\Windows\Customer Experience
21 Task Run [Link] C:\Windows\System32\[Link] exe
Improvement Program\Consolidator
[Link]

07/05/20
XblGameSaveTask. XblGameSaveTaskLogon,
21 Task Run C:\Windows\System32\[Link] exe
exe \Microsoft\XblGameSave\XblGameSaveTaskLogon
[Link]

07/05/20
SilentCleanup,
21 Task Run [Link] C:\Windows\system32\[Link] exe
\Microsoft\Windows\DiskCleanup\SilentCleanup
[Link]

07/05/20
XblGameSaveTask. XblGameSaveTask,
21 Task Run C:\Windows\System32\[Link] exe
exe \Microsoft\XblGameSave\XblGameSaveTask
[Link]
07/05/20
Schedule Scan,
21 Task Run [Link] C:\Windows\system32\[Link] exe
\Microsoft\Windows\UpdateOrchestrator\Schedule Scan
[Link]

07/05/20
QueueReporting, \Microsoft\Windows\Windows Error
21 Task Run [Link] C:\Windows\system32\[Link] exe
Reporting\QueueReporting
[Link]

07/05/20
Configuration, \Microsoft\Windows\Software Inventory
21 Task Run [Link] C:\Windows\system32\[Link] exe
Logging\Configuration
[Link]

07/05/20
21 Task Run [Link] C:\Windows\system32\[Link] CacheTask, \Microsoft\Windows\Wininet\CacheTask dll
[Link]

07/05/20
MsCtfMonitor,
21 Task Run [Link] C:\Windows\system32\[Link] dll
\Microsoft\Windows\TextServicesFramework\MsCtfMonitor
[Link]

07/05/20
ServerManagerLau C:\Windows\system32\ServerManagerLaunc ServerManager, \Microsoft\Windows\Server
21 Task Run exe
[Link] [Link] Manager\ServerManager
[Link]

07/05/20
UserTask,
21 Task Run [Link] C:\Windows\system32\[Link] dll
\Microsoft\Windows\CertificateServicesClient\UserTask
[Link]

07/05/20
21 User Logon WORKGROUP\Administrador
[Link]
07/05/20
SystemTask,
21 Task Run [Link] C:\Windows\system32\[Link] dll
\Microsoft\Windows\CertificateServicesClient\SystemTask
[Link]

07/05/20
Tpm-Maintenance, \Microsoft\Windows\TPM\Tpm-
21 Task Run [Link] C:\Windows\system32\[Link] dll
Maintenance
[Link]

07/05/20
21 System Started
[Link]

07/05/20
21 Task Run [Link]" "C:\Program Files\Npcap\[Link]" npcapwatchdog, \npcapwatchdog bat"
[Link]

07/05/20
21 Task Run [Link] C:\Windows\system32\[Link] Device, \Microsoft\Windows\Device Information\Device exe
[Link]

07/05/20
21 User Logon WORKGROUP\DWM-1
[Link]

07/05/20
System
21
Shutdown
[Link]

07/05/20
21 User Logoff WIN-SF01JTM2DHI\Administrador
[Link]
07/05/20
21 User Logon WORKGROUP\Administrador
[Link]

07/05/20
21 System Started
[Link]

07/05/20
21 User Logon WORKGROUP\DWM-1
[Link]

07/05/20
System
21
Shutdown
[Link]

07/05/20
21 User Logoff WIN-SF01JTM2DHI\Administrador
[Link]

07/05/20
21 User Logon WORKGROUP\Administrador
[Link]

07/05/20
21 System Started
[Link]

07/05/20
21 User Logon WORKGROUP\DWM-1
[Link]
07/05/20
System
21
Shutdown
[Link]

07/05/20
21 User Logoff WIN-SF01JTM2DHI\Administrador
[Link]

07/05/20
SmartScreenSpecific,
21 Task Run [Link] C:\Windows\system32\[Link] dll
\Microsoft\Windows\AppID\SmartScreenSpecific
[Link]

07/05/20
21 User Logon WORKGROUP\Administrador
[Link]

07/05/20
21 System Started
[Link]

07/05/20
21 User Logon WORKGROUP\DWM-1
[Link]

07/05/20
System
21
Shutdown
[Link]

07/05/20
21 User Logoff WIN-SF01JTM2DHI\Administrador
[Link]
07/05/20
Refresh Settings,
21 Task Run [Link] C:\Windows\system32\[Link] exe
\Microsoft\Windows\UpdateOrchestrator\Refresh Settings
[Link]

07/05/20
21 Task Run [Link] C:\Windows\System32\[Link] sih, \Microsoft\Windows\WindowsUpdate\sih exe
[Link]

07/05/20
21 User Logon WORKGROUP\Administrador
[Link]

07/05/20
21 System Started
[Link]

07/05/20
21 User Logon WORKGROUP\DWM-1
[Link]

07/05/20
System
21
Shutdown
[Link]

07/05/20
21 User Logoff WIN-SF01JTM2DHI\Administrador
[Link]

07/05/20
NetworkStateChangeTask,
21 Task Run [Link] C:\Windows\system32\[Link] dll
\Microsoft\Windows\SettingSync\NetworkStateChangeTask
[Link]
07/05/20
SpeechModelDow C:\Windows\system32\speech_onecore\com SpeechModelDownloadTask,
21 Task Run exe
[Link] mon\[Link] \Microsoft\Windows\Speech\SpeechModelDownloadTask
[Link]

07/05/20
SetupCleanupTask. C:\Windows\system32\oobe\SetupCleanupTa SetupCleanupTask,
21 Task Run dll
dll [Link] \Microsoft\Windows\Setup\SetupCleanupTask
[Link]

07/05/20 Pre-staged app cleanup,


21 Task Run [Link] C:\Windows\system32\[Link] \Microsoft\Windows\AppxDeploymentClient\Pre-staged app exe
[Link] cleanup

07/05/20
AppHostRegistratio C:\Windows\system32\AppHostRegistrationV appuriverifierdaily,
21 Task Run exe
[Link] [Link] \Microsoft\Windows\ApplicationData\appuriverifierdaily
[Link]

07/05/20 Microsoft Compatibility Appraiser,


compattelrunner.e
21 Task Run C:\Windows\system32\[Link] \Microsoft\Windows\Application Experience\Microsoft exe
xe
[Link] Compatibility Appraiser

06/05/20
21 User Logon WORKGROUP\Administrador
[Link]

06/05/20
21 User Logon WORKGROUP\DWM-1
[Link]

06/05/20
21 System Started
[Link]
06/05/20
System
21
Shutdown
[Link]

06/05/20
21 User Logoff WIN-SF01JTM2DHI\Administrador
[Link]

06/05/20
View Folder in CarpetaCompartid
21 \\VBOXSVR\CarpetaCompartida
Explorer a
[Link]

06/05/20
Software
21 [Link] C:\Program Files\Wireshark\[Link] Wireshark 3.4.5 64-bit exe
Installation
[Link]

06/05/20
Software
21 [Link] C:\Program Files\Npcap\[Link] Npcap exe
Installation
[Link]

06/05/20 C:\ProgramData\Package Cache\{53f1dc9d-


Software Microsoft Visual C++ 2015-2019 Redistributable (x64) -
21 VC_redist.[Link] ed94-4650-a079- exe
Installation 14.28.29910
[Link] 129785ce7905}\VC_redist.[Link]

06/05/20
Windows
21
Installer Ended
[Link]

06/05/20
Windows
21
Installer Started
[Link]
06/05/20
Windows
21
Installer Ended
[Link]

06/05/20
Windows
21
Installer Started
[Link]

06/05/20
Open file or
21 [Link] C:\Users\Administrador\Desktop\[Link] txt
folder
[Link]

06/05/20 .NET Framework NGEN v4.0.30319 Critical,


21 Task Run [Link] C:\Windows\System32\[Link] \Microsoft\Windows\.NET Framework\.NET Framework NGEN dll
[Link] v4.0.30319 Critical

06/05/20 .NET Framework NGEN v4.0.30319 64 Critical,


21 Task Run [Link] C:\Windows\System32\[Link] \Microsoft\Windows\.NET Framework\.NET Framework NGEN dll
[Link] v4.0.30319 64 Critical

06/05/20 SvcRestartTaskNetwork,
21 Task Run [Link] C:\Windows\System32\[Link] \Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartT dll
[Link] askNetwork

06/05/20 SvcRestartTaskLogon,
21 Task Run [Link] C:\Windows\System32\[Link] \Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartT dll
[Link] askLogon

06/05/20
21 User Logon WORKGROUP\Administrador
[Link]
06/05/20
21 System Started
[Link]

06/05/20
21 User Logon WORKGROUP\DWM-1
[Link]

06/05/20
21 User Logon WORKGROUP\Administrador
[Link]

06/05/20
21 System Started
[Link]

06/05/20
21 User Logon WORKGROUP\DWM-1
[Link]

06/05/20
System
21
Shutdown
[Link]

06/05/20
21 User Logoff WIN-SF01JTM2DHI\Administrador
[Link]

06/05/20
View Folder in
21 D:\
Explorer
[Link]
06/05/20
ForceSynchronizeTime, \Microsoft\Windows\Time
21 Task Run [Link] C:\Windows\system32\[Link] dll
Synchronization\ForceSynchronizeTime
[Link]

06/05/20
Calibration Loader,
21 Task Run [Link] C:\Windows\System32\[Link] dll
\Microsoft\Windows\WindowsColorSystem\Calibration Loader
[Link]

06/05/20
21 User Logon WORKGROUP\Administrador
[Link]

06/05/20
21 System Started
[Link]

06/05/20
21 User Logon WORKGROUP\DWM-1
[Link]

06/05/20
System
21
Shutdown
[Link]

06/05/20
21 System Started
[Link]

06/05/20
Software
21 IE40
Installation
[Link]
06/05/20
Software
21 SchedulingAgent
Installation
[Link]

06/05/20
Software
21 Fontcore
Installation
[Link]

06/05/20
Software
21 WIC
Installation
[Link]

06/05/20
Software
21 IE4Data
Installation
[Link]

06/05/20
Software
21 DirectDrawEx
Installation
[Link]

06/05/20
Software
21 MobileOptionPack
Installation
[Link]

06/05/20
Software
21 IEData
Installation
[Link]

06/05/20
Software
21 Connection Manager
Installation
[Link]
06/05/20
Software
21 AddressBook
Installation
[Link]

06/05/20
Software
21 MPlayer2
Installation
[Link]

06/05/20
Software
21 DXM_Runtime
Installation
[Link]

06/05/20
Software
21 IE5BAKEX
Installation
[Link]

06/05/20
21 User Logon \DWM-1
[Link]

You might also like