Windows 디렉토리/파일 검색

Windows 아티팩트 검색

MD5SHA1경로(파일명)
ce8ff117e0701ef5ec76c3939e1ca3ba 395d6d3d843d47b90616c94d76705449354caa1f [NTFS]\[root]\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-Scheduled%4Operational.evtx
1b2bb70b55a3a46ce7ec4cc1a3607389 370c3cce44ec525182594d6e240cf4f78b7945bc [NTFS]\[root]\Windows\System32\winevt\Logs\Microsoft-Windows-WindowsBackup%4ActionCenter.evtx
8575f193a5e74226228ffbbb5b3e16c4 cc6d56f8c77d7749a8425f54c3ba5cf0d4bb791c [NTFS]\[root]\Windows\System32\winevt\Logs\Microsoft-Windows-ShellCommon-StartLayoutPopulation%4Operational.evtx
0bc293a2492eb732f6a2418b6ac9b1fd dd67db566349ae31f63f279c144a8df961acad75 [NTFS]\[root]\Windows\System32\winevt\Logs\Microsoft-Windows-HelloForBusiness%4Operational.evtx
f107bb4fdc3ac259f52e75353c1084f5 08b53733d0a23872f2109d25cf7e11d3ebf11bd6 [NTFS]\[root]\Windows\System32\winevt\Logs\Microsoft-Windows-AAD%4Operational.evtx
908418d0a2f2c6163805403001ece729 e12261aeeb424744b83b82a5fd394ead3be42a26 [NTFS]\[root]\Windows\System32\winevt\Logs\Microsoft-Windows-Authentication User Interface%4Operational.evtx
373d9eecc4a8541e9d5e4afb5c6a73e7 60aa681b746b8d7d2235b2f5dd41e715899ce9d7 [NTFS]\[root]\Windows\System32\winevt\Logs\Microsoft-Windows-TWinUI%4Operational.evtx
1d87c07bb8f1c8606a19212e56522b7a 144b3c5301beb76c3f29cfb3da051abf77470434 [NTFS]\[root]\Windows\System32\winevt\Logs\Microsoft-Windows-Biometrics%4Operational.evtx
4b8e41854ae5ffdf1abcda8e55e554d7 375a817c023786b356e3a624458785fb001461ba [NTFS]\[root]\Windows\System32\winevt\Logs\Microsoft-Windows-Security-SPP-UX-Notifications%4ActionCenter.evtx
540b65dc57148f0d0faa8a3346bb68ce b5a6155e744701d266af0d26a128af58b146df8c [NTFS]\[root]\Windows\System32\winevt\Logs\Microsoft-Windows-WindowsUpdateClient%4Operational.evtx
540b65dc57148f0d0faa8a3346bb68ce b5a6155e744701d266af0d26a128af58b146df8c [NTFS]\[root]\Windows\System32\winevt\Logs\Microsoft-Windows-Security-Mitigations%4UserMode.evtx
d757c0bed24972d6960cdf148ef73353 c005095eedd12d221be8ed954554fef39356e7dc [NTFS]\[root]\Windows\System32\winevt\Logs\Microsoft-Windows-Security-Mitigations%4KernelMode.evtx
3a98b2cd742a543aaa3656b0a0922901 9247ce408215287ba5b051da05dc6fef0aa81325 [NTFS]\[root]\Windows\System32\winevt\Logs\Microsoft-Windows-Known Folders API Service.evtx
0810a5642f3f1ecbe42fcb951ef45834 0e3f2991fd026f3836273648c673be741f50ed68 [NTFS]\[root]\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx
3646837973acedd306e4a1831c5a2f78 27e0111a1dc362346cf675636f0dea3040154be9 [NTFS]\[root]\Windows\System32\winevt\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx
5b50900c41dcbf5866c804c04c8d27d3 6d0cb5e5dee5ae5b7618030a059663f11223472f [NTFS]\[root]\Windows\System32\winevt\Logs\Microsoft-Windows-LanguagePackSetup%4Operational.evtx
7f90848e4f160ddf1cbf89d195035a56 dda53de2966153bc0ec033204458231b345a7645 [NTFS]\[root]\Windows\System32\winevt\Logs\Microsoft-Windows-BitLocker%4BitLocker Management.evtx
540b65dc57148f0d0faa8a3346bb68ce b5a6155e744701d266af0d26a128af58b146df8c [NTFS]\[root]\Windows\System32\winevt\Logs\Microsoft-Windows-ModernDeployment-Diagnostics-Provider%4Diagnostics.evtx
aaea57d9d498b2a37f3ade323a5c0822 7e314f38eae19333efd7c6785568fce1b90d0b60 [NTFS]\[root]\Windows\System32\winevt\Logs\Microsoft-Windows-ModernDeployment-Diagnostics-Provider%4ManagementService.evtx
b6c494f4384144d74fef0195078192e8 28e2091e60b6ff2b0c863d3c6bbb9c40c5a56d44 [NTFS]\[root]\Windows\System32\winevt\Logs\Microsoft-Windows-ModernDeployment-Diagnostics-Provider%4Autopilot.evtx