Member-only story

THM - Windows Event Logs

3 min readMar 26, 2025

A writeup for the room Windows Event Logs on TryHackMe

Introduction to Windows Event Logs and the tools to query them.

This writeup only covers the final challenge in Task 7 - Putting theory into practice.

https://tryhackme.com/room/windowseventlogs

Task 7 - Putting theory into practice

1. What event ID is to detect a PowerShell downgrade attack?

You only need to do a Google search to find the answer.

2. What is the Date and Time this attack took place?

Open the logs with Event Viewer and filter the results by the event ID found earlier.

--

--

Francesco Pastore
Francesco Pastore

Written by Francesco Pastore

An engineering student in Milan and a web developer for an IT company. Write about programming and cybersecurity topics.

No responses yet