As I look back at my RUSEC memories, I remembered the time that I met my mentor! Seems like he accidently kept sending my machine a payload that made my screen go blue…
We were given Challenge.evtx and from the description told to look for BSOD events
A quick internet search led me to this forum answer that highlighted the relevant event IDs 6008, 41, 1001
There are various ways to interact with .evtx files on linux and I used to be partial to evtx_dump
There were also a lot of NTP events idk what those were about. Also not that anyone cares but i don’t like information being hidden in the binary section of evtx logs, aren’t those system generated? can an actual attacker really manipulate those to hide information there? idk