logo

Windows Event Logs for Red Teams

ID: c8fec95a-2b75-571c-aabd-18ba1059bab0

STIX ID: report--c8fec95a-2b75-571c-aabd-18ba1059bab0

Feed Name: Black Hills Infosec Blog

Threat Score
65/100

Date Published: 2022-08-08

Date Updated: 2026-04-27

Author: BHIS

...
...

This blog post details a proof-of-concept technique for storing and retrieving binary payloads in Windows Event Logs to achieve fileless execution and potential persistence: it covers Windows Event Log basics, permission and size constraints, creating entries with Write-EventLog (including RawData), extracting and executing payloads with a C# PoC (demonstrating calc.exe and a Metasploit reverse shell), detection observations with Windows Defender, and references to persistence tooling (SharpEventPersist).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.