System uptime

Windows DFIR notes are no longer maintained on InfoSec-Notes. Updated versions can be found on: artefacts.help.

EVTX

The TurnedOnTimesView utility can be used to parse System.evtx files and determine the time ranges that a system was turned on (by looking as a set of the aforementioned events).


References

https://www.nirsoft.net/utils/computer_turned_on_times.html

Last updated