System uptime
Windows DFIR notes are no longer maintained on InfoSec-Notes. Updated versions can be found on: artefacts.help.
EVTX
The TurnedOnTimesView
utility can be used to parse System.evtx
files and determine the time ranges that a system was turned on (by looking as a set of the aforementioned events).
References
https://www.nirsoft.net/utils/computer_turned_on_times.html
Last updated