0

I need to know if anyone can inject events in event viewer logs in an old date, how event viewer data are stored, and can anyone change them?

Saw
  • 6,199
  • 11
  • 53
  • 104

1 Answers1

1

Obviously you can't do this on a running system, but the Windows Event Log format has been reverse engineered to the point that you could probably do it offline; perhaps somebody has written a tool for it. Here is one analysis.

Luke
  • 11,211
  • 2
  • 27
  • 38