drop 4688 evtx csv · lolbin abuse patterns · burst clusters · parent chains · network indicators · export csv · runs locally
security 4688 · sysmon event 1 · commandline required
drop 4688 or sysmon evtx csv