When it comes to investigating suspicious activity on Windows, there is no better place to look than in the Windows event logs. After enabling auditing, you can collect a huge amount of information on ...