PowerShell provides built-in EventLog cmdlets for collecting and inspecting Windows event logs. The most commonly used cmdlet is Get-EventLog, which retrieves events from local logs such as Application, System, Security, etc.
Key cmdlets
Get-EventLog– read events from a specific log- Other related cmdlets can be found with
Get-Help *EventLog
Common usage
Get-EventLog -LogName Application -Newest 20
Get-EventLog -LogName System -Newest 20
Get-EventLog -LogName Security -Newest 20
Accessing the Security log typically requires administrative privileges.
Why it matters in digital investigations
Event logs are a primary source of Digital Evidence for user activity, system changes, errors, and security events. PowerShell's built-in event log cmdlets allow investigators to query these logs programmatically and efficiently (see PowerShell as an Acquisition Engine).