Skip to content

Instantly share code, notes, and snippets.

Created December 29, 2020 14:43
Show Gist options
  • Save medmondson44/294e90981bc1454d316e27e03b487e04 to your computer and use it in GitHub Desktop.
Save medmondson44/294e90981bc1454d316e27e03b487e04 to your computer and use it in GitHub Desktop.
This is a fork of the Endgame script scrape-events.ps1. I gave it more functionality to take any event log and to be able to query remotely or take a path to the event log. Original Endgame script cant be found here:
function Get-EventProps {
Param (
Process {
$eventXml = [xml]$event.ToXML()
$eventKeys = $eventXml.Event.EventData.Data
$Properties = @{}
$Properties.EventId = $event.Id
For ($i=0; $i -lt $eventKeys.Count; $i++) {
$Properties[$eventKeys[$i].Name] = $eventKeys[$i].'#text'
function reverse {
$arr = @($input)
function Get-LatestLogs {
Get-LatestLogs -computername localhost -Logname security -MaxEvents 5 | ConvertTo-Json | Out-File -Encoding ASCII -FilePath my-security-data.json
param (
HelpMessage="Enter ComputerName")]
foreach ($comp in $Computername)
Get-WinEvent -ComputerName $Comp -filterhashtable @{logname=$logname} -MaxEvents $MaxEvents | Get-EventProps | reverse
function Get-LatestLogsFromPath {
Get-LatestLogsFromPath -Path c:\windows\system32\winevt\logs\security -MaxEvents 5 | ConvertTo-Json | Out-File -Encoding ASCII -FilePath my-security-data.json
param (
Get-WinEvent -filterhashtable @{Path=$Path} -MaxEvents $MaxEvents | Get-EventProps | reverse
function Get-LatestLogsId {
Get-LatestLogsId -computername localhost -Logname security -id 4624 -MaxEvents 5 | ConvertTo-Json | Out-File -Encoding ASCII -FilePath my-security-data.json
param (
HelpMessage="Enter ComputerName")]
foreach ($comp in $Computername)
Get-WinEvent -ComputerName $Comp -filterhashtable @{logname=$logname;id=$id} -MaxEvents $MaxEvents | Get-EventProps | reverse
function Get-LatestLogsFromPathId {
Get-LatestLogsFromPath -Path c:\windows\system32\winevt\logs\security -id 4624 -MaxEvents 5 | ConvertTo-Json | Out-File -Encoding ASCII -FilePath my-security-data.json
param (
Get-WinEvent -filterhashtable @{Path=$Path;id=$id} -MaxEvents $MaxEvents | Get-EventProps | reverse
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment