@ -41,18 +41,10 @@ or:
`.\DeepBlue.ps1 -log system`
or:
`.\DeepBlue.ps1 "" system`
### Process evtx file:
`.\DeepBlue.ps1 .\evtx\new-user-security.evtx`
`.\DeepBlue.ps1 -file .\evtx\new-user-security.evtx`
## Windows Event Logs processed
- Windows Security
The note is not visible to the blocked user.