This is really just about parsing out the evtx logs and then reading them

the kali IP from the logs,

image.png

10.1.1.42

image.png

I got 32, I actually got 32 from running chainsaw on this

32
psexec

image.png

4
Susan123!

image.png

Extracting the logs wiht ZimmerEvtxECmd tool