Back to Techniques
eventvwr.exe
eventvwr.exe launches the Windows Event Viewer (MMC). Frequently abused in social engineering to guide users into trusted admin views. Offers Explorer file dialogs via "Save All Events As…" / "Open Saved Log…".
Press Win-R
Type
eventvwrand press EnterIn instructions, direct the user to a given log view
Mitigations:
Educate users to distrust unsolicited requests to open admin tools
Contributor:
ClickGrab
(2025-09-16)
Press Win-R
Type
eventvwrand press EnterPress Alt-A to open the Action menu, then press O (Open Saved Log…)
The file picker (Explorer shell UI) opens
Contributor:
ClickGrab
(2025-09-16)