What is the primary forensic value of Windows Event Logs?
-
A
They store a copy of all files created on the system
-
B
They provide a chronological record of system events including logons, service starts, and security actions
-
C
They contain the full content of deleted files
-
D
They record every keystroke entered by users