[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fyKDqkX0BDacxB_X-yOpRo-7vX-94k3-QKajzB-e1hUg":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":33,"aiModel":30,"aiConfidence":30,"updatedAt":50,"createdAt":50,"_status":49},703,"How does handle enumeration for EVT logs differ between Windows XP and Windows 8+?","On Windows XP, you cannot use NtQuerySystemInformation with SystemHandleInformation; instead you must use SystemExtendedHandleInformation (supported from XP onward). The object type number for file handles is 0x1c on XP and Windows 7, but 0x1e on Windows 8+. Additionally, you must filter out handles that may cause hangs by calling WaitForSingleObject before duplicating. For the newer OS approach, see [Windows XML Event Log (EVTX) Single Log Entry Deletion (Part 5)](\u002Fnews\u002Fwindows-xml-event-log-evtx-single-log-entry-deletion-part-5-deleting-a-single-log-entry-from-the-current-system-by-obtaining-log-file-handle-via-duplicatehandle).","\u003Cp>On Windows XP, you cannot use NtQuerySystemInformation with SystemHandleInformation; instead you must use SystemExtendedHandleInformation (supported from XP onward). The object type number for file handles is 0x1c on XP and Windows 7, but 0x1e on Windows 8+. Additionally, you must filter out handles that may cause hangs by calling WaitForSingleObject before duplicating. For the newer OS approach, see [Windows XML Event Log (EVTX) Single Log Entry Deletion (Part 5)](\u002Fnews\u002Fwindows-xml-event-log-evtx-single-log-entry-deletion-part-5-deleting-a-single-log-entry-from-the-current-system-by-obtaining-log-file-handle-via-duplicatehandle).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fwindows-event-viewer-log-evt-single-log-deletion-part-3-deleting-evt-log-records-for-a-specified-time-period-on-the-current-system\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-does-handle-enumeration-for-evt-logs-differ-between-windows-xp-and-windows-8-1777482263376","handle enumeration, NtQuerySystemInformation, SystemExtendedHandleInformation, object type number, Windows XP, Windows 8, file handle type",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":27,"cover":30,"author":31,"views":19,"readingTime":32,"status":33,"publishedAt":34,"seo":35,"tags":39,"qaPairs":40,"meta":46,"updatedAt":47,"createdAt":48,"_status":49},174,"Windows Event Viewer Log (EVT) Single Log Deletion (Part 3) — Deleting EVT Log Records for a Specified Time Period on the Current System","windows-event-viewer-log-evt-single-log-deletion-part-3-deleting-evt-log-records-for-a-specified-time-period-on-the-current-system","Learn to delete Windows EVT log records for a specific time period on XP systems via handle enumeration and DLL injection methods. Includes code examples.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The third article in the series on Windows Event Viewer Log (EVT) single log deletion introduces methods and detailed testing procedures for deleting EVT log records for a specified time period on the current system, explains the reasons why the number of logs cannot be modified, and finally provides open-source implementation code for querying and modifying log content.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Method for enumerating all system handles on Windows XP\u003C\u002Fli>\u003Cli>Criteria for filtering log file handles\u003C\u002Fli>\u003Cli>Example code for DLL injection on Windows XP\u003C\u002Fli>\u003Cli>Actual testing process\u003C\u002Fli>\u003Cli>Reasons why the number of logs cannot be modified\u003C\u002Fli>\u003Cli>Implementation details of the log query program\u003C\u002Fli>\u003Cli>Implementation details of the log modification program\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Enumerating System Handles on Windows XP\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The previous article \"Windows Single Log Deletion (5) – Deleting Current System Single Log Records by Obtaining Log File Handles via DuplicateHandle\" introduced the implementation method for Windows 8 and later systems:\u003C\u002Fp>\u003Col>\u003Cli>Using NtQuerySystemInformation to query SystemHandleInformation can obtain handle information for all processes\u003C\u002Fli>\u003Cli>Obtaining handle names and specific numerical information via NtDuplicateObject\u003C\u002Fli>\u003Cli>Filtering out the desired handles\u003C\u002Fli>\u003Cli>Duplicating handles via DuplicateHandle\u003C\u002Fli>\u003Cli>Obtaining permission to modify log files\u003C\u002Fli>\u003C\u002Fol>\u003Cp>On Windows XP systems, NtQuerySystemInformation cannot be used to query SystemHandleInformation to obtain process handle information\u003C\u002Fp>\u003Cp>Referring to Process Hacker's source code to find implementation methods\u003C\u002Fp>\u003Cp>Code location:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fprocesshacker\u002Fprocesshacker\u002Fblob\u002Fe2d793289dede80f6e3bda26d6478dc58b20b7f8\u002FProcessHacker\u002Fhndlprv.c#L307\u003C\u002Fp>\u003Cp>Obtained reference materials:\u003C\u002Fp>\u003Cp>On Windows 8 and later, NtQueryInformationProcess with ProcessHandleInformation is the most efficient method.\u003C\u002Fp>\u003Cp>On Windows XP and later, NtQuerySystemInformation with SystemExtendedHandleInformation.\u003C\u002Fp>\u003Cp>Otherwise, NtQuerySystemInformation with SystemHandleInformation can be used.\u003C\u002Fp>\u003Cp>Attempt the second method: query SystemExtendedHandleInformation using NtQuerySystemInformation\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The second method supports Windows XP and later systems\u003C\u002Fp>\u003Ch2>0x03 Filter handles for specified log files\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Filter handles of type file\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ObjectTypeNumber = 0x1c\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For Windows 8 and later systems, ObjectTypeNumber = 0x1e\u003C\u002Fp>\u003Cp>For Windows XP and Windows 7 systems, ObjectTypeNumber = 0x1c\u003C\u002Fp>\u003Ch3>2. Filter out handles that may cause hangs\u003C\u002Fh3>\u003Cp>Determine via the WaitForSingleObject API\u003C\u002Fp>\u003Cp>Otherwise, it will cause the process to hang\u003C\u002Fp>\u003Ch3>3. Narrow down the scope by specifying file attributes\u003C\u002Fh3>\u003Cp>Log file attributes are fixed: handle-&gt;GrantedAccess = 0x0012019f\u003C\u002Fp>\u003Cp>The complete implementation code has been open-sourced, download link is as follows:\u003C\u002Fp>\u003Cp>An open-source project).cpp\u003C\u002Fp>\u003Cp>The code implements searching based on input keywords to obtain corresponding handle names and Handle values\u003C\u002Fp>\u003Ch2>0x04 Log Deletion Implementation Method 1: Obtaining Handle Operation Permissions via DLL Injection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Inject a DLL into the system process, the DLL file can then obtain the handle to the log file\u003C\u002Fp>\u003Cp>The subsequent operations are:\u003C\u002Fp>\u003Col>\u003Cli>Call the function CreateFileMapping() to create a file mapping kernel object\u003C\u002Fli>\u003Cli>Call the function MapViewOfFile() to map the file data into the process's address space\u003C\u002Fli>\u003Cli>Modify the data in memory to delete specified log records\u003C\u002Fli>\u003Cli>Call the function FlushViewOfFile() to write the memory data to disk\u003C\u002Fli>\u003Cli>Clear the memory mapping object\u003C\u002Fli>\u003C\u002Fol>\u003Cp>For the complete implementation process, refer to the previously introduced article on deleting single evtx file logs: 'Windows XML Event Log (EVTX) Single Log Deletion (Part 4) – Deleting Current System Single Log Records by Injecting to Obtain Log File Handle'\u003C\u002Fp>\u003Cp>Under the XP system, the method of NtCreateThreadEx + LdrLoadDll cannot be used to inject DLL; you can directly call CreateRemoteThread\u003C\u002Fp>\u003Cp>Implementation code can be referenced:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch2>0x05 Log Deletion Method 2: Obtaining Handle Operation Permissions via DuplicateHandle\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Refer to the previous article \"Windows XML Event Log (EVTX) Single Log Deletion (5) – Deleting a Single Log Record from the Current System by Obtaining Log File Handle via DuplicateHandle\"\u003C\u002Fp>\u003Cp>After filtering the handles, call NtDuplicateObject again to obtain the real handle and perform deletion operations on the log file\u003C\u002Fp>\u003Cp>Similarly, the following operations are required:\u003C\u002Fp>\u003Col>\u003Cli>Call the CreateFileMapping() function to create a file mapping kernel object\u003C\u002Fli>\u003Cli>Call the MapViewOfFile() function to map the file data into the process's address space\u003C\u002Fli>\u003Cli>Modify the data in memory to delete the specified log record\u003C\u002Fli>\u003Cli>Call the FlushViewOfFile() function to write the memory data to disk\u003C\u002Fli>\u003Cli>Clear the memory mapping object\u003C\u002Fli>\u003C\u002Fol>\u003Cp>For the log deletion part, refer to the previous article \"Windows Event Viewer Log (EVT) Single Log Deletion (2) – Program Implementation to Delete Log Records within a Specified Timeframe from an EVT File\"\u003C\u002Fp>\u003Cp>Here is a complete implementation code:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Cp>The code implements the deletion of multiple log records within a specified timeframe from a given EVT file and generates debug files sys2.evt and sys3.evt\u003C\u002Fp>\u003Cp>sys2.evt saves the array content after log deletion\u003C\u002Fp>\u003Cp>sys3.evt saves the content mapped into memory\u003C\u002Fp>\u003Cp>After program execution, sys2.evt and sys3.evt successfully deleted the specified logs, but the current system's log file generated errors\u003C\u002Fp>\u003Cp>For comparative testing, I adjusted the deletion time period to values outside the current logs, meaning no logs would be deleted. After program execution, the current system's log file remained normal\u003C\u002Fp>\u003Cp>Furthermore, as long as the number of logs is not changed, modifying the log content keeps the current system's log file normal\u003C\u002Fp>\u003Cp>This leads to a conclusion:\u003Cstrong>It is impossible to change the number of logs by obtaining the log file handle and modifying memory data\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Similarly, directly modifying the File header of the memory file through ProcessHacker also cannot change the number of logs\u003C\u002Fp>\u003Cp>Wrote a program to verify, using the API GetNumberOfEventLogRecords to query the number of logs\u003C\u002Fp>\u003Cp>C code as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \u003Cwindows.h>\u003Cbr>#pragma comment(lib,\"Advapi32.lib\")\u003Cbr>\u003Cbr>int main(int argc, char *argv[])\u003Cbr>{\u003Cbr>\tHANDLE hEventLog = NULL;\u003Cbr>\u003Cbr>\thEventLog = OpenEventLog(NULL, argv[1]);\u003Cbr>\tif (NULL == hEventLog)\u003Cbr>\t{\u003Cbr>\t\tprintf(\"OpenEventLog failed with 0x%x.\\n\", GetLastError());\u003Cbr>\t\tgoto cleanup;\u003Cbr>\t}\u003Cbr>\u003Cbr>\tDWORD NumberOfRecords = 0;\u003Cbr>\tBOOL flag = GetNumberOfEventLogRecords(hEventLog, &amp;NumberOfRecords);\u003Cbr>\u003Cbr>\tif (NULL == flag)\u003Cbr>\t{\u003Cbr>\t\tprintf(\"GetNumberOfEventLogRecords failed with 0x%x.\\n\", GetLastError());\u003Cbr>\t\tgoto cleanup;\u003Cbr>\t}\u003Cbr>\tprintf(\"%d\\n\", NumberOfRecords);\u003Cbr>\u003Cbr>cleanup:\u003Cbr>\u003Cbr>\tif (hEventLog)\u003Cbr>\t\tCloseEventLog(hEventLog);\u003Cbr>\u003Cbr>}\u003C\u002Fwindows.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>cmd：\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>GetNumberOfEventLogRecords.exe system\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Get the number of log records\u003C\u002Fp>\u003Cp>Directly modify the Last (newest) record number in the File header and the Last (newest) record number in the End of file record of the memory file via ProcessHacker\u003C\u002Fp>\u003Cp>Execute the program again to obtain the number of log records, and find that the obtained number of log records remains unchanged\u003C\u002Fp>\u003Cp>Verify the conclusion: modifying log content in memory cannot change the actual number of log records\u003C\u002Fp>\u003Ch2>0x06 Program Implementation Details for Log Query and Log Modification\u003C\u002Fh2>\u003Cp>The code for log query is as follows:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Cp>The code implements traversing logs and displaying information for each log\u003C\u002Fp>\u003Cp>The code for log modification is as follows:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Cp>The code implements modifying information of specified logs\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces two methods for deleting evt log records within a specified time period in the current system: obtaining handle operation permissions through DLL injection and DuplicateHandle respectively, and utilizing these handles to modify log files\u003C\u002Fp>\u003Cp>The deletion method is not simple overwriting but complete removal of logs from a certain period. Evtx file log deletion can also refer to this approach, though implementation is relatively more complex. Implementation code for evtx will be updated subsequently\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr",null,"Onedaysec",6,"published","2026-02-02T07:38:21.203Z",{"title":36,"description":14,"keywords":37,"ogImage":30,"canonicalUrl":30,"noIndex":38},"Delete Windows EVT Logs by Time Period: XP Handle Enumeration & Injection","Windows XP, EVT log deletion, event viewer, handle enumeration, DLL injection, log forensics, system security",false,[],{"docs":41,"hasNextPage":38},[42,43,4,44,45],705,704,702,701,{"title":30,"description":30,"image":30},"2026-07-24T02:07:20.243Z","2026-07-23T16:01:59.181Z","draft","2026-07-23T16:14:18.209Z"]