[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fdF03EeqyIz3TNY2VHk7ezGMtN__yw-s0Hrs1kLTSolQ":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},1161,"How does SharpSniper find the IP address used by a domain user?","SharpSniper queries the domain controller's security logs for Event ID 4624 and filters by the target username using an XPath query like 'Event[System[(EventID=4624)] and EventData[Data[@Name='TargetUserName']='username']]'. It then extracts the IP address from the log using a regular expression for IPv4 addresses. This process is detailed in the [Analysis of SharpSniper Exploitation](\u002Fnews\u002Fanalysis-of-sharpsniper-exploitation).","\u003Cp>SharpSniper queries the domain controller&#39;s security logs for Event ID 4624 and filters by the target username using an XPath query like &#39;Event[System[(EventID=4624)] and EventData[Data[@Name=&#39;TargetUserName&#39;]=&#39;username&#39;]]&#39;. It then extracts the IP address from the log using a regular expression for IPv4 addresses. This process is detailed in the [Analysis of SharpSniper Exploitation](\u002Fnews\u002Fanalysis-of-sharpsniper-exploitation).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fanalysis-of-sharpsniper-exploitation\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-does-sharpsniper-find-the-ip-address-used-by-a-domain-user-1777480288324","XPath query, regular expression, IP extraction, Event ID 4624",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},282,"Analysis of SharpSniper Exploitation","analysis-of-sharpsniper-exploitation","Analyze SharpSniper for locating domain user IPs via DC logs. Learn implementation with wevtutil and PowerShell for security log queries and IP extraction.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>SharpSniper is used to locate the IP address of a specified domain user in a domain environment, requiring permissions to read domain controller logs. Address: https:\u002F\u002Fgithub.com\u002FHunnicCyber\u002FSharpSniper\u003C\u002Fp>\u003Cp>This article will analyze the implementation principles of SharpSniper, explore extended usage methods, and respectively introduce how to achieve the same functionality using wevtutil.exe and PowerShell scripts, sharing key details to note.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>SharpSniper Implementation Principles\u003C\u002Fli>\u003Cli>Implementation Using wevtutil\u003C\u002Fli>\u003Cli>Implementation Using PowerShell\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 SharpSniper Implementation Principles\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>By querying user login logs (Event ID: 4624) on the domain controller, obtain the IP addresses used by domain users.\u003C\u002Fp>\u003Cp>The specific implementation is as follows:\u003C\u002Fp>\u003Ch3>1. Obtain IP addresses used by domain users by querying logs\u003C\u002Fh3>\u003Cp>XPath query condition (taking user testb as an example):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\"Event[System[(EventID=4624)] and EventData[Data[@Name='TargetUserName']='testb']]\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Corresponding code location:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FHunnicCyber\u002FSharpSniper\u002Fblob\u002Fmaster\u002FQueryDC.cs#L16\u003C\u002Fp>\u003Ch3>2. Filter out IP addresses used by domain users through regular expressions\u003C\u002Fh3>\u003Cp>Regular expression:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\"\\b\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}\\b\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cul>\u003Cli>\\b indicates a word boundary before or after\u003C\u002Fli>\u003Cli>\\d{1,3} indicates the character count is between 1 and 3 digits\u003C\u002Fli>\u003Cli>\\. indicates matching the character \".\"\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Corresponding code location:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FHunnicCyber\u002FSharpSniper\u002Fblob\u002Fmaster\u002FProgram.cs#L54\u003C\u002Fp>\u003Ch2>0x03 Implementation using wevtutil\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Query login logs for a specified user (taking user testb as an example)\u003C\u002Fh3>\u003Cp>The cmd command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wevtutil qe security \u002Fformat:text \u002Fq:\"Event[System[(EventID=4624)] and EventData[Data[@Name='TargetUserName']='testb']]\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Includes detailed information for each log entry, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016720430_0_087e7fc640.jpeg\">\u003C\u002Fp>\u003Ch3>2. Extract IP addresses from the detailed information\u003C\u002Fh3>\u003Cp>The find command can be used here for filtering\u003C\u002Fp>\u003Cp>The cmd command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wevtutil qe security \u002Fformat:text \u002Fq:\"Event[System[(EventID=4624)] and EventData[Data[@Name='TargetUserName']='testb']]\"|find \"Source Network Address\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The filtered results are shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016727078_1_3b8cd6f78b.jpeg\">\u003C\u002Fp>\u003Cp>Extract all IP addresses used by user testb from the logs\u003C\u002Fp>\u003Ch3>Supplement: Writing XPath query conditions\u003C\u002Fh3>\u003Cp>Event Viewer can be used to automatically generate the required XPath statements\u003C\u002Fp>\u003Cp>1. Open Event Viewer\u003C\u002Fp>\u003Cp>Command execution: eventvwr.msc\u003C\u002Fp>\u003Cp>2. Select Create Custom View...\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016731419_2_0687de3fa7.jpeg\">\u003C\u002Fp>\u003Cp>3. After setting query conditions, select the XML tab\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016735292_3_ce74768198.jpeg\">\u003C\u002Fp>\u003Cp>Automatically generate the required XPath statement, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016738495_4_8ad788fb7e.jpeg\">\u003C\u002Fp>\u003Cp>4. Two methods for using wevtutil to call query statements\u003C\u002Fp>\u003Cp>(1) Modify according to the format of the \u002Fq parameter\u003C\u002Fp>\u003Cp>Extract the content within the Select tag from the automatically generated XPath statement\u003C\u002Fp>\u003Cp>(2) Call the query by reading a file\u003C\u002Fp>\u003Cp>Directly use the automatically generated XPath statement\u003C\u002Fp>\u003Cp>Save the query statement from step 3 to a file, e.g., custom1.xml\u003C\u002Fp>\u003Cp>The command to read file call query is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wevtutil qe custom1.xml \u002Fsq:true \u002Frd:true \u002Ff:text\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Implementation using PowerShell\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Query login logs for a specified user (taking user testb as an example)\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-WinEvent -LogName \"security\" -FilterXPath \"Event[System[(EventID=4624)] and EventData[Data[@Name='TargetUserName']='testb']]\"|Format-List\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Including detailed information for each log entry, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016742418_5_2afc284046.jpeg\">\u003C\u002Fp>\u003Ch3>2. Three methods to extract IP addresses from detailed information\u003C\u002Fh3>\u003Ch4>(1) Using the find command\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-WinEvent -LogName \"security\" -FilterXPath \"Event[System[(EventID=4624)] and EventData[Data[@Name='TargetUserName']='testb']]\"|Format-List|find \"Source Network Address\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Result as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016745513_6_453db59698.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Filtering through regular expressions\u003C\u002Fh4>\u003Cp>First implementation method:\u003C\u002Fp>\u003Cp>Using the regular expression in SharpSniper, the corresponding PowerShell command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$events = Get-WinEvent -LogName \"security\" -FilterXPath \"Event[System[(EventID=4624)] and EventData[Data[@Name='TargetUserName']='testb']]\"\u003Cbr>$i=0\u003Cbr>while ($i -lt $events.length) {\u003Cbr>    $IP=[regex]::matches($events[$i].Message, '\\b\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}\\b')\u003Cbr>    Write-Host $IP\u003Cbr>    $i++\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016747581_7_663062b53f.jpeg\">\u003C\u002Fp>\u003Cp>The second implementation method:\u003C\u002Fp>\u003Cp>Search for the keyword \"Source Network Address:\", the corresponding PowerShell command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$events = Get-WinEvent -LogName \"security\" -FilterXPath \"Event[System[(EventID=4624)] and EventData[Data[@Name='TargetUserName']='testb']]\"\u003Cbr>$i=0\u003Cbr>while ($i -lt $events.length) {\u003Cbr>    $IP=[regex]::matches($events[$i].Message, 'Source Network Address:(.+)') | %{$_.Groups[1].Value.Trim()}\u003Cbr>    Write-Host $IP\u003Cbr>    $i++\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Result as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016749454_8_6daf4e36d6.jpeg\">\u003C\u002Fp>\u003Ch4>(3) First convert to XML format, then filter\u003C\u002Fh4>\u003Cp>When outputting, only the Message column is available, cannot selectively output only the content of \"Source Network Address\"\u003C\u002Fp>\u003Cp>If converting the output content to XML format here, the column corresponding to \"Source Network Address\" is ipaddress\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblog.51cto.com\u002Fbeanxyz\u002F1695288\u003C\u002Fp>\u003Cp>The corresponding PowerShell commands are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$Events = Get-WinEvent -LogName \"security\" -FilterXPath \"Event[System[(EventID=4624)] and EventData[Data[@Name='TargetUserName']='testb']]\"     \u003Cbr>ForEach ($Event in $Events) {       \u003Cbr>  $eventXML = [xml]$Event.ToXml()         \u003Cbr>  For ($i=0; $i -lt $eventXML.Event.EventData.Data.Count; $i++) {   \u003Cbr>    Add-Member -InputObject $Event -MemberType NoteProperty -Force -Name $eventXML.Event.EventData.Data[$i].name -Value $eventXML.Event.EventData.Data[$i].'#text'     \u003Cbr>  }       \u003Cbr>}       \u003Cbr>$events|select ipaddress\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The result is shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016750907_9_6d89d50f7c.jpeg\">\u003C\u002Fp>\u003Ch3>Supplement: Using PowerShell to invoke automatically generated XPath query conditions\u003C\u002Fh3>\u003Cp>Referring to the content in 0x03, use Event Viewer to automatically generate the required XPath statements\u003C\u002Fp>\u003Cp>Directly save in the variable $xml and invoke it, the corresponding PowerShell command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$xml = @'\u003Cbr>\u003Cbr>\u003Cquerylist>\u003Cbr>  \u003Cquery id=\"0\" path=\"Security\">\u003Cbr>    \u003Cselect path=\"Security\">*[System[(EventID=4624) and TimeCreated[timediff(@SystemTime) &lt;= 604800000]]]\u003C\u002Fselect>\u003Cbr>  \u003C\u002Fquery>\u003Cbr>\u003C\u002Fquerylist>\u003Cbr>\u003Cbr>'@\u003Cbr>\u003Cbr>Get-WinEvent -FilterXml $xml\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article analyzes the implementation principles and extended usage of SharpSniper, introducing how to achieve the same functionality using wevtutil.exe and PowerShell scripts, which can be used to obtain IP addresses used by key users in a domain environment.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>SharpSniper is used to locate the IP address of a specified domain user in a domain environment, requiring permissions to read domain controller logs. Address: https:\u002F\u002Fgithub.com\u002FHunnicCyber\u002FSharpSniper\u003C\u002Fp>\u003Cp>This article will analyze the implementation principles of SharpSniper, explore extended usage methods, and respectively introduce how to achieve the same functionality using wevtutil.exe and PowerShell scripts, sharing key details to note.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>SharpSniper Implementation Principles\u003C\u002Fli>\u003Cli>Implementation Using wevtutil\u003C\u002Fli>\u003Cli>Implementation Using PowerShell\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 SharpSniper Implementation Principles\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>By querying user login logs (Event ID: 4624) on the domain controller, obtain the IP addresses used by domain users.\u003C\u002Fp>\u003Cp>The specific implementation is as follows:\u003C\u002Fp>\u003Ch3>1. Obtain IP addresses used by domain users by querying logs\u003C\u002Fh3>\u003Cp>XPath query condition (taking user testb as an example):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\"Event[System[(EventID=4624)] and EventData[Data[@Name='TargetUserName']='testb']]\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Corresponding code location:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FHunnicCyber\u002FSharpSniper\u002Fblob\u002Fmaster\u002FQueryDC.cs#L16\u003C\u002Fp>\u003Ch3>2. Filter out IP addresses used by domain users through regular expressions\u003C\u002Fh3>\u003Cp>Regular expression:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\"\\b\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}\\b\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cul>\u003Cli>\\b indicates a word boundary before or after\u003C\u002Fli>\u003Cli>\\d{1,3} indicates the character count is between 1 and 3 digits\u003C\u002Fli>\u003Cli>\\. indicates matching the character \".\"\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Corresponding code location:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FHunnicCyber\u002FSharpSniper\u002Fblob\u002Fmaster\u002FProgram.cs#L54\u003C\u002Fp>\u003Ch2>0x03 Implementation using wevtutil\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Query login logs for a specified user (taking user testb as an example)\u003C\u002Fh3>\u003Cp>The cmd command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wevtutil qe security \u002Fformat:text \u002Fq:\"Event[System[(EventID=4624)] and EventData[Data[@Name='TargetUserName']='testb']]\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Includes detailed information for each log entry, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016720430_0_087e7fc640-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Extract IP addresses from the detailed information\u003C\u002Fh3>\u003Cp>The find command can be used here for filtering\u003C\u002Fp>\u003Cp>The cmd command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wevtutil qe security \u002Fformat:text \u002Fq:\"Event[System[(EventID=4624)] and EventData[Data[@Name='TargetUserName']='testb']]\"|find \"Source Network Address\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The filtered results are shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016727078_1_3b8cd6f78b-1.jpeg\">\u003C\u002Fp>\u003Cp>Extract all IP addresses used by user testb from the logs\u003C\u002Fp>\u003Ch3>Supplement: Writing XPath query conditions\u003C\u002Fh3>\u003Cp>Event Viewer can be used to automatically generate the required XPath statements\u003C\u002Fp>\u003Cp>1. Open Event Viewer\u003C\u002Fp>\u003Cp>Command execution: eventvwr.msc\u003C\u002Fp>\u003Cp>2. Select Create Custom View...\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016731419_2_0687de3fa7-1.jpeg\">\u003C\u002Fp>\u003Cp>3. After setting query conditions, select the XML tab\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016735292_3_ce74768198-1.jpeg\">\u003C\u002Fp>\u003Cp>Automatically generate the required XPath statement, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016738495_4_8ad788fb7e-1.jpeg\">\u003C\u002Fp>\u003Cp>4. Two methods for using wevtutil to call query statements\u003C\u002Fp>\u003Cp>(1) Modify according to the format of the \u002Fq parameter\u003C\u002Fp>\u003Cp>Extract the content within the Select tag from the automatically generated XPath statement\u003C\u002Fp>\u003Cp>(2) Call the query by reading a file\u003C\u002Fp>\u003Cp>Directly use the automatically generated XPath statement\u003C\u002Fp>\u003Cp>Save the query statement from step 3 to a file, e.g., custom1.xml\u003C\u002Fp>\u003Cp>The command to read file call query is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wevtutil qe custom1.xml \u002Fsq:true \u002Frd:true \u002Ff:text\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Implementation using PowerShell\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Query login logs for a specified user (taking user testb as an example)\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-WinEvent -LogName \"security\" -FilterXPath \"Event[System[(EventID=4624)] and EventData[Data[@Name='TargetUserName']='testb']]\"|Format-List\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Including detailed information for each log entry, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016742418_5_2afc284046-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Three methods to extract IP addresses from detailed information\u003C\u002Fh3>\u003Ch4>(1) Using the find command\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-WinEvent -LogName \"security\" -FilterXPath \"Event[System[(EventID=4624)] and EventData[Data[@Name='TargetUserName']='testb']]\"|Format-List|find \"Source Network Address\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Result as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016745513_6_453db59698-1.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Filtering through regular expressions\u003C\u002Fh4>\u003Cp>First implementation method:\u003C\u002Fp>\u003Cp>Using the regular expression in SharpSniper, the corresponding PowerShell command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$events = Get-WinEvent -LogName \"security\" -FilterXPath \"Event[System[(EventID=4624)] and EventData[Data[@Name='TargetUserName']='testb']]\"\u003Cbr>$i=0\u003Cbr>while ($i -lt $events.length) {\u003Cbr>    $IP=[regex]::matches($events[$i].Message, '\\b\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}\\b')\u003Cbr>    Write-Host $IP\u003Cbr>    $i++\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016747581_7_663062b53f-1.jpeg\">\u003C\u002Fp>\u003Cp>The second implementation method:\u003C\u002Fp>\u003Cp>Search for the keyword \"Source Network Address:\", the corresponding PowerShell command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$events = Get-WinEvent -LogName \"security\" -FilterXPath \"Event[System[(EventID=4624)] and EventData[Data[@Name='TargetUserName']='testb']]\"\u003Cbr>$i=0\u003Cbr>while ($i -lt $events.length) {\u003Cbr>    $IP=[regex]::matches($events[$i].Message, 'Source Network Address:(.+)') | %{$_.Groups[1].Value.Trim()}\u003Cbr>    Write-Host $IP\u003Cbr>    $i++\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Result as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016749454_8_6daf4e36d6-1.jpeg\">\u003C\u002Fp>\u003Ch4>(3) First convert to XML format, then filter\u003C\u002Fh4>\u003Cp>When outputting, only the Message column is available, cannot selectively output only the content of \"Source Network Address\"\u003C\u002Fp>\u003Cp>If converting the output content to XML format here, the column corresponding to \"Source Network Address\" is ipaddress\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblog.51cto.com\u002Fbeanxyz\u002F1695288\u003C\u002Fp>\u003Cp>The corresponding PowerShell commands are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$Events = Get-WinEvent -LogName \"security\" -FilterXPath \"Event[System[(EventID=4624)] and EventData[Data[@Name='TargetUserName']='testb']]\"     \u003Cbr>ForEach ($Event in $Events) {       \u003Cbr>  $eventXML = [xml]$Event.ToXml()         \u003Cbr>  For ($i=0; $i -lt $eventXML.Event.EventData.Data.Count; $i++) {   \u003Cbr>    Add-Member -InputObject $Event -MemberType NoteProperty -Force -Name $eventXML.Event.EventData.Data[$i].name -Value $eventXML.Event.EventData.Data[$i].'#text'     \u003Cbr>  }       \u003Cbr>}       \u003Cbr>$events|select ipaddress\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The result is shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016750907_9_6d89d50f7c-1.jpeg\">\u003C\u002Fp>\u003Ch3>Supplement: Using PowerShell to invoke automatically generated XPath query conditions\u003C\u002Fh3>\u003Cp>Referring to the content in 0x03, use Event Viewer to automatically generate the required XPath statements\u003C\u002Fp>\u003Cp>Directly save in the variable $xml and invoke it, the corresponding PowerShell command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$xml = @'\u003Cbr>\u003Cbr>\u003Cquerylist>\u003Cbr>  \u003Cquery id=\"0\" path=\"Security\">\u003Cbr>    \u003Cselect path=\"Security\">*[System[(EventID=4624) and TimeCreated[timediff(@SystemTime) &lt;= 604800000]]]\u003C\u002Fselect>\u003Cbr>  \u003C\u002Fquery>\u003Cbr>\u003C\u002Fquerylist>\u003Cbr>\u003Cbr>'@\u003Cbr>\u003Cbr>Get-WinEvent -FilterXml $xml\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article analyzes the implementation principles and extended usage of SharpSniper, introducing how to achieve the same functionality using wevtutil.exe and PowerShell scripts, which can be used to obtain IP addresses used by key users in a domain environment.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",67,"Onedaysec",4,"published","2026-02-02T07:25:19.686Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"SharpSniper Analysis: Domain User IP Tracking via Event Logs","SharpSniper, domain user IP tracking, event logs, wevtutil, PowerShell, security logs, 4624, XPath, network forensics",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46],1163,1162,1160,{"title":39,"description":39,"image":39},"2026-07-24T15:37:09.189Z","2026-07-23T16:02:36.789Z","draft","2026-07-23T16:17:06.447Z"]