grokevt

Log file extractor

A collection of Python scripts to extract information from Windows event log files

GrokEVT is a collection of scripts built for reading Windows® NT/2K/XP/2K3 event log files. GrokEVT is released under the GNU GPL, and is implemented in Python.

GitHub

10 stars
2 watching
4 forks
Language: Python
last commit: about 2 years ago
Linked from 1 awesome list


Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
williballenthin/python-evtA Python module for parsing classic Windows Event Log files (.evt)49
fox-it/dissect.eventlogProvides parsers for parsing Windows log file formats6
yarox24/evtkitTool to repair Windows Event Log files (.evt) acquired during forensic investigations18
williballenthin/python-evtxA Python module for parsing Windows Event Log files (.evtx) into structured data732
williballenthin/evtxtractReconstructs fragments of event log data from raw binary files, including unallocated space and memory images.191
fox-it/dissect.etlA parser for Event Trace Log files used by the Windows operating system to log kernel events.2
reed1713/elatA toolset for analyzing Windows event logs to detect and analyze malware29
f3eev/sharkexecA C# toolkit designed to extract credentials and browsing history from Windows systems.295
barasher/go-exiftoolA Go wrapper around ExifTool to extract metadata from various file types.255
shadawck/glitA tool to gather and extract emails of users from GitHub repositories, organizations, or user profiles.48
allyshka/pwngitmanagerA tool for extracting specific files from git repositories during penetration testing without downloading the entire repository.107
sumeshi/evtx2esA Python library that enables fast import of Windows Event Logs into Elasticsearch82
hakky54/certificate-ripperA tool to extract and format SSL/TLS certificates from servers718
uknowsec/sharpdecryptpwdA tool for extracting passwords from various Windows applications1,181
ecmwf/climetlabProvides an interface to weather and climate data for scientific analysis in Python378