evtkit

Event log repair tool

Tool to repair Windows Event Log files (.evt) acquired during forensic investigations

Fix acquired .evt - Windows Event Log files (Forensics)

GitHub

18 stars
4 watching
4 forks
Language: Python
last commit: over 8 years ago
Linked from 1 awesome list


Backlinks from these awesome lists:

Related projects:

Repository Description Stars
williballenthin/python-evtx A Python module for parsing Windows Event Log files (.evtx) into structured data 732
williballenthin/evtxtract Reconstructs fragments of event log data from raw binary files, including unallocated space and memory images. 189
williballenthin/python-evt A Python module for parsing classic Windows Event Log files (.evt) 48
yamato-security/wela Analyzes Windows Event Logs to identify security-related events and provides forensic tools for incident response. 763
ericzimmerman/evtx Tool to parse Event Viewer logs and extract useful information 282
sumeshi/evtx2es A Python library that enables fast import of Windows Event Logs into Elasticsearch 82
dissectmalware/officeforensictools A Python-based collection of tools for gathering forensic information from Office documents 26
mdecrevoisier/evtx-to-mitre-attack Provides Windows log event indicators mapped to MITRE ATT&CK tactic and techniques 527
ecbftw/grokevt A collection of Python scripts to extract information from Windows event log files 10
reed1713/elat A toolset for analyzing Windows event logs to detect and analyze malware 29
travisfoley/dfirtriage A digital forensic tool designed to gather and analyze data from Windows-based systems in incident response scenarios. 334
pjrinaldi/wombatforensics A multi-threaded GUI forensic analysis tool for Linux 47
sbousseaden/evtx-attack-samples A repository of Windows Event log samples associated with various attack and post-exploitation techniques. 2,252
fox-it/dissect.eventlog This is a Python module that parses Windows log file formats 6
vitaly-kamluk/bitscout A customizable tool for creating bootable disk images for remote system analysis and forensic investigations. 462