EVTXtract recovers and reconstructs fragments of EVTX log files from raw binary data, including unallocated space and memory images.
created at Oct. 5, 2013, 8:59 p.m.
Cross-platform, open-source shellbag parser
created at Nov. 23, 2011, 2:12 a.m.
Pure Python parser for classic Windows Event Log files (.evt)
created at Jan. 24, 2015, 4:07 p.m.