Cross-platform, open-source shellbag parser
updated at Sept. 9, 2024, 3:54 p.m.
Pure Python parser for classic Windows Event Log files (.evt)
updated at Sept. 24, 2024, 6:49 p.m.
EVTXtract recovers and reconstructs fragments of EVTX log files from raw binary data, including unallocated space and memory images.
updated at Nov. 5, 2024, 9:26 a.m.