williballenthin / EVTXtract
EVTXtract recovers and reconstructs fragments of EVTX log files from raw binary data, including unallocated space and memory images.
☆189Updated 4 years ago
Related projects ⓘ
Alternatives and complementary repositories for EVTXtract
- A modern Python-3-based alternative to RegRipper☆187Updated 2 weeks ago
- ☆273Updated last year
- ☆294Updated 4 years ago
- "Evolving AppCompat/AmCache data analysis beyond grep"☆197Updated 3 years ago
- Extract common Windows artifacts from source images and VSCs☆65Updated 3 years ago
- Parse Windows Prefetch files: Supports XP - Windows 10 Prefetch files