williballenthin / EVTXtract

EVTXtract recovers and reconstructs fragments of EVTX log files from raw binary data, including unallocated space and memory images.
192Updated last month

Alternatives and similar repositories for EVTXtract:

Users that are interested in EVTXtract are comparing it to the libraries listed below