williballenthin / python-evtxLinks
Pure Python parser for Windows Event Log files (.evtx)
☆756Updated 4 months ago
Alternatives and similar repositories for python-evtx
Users that are interested in python-evtx are comparing it to the libraries listed below
Sorting:
- analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multip…☆505Updated 2 months ago
 - Pure Python parser for Windows Registry hives.☆436Updated 9 months ago
 - ☆518Updated 4 years ago
 - Volatility plugins developed and maintained by the community☆369Updated 4 years ago
 - A VBA parser and emulation engine to analyze malicious macros.☆1,112Updated last year
 - Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into …☆812Updated last year
 - Sources, configuration and how to detect evil things utilizing Microsoft Sysmon.☆929Updated last year
 - RDP Bitmap Cache parser☆576Updated 9 months ago
 - A Powershell incident response framework☆1,620Updated 2 years ago
 - PowerShell Obfuscation Detection Framework☆745Updated last year
 - ☆427Updated 2 years ago
 - A forensics tool to convert the data in the Windows srum (System Resource Usage Monitor) database to an xlsx spreadsheet.☆721Updated 4 months ago
 - PowerShell script for deobfuscating encoded PowerShell scripts☆427Updated 4 years ago
 - ☆278Updated 2 years ago
 - Investigate suspicious activity by visualizing Sysmon's event log☆425Updated last year
 - PowerForensics provides an all in one platform for live disk forensic analysis☆1,421Updated last year
 - Super timeline all the things☆1,954Updated this week
 - Noriben - Portable, Simple, Malware Analysis Sandbox☆1,197Updated 2 months ago
 - The Python interface for YARA☆711Updated 5 months ago
 - yarGen is a generator for YARA rules