evtkit Logo

evtkit

0
Free
Updated 11 March 2025
Visit Website

evtkit is a tool used for fixing acquired .evt Windows Event Log files in the field of digital forensics. It requires Python 2 (not tested on 3) with no external dependencies. Users can fix .evt files in-place by running evtkit.py on files like AppEvent.Evt and SysEvent.Evt. Additionally, it can find all *.evt files in evt_dir/, copy them to fixed_copy/, and repair them. The tool also offers options such as -h or --help to display the help message, -c or --copy_to_dir to specify the output directory for fixed .evt files, and -q or --quiet to turn off verbosity.

FEATURES

SIMILAR TOOLS

Forensic imaging program with full hash authentication and various acquisition options.

A library to access the Extensible Storage Engine (ESE) Database File (EDB) format used in various Windows applications.

Create checkpoint snapshots of the state of running pods for later off-line analysis.

A cross-platform registry hive editor for forensic analysis with advanced features like hex viewer and reporting engine.

An extensible network forensic analysis framework with deep packet analysis and plugin support.

Custom built application for asynchronous forensic data presentation on an Elasticsearch backend, with upcoming features like Docker-based installation and new UI rewrite in React.

Zenduty's platform provides real-time operational health monitoring and incident response orchestration to improve incident response times and build a solid on-call culture.

Tool for parsing NTFS journal files, $Logfile, and $MFT.

A tool for extracting files from packet capture files with ease of use and extensibility for Python developers.

CyberSecTools logoCyberSecTools

Explore the largest curated directory of cybersecurity tools and resources to enhance your security practices. Find the right solution for your domain.

Operated by:

Mandos Cyber • KVK: 97994448

Netherlands • contact@mandos.io

Copyright © 2025 - All rights reserved