evtkit Logo

evtkit

0
Free
Visit Website

evtkit is a tool used for fixing acquired .evt Windows Event Log files in the field of digital forensics. It requires Python 2 (not tested on 3) with no external dependencies. Users can fix .evt files in-place by running evtkit.py on files like AppEvent.Evt and SysEvent.Evt. Additionally, it can find all *.evt files in evt_dir/, copy them to fixed_copy/, and repair them. The tool also offers options such as -h or --help to display the help message, -c or --copy_to_dir to specify the output directory for fixed .evt files, and -q or --quiet to turn off verbosity.

FEATURES

ALTERNATIVES

Open Backup Extractor is an open source program for extracting data from iPhone and iPad backups.

A script to extract subdomains/emails for a given domain using SSL/TLS certificate dataset on Censys.

A powerful reverse engineering framework

Tool for parsing Android logs events and protobuf data

Exterro is a data risk management platform that optimizes e-discovery, digital forensics, and cybersecurity compliance operations.

A user-friendly and fast Forensic Analysis tool with features like tagging files and generating preview reports.

DMG2IMG is a tool for converting Apple compressed dmg archives to standard image disk files with support for zlib, bzip2, and LZFSE compression.

A modified version of GNU dd with added features like hashing and fast disk wiping.