evtkit Logo

evtkit

0
Free
Visit Website

evtkit is a tool used for fixing acquired .evt Windows Event Log files in the field of digital forensics. It requires Python 2 (not tested on 3) with no external dependencies. Users can fix .evt files in-place by running evtkit.py on files like AppEvent.Evt and SysEvent.Evt. Additionally, it can find all *.evt files in evt_dir/, copy them to fixed_copy/, and repair them. The tool also offers options such as -h or --help to display the help message, -c or --copy_to_dir to specify the output directory for fixed .evt files, and -q or --quiet to turn off verbosity.

FEATURES

ALTERNATIVES

A reconnaissance tool for GitHub organizations

Tool for analyzing Windows Recycle Bin INFO2 file

Documentation project for Digital Forensics Artifact Repository

A forensic research tool for gathering forensic traces on Android and iOS devices, supporting the use of public indicators of compromise.

iOSForensic is a Python tool for forensic analysis on iOS devices, extracting files, logs, SQLite3 databases, and .plist files into XML.

A tool for discovering, analyzing, and remedying sensitive data

Dissect is a digital forensics & incident response framework that simplifies the analysis of forensic artefacts from various disk and file formats.

Generate comprehensive reports about Windows systems with detailed system, security, networking, and USB information.

CyberSecTools logoCyberSecTools

Explore the largest curated directory of cybersecurity tools and resources to enhance your security practices. Find the right solution for your domain.

Copyright © 2024 - All rights reserved