LfLe
Recover event log entries from an image by heuristically looking for record structures.

LfLe
Recover event log entries from an image by heuristically looking for record structures.
LfLe Description
Recover event log entries from an image by heuristically looking for record structures. Dependencies: argparse (http://pypi.python.org/pypi/argparse available via easy_install/pip). Usage: Use this tool to extract event log messages from an image file by looking for things that appear to be records. Then, feed the resulting file into an event log viewer, such as Event Log Explorer (http://www.eventlogxp.com/, use 'direct' mode when opening). Sample Output: evt/LfLe - [master●] » python lfle.py '/media/truecrypt2/VM/Windows XP Professional - Service Pack 3 - TEMPLATE/Windows XP Professional - Service Pack 3-cl1.vmdk' recovered.evt 100% complete% done. Wrote 5413 records. Skipped 48 records with length greater than 0x10000. Skipped 12.
LfLe FAQ
Common questions about LfLe including features, pricing, alternatives, and user reviews.
LfLe is Recover event log entries from an image by heuristically looking for record structures.. It is a Security Operations solution designed to help security teams with File Analysis, Binary Analysis.
ALTERNATIVES
Malware analysis platform for SOC teams with binary analysis and threat detection
A Windows context menu integration tool that scans files and folders for malware patterns, crypto signatures, and malicious documents using Yara rules and PEID signatures.
A command-line tool for creating hex dumps, converting between binary and human-readable representations, and patching binary files.
POPULAR
TRENDING CATEGORIES
Stay Updated with Mandos Brief
Get strategic cybersecurity insights in your inbox