libevt Logo

libevt

0
Free
Visit Website

libevt is a library to access the Windows Event Log (EVT) format.The library provides a way to read and parse EVT files, which are used to store event logs in Windows operating systems.libevt is open-source and licensed under the LGPLv3+ license.It is currently in the alpha stage and has a wiki page with documentation and instructions on how to build from source.

FEATURES

ALTERNATIVES

A library to access and manipulate RAW image files.

Exiv2 is a C++ library and command-line utility for image metadata manipulation.

A collection of PowerShell modules for artifact gathering and reconnaissance of Windows-based endpoints.

iOS Mobile Backup Xtractor tool for extracting iOS backups.

A Kernel fuzzer focusing on race bugs

A comprehensive incident response tool for Windows computers, providing advanced memory forensics and access to locked systems.

A shell script for basic forensic collection of various artefacts from UNIX systems.

A script to assist in creating templates for VirtualBox to enhance VM detection evasion.