libevt Logo

libevt

0
Free
Visit Website

libevt is a library to access the Windows Event Log (EVT) format.The library provides a way to read and parse EVT files, which are used to store event logs in Windows operating systems.libevt is open-source and licensed under the LGPLv3+ license.It is currently in the alpha stage and has a wiki page with documentation and instructions on how to build from source.

FEATURES

ALTERNATIVES

A python module for orchestrating content acquisitions and analysis via Amazon SSM.

A bash script for automating Linux swap analysis for post-exploitation or forensics purposes.

mac_apt is a versatile DFIR tool for processing Mac and iOS images, offering extensive artifact extraction capabilities and cross-platform support.

Tool for parsing Android logs events and protobuf data

Dissect is a digital forensics & incident response framework that simplifies the analysis of forensic artefacts from various disk and file formats.

A library for working with Windows NT data types, providing access and manipulation functions.

A command-line utility and Python package for mounting and unmounting various disk image formats with support for different volume systems and filesystems.

A software utility with forensic tools for smartphones, offering powerful data extraction and decoding capabilities.