python-evtx Logo

python-evtx

0
Free
Visit Website

python-evtx is a pure Python parser for recent Windows Event Log files (those with the file extension ".evtx"). The module provides programmatic access to the File and Chunk headers, record templates, and event entries. For example, you can use python-evtx to review the event logs of Windows 7 systems from a Mac or Linux workstation. The structure definitions and parsing strategies were heavily inspired by the work of Andreas Schuster and his Perl implementation "Parse-Evtx".

FEATURES

ALTERNATIVES

AlienVault OSSIM provides an all-in-one security management solution with asset discovery, vulnerability assessment, and SIEM capabilities.

Free

Cybersecurity project for security monitoring of Node.js applications.

Free

Access a repository of Analytic Stories and security guides mapped to industry frameworks, with Splunk searches, machine learning algorithms, and playbooks for threat detection and response.

Free

SysmonSearch makes event log analysis more effective by aggregating Microsoft Sysmon logs and providing detailed analysis through Elasticsearch and Kibana.

Free

Serverless, real-time data analysis framework for incident detection and response.

Free

Tool for deleting logs on Linux/Windows servers.

Free

A Command Line Map-Reduce tool for analyzing cowrie log files over time and creating visualizations and statistics.

Free

A Security Information and Event Management (SIEM) system with a focus on security and minimalism.

Free