博客
关于我
强烈建议你试试无所不能的chatGPT,快点击我
GrokEVT – Read Windows NT/2K/XP/2K3 event logs
阅读量:2434 次
发布时间:2019-05-10

本文共 1805 字,大约阅读时间需要 6 分钟。

Windows event log files form a very important part of Windows . All the application, security, and system events in the event logs provide important information about any hardware, software, and system components, and monitor security events on a local or remote computer. In short, event logs can help you identify and diagnose the source of current system problems, or help you predict potential system problems.

For example, events like valid and invalid logon attempts, as well as events related to resource use, such as the creating, opening, or deleting of files are very important for Windows forensic investigators. GrokEVT is one such Python implementation that helps you read Windows® NT/2K/XP/2K3  event log files.

It is a collection of python scripts that have been released under GNU GPL license. It does pretty much everything – extract the event records from the file, search the Registry for message files, then extract the message strings from the file. So, you see, it not only works with the Windows event log files (.evt), but also registry. So, when you have an image for a Windows you would want to perform a forensic investigation on, GrokEVT is the tool which will help you with it. It will surely help you to locate event records in on the disk, and provide you means to extract it.

Now, since this is an on going project, it has been reported to work only on Linux & FreeBSD as according to the authors tests, those are only the OS’es that natively allow case-insensitive filename mounting options. It will also work on Windows. You need software solutions like DD to work with.

All in all a very good python script. It does have a few dependencies though. You will need Python 2.3, which must be in your $PATH and the ‘make’ program.

You can download the latest version – 0.4.1 .

转载地址:http://pemmb.baihongyu.com/

你可能感兴趣的文章
ionic 前端 - 汉字转拼音
查看>>
Ionic-与时间有关的故事-localecompare()
查看>>
Logback-spring.xml日志配置
查看>>
[Vue warn]: Property or method "name" is not defined on the instance but referenced during render
查看>>
ts:json串转换成数组
查看>>
String、StringBuffer和StringBuilder的区别
查看>>
java——职责链模式
查看>>
java_选择类排序——简单选择排序
查看>>
java_中介者模式
查看>>
java_备忘录模式
查看>>
多线程——背景了解
查看>>
power designer使Comment与Name相同.txt
查看>>
学习Spring 开发指南------基础语义
查看>>
IE下的图片空隙间距BUG和解决办法
查看>>
[pb]从excel导入数据到datawindow
查看>>
CSS Padding in Outlook 2007 and 2010
查看>>
有关内存的思考题
查看>>
What is the difference between gross sales and revenue?
查看>>
Dreamweaver默认打开后缀名为ftl的文件时
查看>>
LNMP一键安装
查看>>