Windows XP Event Lo...
 
Notifications
Clear all

Windows XP Event Logs

4 Posts
3 Users
0 Reactions
584 Views
(@jhooker)
Active Member
Joined: 19 years ago
Posts: 17
Topic starter  

Is it possible to analyse windows xp event logs using linux based / FOSS tools?

thanks!


   
Quote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

Yes. I have written Perl code for analyzing .evt files, that are based on parsing the files on a binary level without using the MS API at all.


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

Also, check out PyFlag.


   
ReplyQuote
(@farmerdude)
Estimable Member
Joined: 20 years ago
Posts: 242
 

jhooker,

Absolutely. Both Delve and grokevt may be used to read EVT files.

regards,

farmerdude


   
ReplyQuote
Share: