Quantcast
Channel: CodeSection,代码区,Python开发技术文章_教程 - CodeSec
Viewing all articles
Browse latest Browse all 9596

Toolsmith Tidbit: Will Ballenthin's Python-evtx

$
0
0

Andrew Case ( @attrc ) called out Will Ballenthin's ( @williballenthin ) python-evtx on Twitter, reminding me that I'm long overdue in mentioning it here as well.


Toolsmith Tidbit: Will Ballenthin's Python-evtx

Will's Python-evtx description from his website for same follows:

"python-evtx is a pure Python parser for recent windows Event Log files (those with the file extension “.evtx”). The module provides programmatic access to the File and Chunk headers, record templates, and event entries. For example, you can use python-evtx to review the event logs of Windows 7 systems from a Mac or linux workstation. The structure definitions and parsing strategies were heavily inspired by the work of Andreas Schuster and his Perl implementation Parse-Evtx."

Assuming you've running Python 2.7, install it via pip install python-evtx or download source from Github: https://github.com/williballenthin/python-evtx


Viewing all articles
Browse latest Browse all 9596

Trending Articles