Skip to content

2.2 - Offline EVTX Parsing

Compare
Choose a tag to compare
@BeanBagKing BeanBagKing released this 24 Feb 02:42
· 2 commits to master since this release
  • Added buttons/functionality to parse EVTX files from a folder, allowing analysis on dead systems/evidence
    • New bug? Some of the offline event logs I'm working with don't parse messages for certain events. However, these same events on my machine (both live and offline) do parse. I'm not sure if this is a bug, or something corrupted in the offline logs. Watch for blank "message" fields in your export and manually verify these!
  • Fixed a bug where the CSV may not have been sorted correctly