You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Wondering if there is a way to parse an XML file of event logs that may have been extracted from memory with volatility or
Willi Ballenthin's evtxtract. Not able to find a method to extract the individual logs from the xml, but if this feature could be added to the tool, that'd be awesome! Thanks!
The text was updated successfully, but these errors were encountered:
We would need to add in an xml parser in order to do this. I am not sure how flexible the current design of the code is to enable that though. Also I think this idea might have been shot down in the past. But i'll have a look to see how viable it is.
Okay so an XML parser is now in for v2.0.0-alpha.3. I have not thoroughly tested it but it should work. Please not that a new mapping file would need to be written to hunt on this data as the field names and format will be different to that of the evtx parser.
Wondering if there is a way to parse an XML file of event logs that may have been extracted from memory with volatility or
Willi Ballenthin's evtxtract. Not able to find a method to extract the individual logs from the xml, but if this feature could be added to the tool, that'd be awesome! Thanks!
The text was updated successfully, but these errors were encountered: