fox-it / dissect.etl Goto Github PK
View Code? Open in Web Editor NEWA Dissect module implementing a parser for Event Trace Log (ETL) files, used by the Windows operating system to log kernel events.
License: GNU Affero General Public License v3.0
A Dissect module implementing a parser for Event Trace Log (ETL) files, used by the Windows operating system to log kernel events.
License: GNU Affero General Public License v3.0
hi,
I'm trying to use dissect.etl
on an etl file generated by WindowsUpdate, but can't extract the details of each event : is this possible ?
WindowsUpdate manifest is present in the manifests
subfolder, but I can't see how to use it or rely on it...
a little help would be greatly appreciated ;-)
regards, lacsaP.
Currently, the focus was on the manifest provider.
there are other providers (mostly legacy) that need to be incorporated.
Ordered in terms of priority:
TMF: Currently used
MOF: Legacy
WPP: Legacy
There was also the idea to create some etl files for those systems... Those are old windows versions. It was introduced in windows 2000.
And included, there is a high chance that the buffer class needs to be changed to accommodate older buffer headers.
Pretty print specific information of the TMF
provider
Pretty print other information of an event
This tools dumps provider schemas, although the information is not complete
Research ticket
Branch dissect.etl with cstruct patches and dependency on >=4.0.dev <=5.0.dev
A declarative, efficient, and flexible JavaScript library for building user interfaces.
๐ Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
An Open Source Machine Learning Framework for Everyone
The Web framework for perfectionists with deadlines.
A PHP framework for web artisans
Bring data to life with SVG, Canvas and HTML. ๐๐๐
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
Some thing interesting about web. New door for the world.
A server is a program made to process requests and deliver data to clients.
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
Some thing interesting about visualization, use data art
Some thing interesting about game, make everyone happy.
We are working to build community through open source technology. NB: members must have two-factor auth.
Open source projects and samples from Microsoft.
Google โค๏ธ Open Source for everyone.
Alibaba Open Source for everyone
Data-Driven Documents codes.
China tencent open source team.