This project contains severl parts:
1.python script that check evtx and update
2.format xmls from evtx,edit the xml and put it back
Log file created by the Windows 7 Event Viewer; contains a list of events recorded by Windows; saved in a proprietary binary format that can only be viewed within the Event Viewer program
TODO:In file header i need to recaculte the first chunk number and last chunk number
TODO:next record identifier
TODO:num of chunks
TODO:recalc chunksum
TODO:first event record number
TODO:last event record number
TODO:first record id
TODO:last record id
done:last event record data offset
done:free sapace offset
done:event records checksum
done:recaculte size and put in to both places
done:format binary xml to xml file
done:pad chunks after puting records back in
TODO:format xml to binary xml and put it back to place
TODO:xml editor
thanks to svch0st for thew images