GrokEVT is a collection of scripts for reading Windows event log files. The scripts work together on one or more mounted Windows partitions to extract all information needed (registry entries, message templates, and log files) to convert the logs to a human-readable format.
bee013fae5a275a7a6fafe9d0f938051
Comments
No comments yet, be the first!