442 lines
13 KiB
HTML
442 lines
13 KiB
HTML
|
|
|
|
<!DOCTYPE html>
|
|
<html class="writer-html5" lang="en" >
|
|
<head>
|
|
<meta charset="utf-8">
|
|
|
|
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
|
|
|
<title>Index — Python Forensics Handbook 0.1.2 documentation</title>
|
|
|
|
|
|
|
|
<link rel="stylesheet" href="_static/css/theme.css" type="text/css" />
|
|
<link rel="stylesheet" href="_static/pygments.css" type="text/css" />
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
<!--[if lt IE 9]>
|
|
<script src="_static/js/html5shiv.min.js"></script>
|
|
<![endif]-->
|
|
|
|
|
|
<script type="text/javascript" id="documentation_options" data-url_root="./" src="_static/documentation_options.js"></script>
|
|
<script src="_static/jquery.js"></script>
|
|
<script src="_static/underscore.js"></script>
|
|
<script src="_static/doctools.js"></script>
|
|
<script src="_static/language_data.js"></script>
|
|
|
|
<script type="text/javascript" src="_static/js/theme.js"></script>
|
|
|
|
|
|
<link rel="index" title="Index" href="#" />
|
|
<link rel="search" title="Search" href="search.html" />
|
|
|
|
<!-- Global site tag (gtag.js) - Google Analytics -->
|
|
<script async src="https://www.googletagmanager.com/gtag/js?id=UA-17386833-12"></script>
|
|
<script>
|
|
window.dataLayer = window.dataLayer || [];
|
|
function gtag(){dataLayer.push(arguments);}
|
|
gtag('js', new Date());
|
|
|
|
gtag('config', 'UA-17386833-12');
|
|
</script>
|
|
|
|
</head>
|
|
|
|
<body class="wy-body-for-nav">
|
|
|
|
|
|
<div class="wy-grid-for-nav">
|
|
|
|
<nav data-toggle="wy-nav-shift" class="wy-nav-side">
|
|
<div class="wy-side-scroll">
|
|
<div class="wy-side-nav-search" >
|
|
|
|
|
|
|
|
<a href="index.html" class="icon icon-home" alt="Documentation Home"> Python Forensics Handbook
|
|
|
|
|
|
|
|
</a>
|
|
|
|
|
|
|
|
|
|
<div class="version">
|
|
0.1.2
|
|
</div>
|
|
|
|
|
|
|
|
|
|
<div role="search">
|
|
<form id="rtd-search-form" class="wy-form" action="search.html" method="get">
|
|
<input type="text" name="q" placeholder="Search docs" />
|
|
<input type="hidden" name="check_keywords" value="yes" />
|
|
<input type="hidden" name="area" value="default" />
|
|
</form>
|
|
</div>
|
|
|
|
|
|
</div>
|
|
|
|
|
|
<div class="wy-menu wy-menu-vertical" data-spy="affix" role="navigation" aria-label="main navigation">
|
|
|
|
|
|
|
|
|
|
|
|
|
|
<p class="caption"><span class="caption-text">Table of Contents:</span></p>
|
|
<ul>
|
|
<li class="toctree-l1"><a class="reference internal" href="ch01_essentials.html">Chapter 1 - Essential Scripts</a></li>
|
|
<li class="toctree-l1"><a class="reference internal" href="ch02_registry.html">Chapter 2 - Registry Parsing</a></li>
|
|
<li class="toctree-l1"><a class="reference internal" href="ch03_event_logs.html">Chapter 3 - Windows Event Log Parsing</a></li>
|
|
<li class="toctree-l1"><a class="reference internal" href="ch06_databases.html">Chapter 6 - Sqlite & MacOS/Mobile/Browsers</a></li>
|
|
</ul>
|
|
|
|
|
|
|
|
</div>
|
|
|
|
</div>
|
|
</nav>
|
|
|
|
<section data-toggle="wy-nav-shift" class="wy-nav-content-wrap">
|
|
|
|
|
|
<nav class="wy-nav-top" aria-label="top navigation">
|
|
|
|
<i data-toggle="wy-nav-top" class="fa fa-bars"></i>
|
|
<a href="index.html">Python Forensics Handbook</a>
|
|
|
|
</nav>
|
|
|
|
|
|
<div class="wy-nav-content">
|
|
|
|
<div class="rst-content">
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
<div role="navigation" aria-label="breadcrumbs navigation">
|
|
|
|
<ul class="wy-breadcrumbs">
|
|
|
|
<li><a href="index.html" class="icon icon-home"></a> »</li>
|
|
|
|
<li>Index</li>
|
|
|
|
|
|
<li class="wy-breadcrumbs-aside">
|
|
|
|
|
|
|
|
</li>
|
|
|
|
</ul>
|
|
|
|
|
|
<hr/>
|
|
</div>
|
|
<div role="main" class="document" itemscope="itemscope" itemtype="http://schema.org/Article">
|
|
<div itemprop="articleBody">
|
|
|
|
|
|
<h1 id="index">Index</h1>
|
|
|
|
<div class="genindex-jumpbox">
|
|
<a href="#C"><strong>C</strong></a>
|
|
| <a href="#F"><strong>F</strong></a>
|
|
| <a href="#G"><strong>G</strong></a>
|
|
| <a href="#I"><strong>I</strong></a>
|
|
| <a href="#L"><strong>L</strong></a>
|
|
| <a href="#M"><strong>M</strong></a>
|
|
| <a href="#N"><strong>N</strong></a>
|
|
| <a href="#O"><strong>O</strong></a>
|
|
| <a href="#P"><strong>P</strong></a>
|
|
| <a href="#R"><strong>R</strong></a>
|
|
| <a href="#S"><strong>S</strong></a>
|
|
| <a href="#W"><strong>W</strong></a>
|
|
|
|
</div>
|
|
<h2 id="C">C</h2>
|
|
<table style="width: 100%" class="indextable genindextable"><tr>
|
|
<td style="width: 33%; vertical-align: top;"><ul>
|
|
<li><a href="ch02_registry.html#pyforhandbook.ch02_registry.yarp_base.RegistryBase.close">close() (RegistryBase method)</a>
|
|
</li>
|
|
</ul></td>
|
|
</tr></table>
|
|
|
|
<h2 id="F">F</h2>
|
|
<table style="width: 100%" class="indextable genindextable"><tr>
|
|
<td style="width: 33%; vertical-align: top;"><ul>
|
|
<li><a href="ch03_event_logs.html#pyforhandbook.ch03_event_logs.using_python_evtx.filter_events_json">filter_events_json() (in module pyforhandbook.ch03_event_logs.using_python_evtx)</a>
|
|
</li>
|
|
</ul></td>
|
|
</tr></table>
|
|
|
|
<h2 id="G">G</h2>
|
|
<table style="width: 100%" class="indextable genindextable"><tr>
|
|
<td style="width: 33%; vertical-align: top;"><ul>
|
|
<li><a href="ch03_event_logs.html#pyforhandbook.ch03_event_logs.using_python_evtx.get_events">get_events() (in module pyforhandbook.ch03_event_logs.using_python_evtx)</a>
|
|
</li>
|
|
</ul></td>
|
|
</tr></table>
|
|
|
|
<h2 id="I">I</h2>
|
|
<table style="width: 100%" class="indextable genindextable"><tr>
|
|
<td style="width: 33%; vertical-align: top;"><ul>
|
|
<li><a href="ch01_essentials.html#pyforhandbook.ch01_essentials.recursion_example.iterate_files">iterate_files() (in module pyforhandbook.ch01_essentials.recursion_example)</a>
|
|
</li>
|
|
</ul></td>
|
|
</tr></table>
|
|
|
|
<h2 id="L">L</h2>
|
|
<table style="width: 100%" class="indextable genindextable"><tr>
|
|
<td style="width: 33%; vertical-align: top;"><ul>
|
|
<li><a href="ch01_essentials.html#pyforhandbook.ch01_essentials.recursion_example.list_directory">list_directory() (in module pyforhandbook.ch01_essentials.recursion_example)</a>
|
|
</li>
|
|
</ul></td>
|
|
<td style="width: 33%; vertical-align: top;"><ul>
|
|
<li><a href="ch06_databases.html#pyforhandbook.ch06_databases.opening_sqlite.list_tables">list_tables() (in module pyforhandbook.ch06_databases.opening_sqlite)</a>
|
|
</li>
|
|
</ul></td>
|
|
</tr></table>
|
|
|
|
<h2 id="M">M</h2>
|
|
<table style="width: 100%" class="indextable genindextable"><tr>
|
|
<td style="width: 33%; vertical-align: top;"><ul>
|
|
<li>
|
|
module
|
|
|
|
<ul>
|
|
<li><a href="index.html#module-pyforhandbook">pyforhandbook</a>
|
|
</li>
|
|
<li><a href="ch01_essentials.html#module-pyforhandbook.ch01_essentials.argparse_example">pyforhandbook.ch01_essentials.argparse_example</a>
|
|
</li>
|
|
<li><a href="ch01_essentials.html#module-pyforhandbook.ch01_essentials.csv_example">pyforhandbook.ch01_essentials.csv_example</a>
|
|
</li>
|
|
<li><a href="ch01_essentials.html#module-pyforhandbook.ch01_essentials.logging_example">pyforhandbook.ch01_essentials.logging_example</a>
|
|
</li>
|
|
<li><a href="ch01_essentials.html#module-pyforhandbook.ch01_essentials.open_files">pyforhandbook.ch01_essentials.open_files</a>
|
|
</li>
|
|
<li><a href="ch01_essentials.html#module-pyforhandbook.ch01_essentials.recursion_example">pyforhandbook.ch01_essentials.recursion_example</a>
|
|
</li>
|
|
<li><a href="ch02_registry.html#module-pyforhandbook.ch02_registry.yarp_base">pyforhandbook.ch02_registry.yarp_base</a>
|
|
</li>
|
|
<li><a href="ch02_registry.html#module-pyforhandbook.ch02_registry.yarp_ntuser">pyforhandbook.ch02_registry.yarp_ntuser</a>
|
|
</li>
|
|
<li><a href="ch03_event_logs.html#module-pyforhandbook.ch03_event_logs.using_python_evtx">pyforhandbook.ch03_event_logs.using_python_evtx</a>
|
|
</li>
|
|
<li><a href="ch06_databases.html#module-pyforhandbook.ch06_databases.opening_sqlite">pyforhandbook.ch06_databases.opening_sqlite</a>
|
|
</li>
|
|
</ul></li>
|
|
</ul></td>
|
|
</tr></table>
|
|
|
|
<h2 id="N">N</h2>
|
|
<table style="width: 100%" class="indextable genindextable"><tr>
|
|
<td style="width: 33%; vertical-align: top;"><ul>
|
|
<li><a href="ch02_registry.html#pyforhandbook.ch02_registry.yarp_ntuser.NTUSER">NTUSER (class in pyforhandbook.ch02_registry.yarp_ntuser)</a>
|
|
</li>
|
|
</ul></td>
|
|
</tr></table>
|
|
|
|
<h2 id="O">O</h2>
|
|
<table style="width: 100%" class="indextable genindextable"><tr>
|
|
<td style="width: 33%; vertical-align: top;"><ul>
|
|
<li><a href="ch03_event_logs.html#pyforhandbook.ch03_event_logs.using_python_evtx.open_evtx">open_evtx() (in module pyforhandbook.ch03_event_logs.using_python_evtx)</a>
|
|
</li>
|
|
</ul></td>
|
|
<td style="width: 33%; vertical-align: top;"><ul>
|
|
<li><a href="ch01_essentials.html#pyforhandbook.ch01_essentials.open_files.open_file">open_file() (in module pyforhandbook.ch01_essentials.open_files)</a>
|
|
</li>
|
|
<li><a href="ch06_databases.html#pyforhandbook.ch06_databases.opening_sqlite.open_sqlite">open_sqlite() (in module pyforhandbook.ch06_databases.opening_sqlite)</a>
|
|
</li>
|
|
</ul></td>
|
|
</tr></table>
|
|
|
|
<h2 id="P">P</h2>
|
|
<table style="width: 100%" class="indextable genindextable"><tr>
|
|
<td style="width: 33%; vertical-align: top;"><ul>
|
|
<li><a href="ch02_registry.html#pyforhandbook.ch02_registry.yarp_ntuser.NTUSER.parse_mount_points2">parse_mount_points2() (NTUSER method)</a>
|
|
</li>
|
|
<li><a href="ch02_registry.html#pyforhandbook.ch02_registry.yarp_ntuser.NTUSER.parse_office_versions">parse_office_versions() (NTUSER method)</a>
|
|
</li>
|
|
<li><a href="ch02_registry.html#pyforhandbook.ch02_registry.yarp_ntuser.NTUSER.parse_trust_records">parse_trust_records() (NTUSER method)</a>
|
|
</li>
|
|
<li>
|
|
pyforhandbook
|
|
|
|
<ul>
|
|
<li><a href="index.html#module-pyforhandbook">module</a>
|
|
</li>
|
|
</ul></li>
|
|
<li>
|
|
pyforhandbook.ch01_essentials.argparse_example
|
|
|
|
<ul>
|
|
<li><a href="ch01_essentials.html#module-pyforhandbook.ch01_essentials.argparse_example">module</a>
|
|
</li>
|
|
</ul></li>
|
|
<li>
|
|
pyforhandbook.ch01_essentials.csv_example
|
|
|
|
<ul>
|
|
<li><a href="ch01_essentials.html#module-pyforhandbook.ch01_essentials.csv_example">module</a>
|
|
</li>
|
|
</ul></li>
|
|
<li>
|
|
pyforhandbook.ch01_essentials.logging_example
|
|
|
|
<ul>
|
|
<li><a href="ch01_essentials.html#module-pyforhandbook.ch01_essentials.logging_example">module</a>
|
|
</li>
|
|
</ul></li>
|
|
</ul></td>
|
|
<td style="width: 33%; vertical-align: top;"><ul>
|
|
<li>
|
|
pyforhandbook.ch01_essentials.open_files
|
|
|
|
<ul>
|
|
<li><a href="ch01_essentials.html#module-pyforhandbook.ch01_essentials.open_files">module</a>
|
|
</li>
|
|
</ul></li>
|
|
<li>
|
|
pyforhandbook.ch01_essentials.recursion_example
|
|
|
|
<ul>
|
|
<li><a href="ch01_essentials.html#module-pyforhandbook.ch01_essentials.recursion_example">module</a>
|
|
</li>
|
|
</ul></li>
|
|
<li>
|
|
pyforhandbook.ch02_registry.yarp_base
|
|
|
|
<ul>
|
|
<li><a href="ch02_registry.html#module-pyforhandbook.ch02_registry.yarp_base">module</a>
|
|
</li>
|
|
</ul></li>
|
|
<li>
|
|
pyforhandbook.ch02_registry.yarp_ntuser
|
|
|
|
<ul>
|
|
<li><a href="ch02_registry.html#module-pyforhandbook.ch02_registry.yarp_ntuser">module</a>
|
|
</li>
|
|
</ul></li>
|
|
<li>
|
|
pyforhandbook.ch03_event_logs.using_python_evtx
|
|
|
|
<ul>
|
|
<li><a href="ch03_event_logs.html#module-pyforhandbook.ch03_event_logs.using_python_evtx">module</a>
|
|
</li>
|
|
</ul></li>
|
|
<li>
|
|
pyforhandbook.ch06_databases.opening_sqlite
|
|
|
|
<ul>
|
|
<li><a href="ch06_databases.html#module-pyforhandbook.ch06_databases.opening_sqlite">module</a>
|
|
</li>
|
|
</ul></li>
|
|
</ul></td>
|
|
</tr></table>
|
|
|
|
<h2 id="R">R</h2>
|
|
<table style="width: 100%" class="indextable genindextable"><tr>
|
|
<td style="width: 33%; vertical-align: top;"><ul>
|
|
<li><a href="ch02_registry.html#pyforhandbook.ch02_registry.yarp_base.RegistryBase">RegistryBase (class in pyforhandbook.ch02_registry.yarp_base)</a>
|
|
</li>
|
|
</ul></td>
|
|
</tr></table>
|
|
|
|
<h2 id="S">S</h2>
|
|
<table style="width: 100%" class="indextable genindextable"><tr>
|
|
<td style="width: 33%; vertical-align: top;"><ul>
|
|
<li><a href="ch01_essentials.html#pyforhandbook.ch01_essentials.logging_example.setup_logging">setup_logging() (in module pyforhandbook.ch01_essentials.logging_example)</a>
|
|
</li>
|
|
</ul></td>
|
|
</tr></table>
|
|
|
|
<h2 id="W">W</h2>
|
|
<table style="width: 100%" class="indextable genindextable"><tr>
|
|
<td style="width: 33%; vertical-align: top;"><ul>
|
|
<li><a href="ch01_essentials.html#pyforhandbook.ch01_essentials.csv_example.write_csv_dicts">write_csv_dicts() (in module pyforhandbook.ch01_essentials.csv_example)</a>
|
|
</li>
|
|
</ul></td>
|
|
<td style="width: 33%; vertical-align: top;"><ul>
|
|
<li><a href="ch01_essentials.html#pyforhandbook.ch01_essentials.csv_example.write_csv_lists">write_csv_lists() (in module pyforhandbook.ch01_essentials.csv_example)</a>
|
|
</li>
|
|
</ul></td>
|
|
</tr></table>
|
|
|
|
|
|
|
|
</div>
|
|
|
|
</div>
|
|
<footer>
|
|
|
|
|
|
<hr/>
|
|
|
|
<div role="contentinfo">
|
|
<p>
|
|
|
|
© Copyright 2020, Chapin Bryce
|
|
|
|
</p>
|
|
</div>
|
|
|
|
|
|
|
|
Built with <a href="http://sphinx-doc.org/">Sphinx</a> using a
|
|
|
|
<a href="https://github.com/rtfd/sphinx_rtd_theme">theme</a>
|
|
|
|
provided by <a href="https://readthedocs.org">Read the Docs</a>.
|
|
|
|
</footer>
|
|
|
|
</div>
|
|
</div>
|
|
|
|
</section>
|
|
|
|
</div>
|
|
|
|
|
|
<script type="text/javascript">
|
|
jQuery(function () {
|
|
SphinxRtdTheme.Navigation.enable(true);
|
|
});
|
|
</script>
|
|
|
|
|
|
|
|
|
|
|
|
|
|
</body>
|
|
</html> |