484 lines
28 KiB
HTML
484 lines
28 KiB
HTML
|
||
|
||
<!DOCTYPE html>
|
||
<html class="writer-html5" lang="en" >
|
||
<head>
|
||
<meta charset="utf-8">
|
||
|
||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||
|
||
<title>Chapter 3 - Windows Event Log Parsing — Python Forensics Handbook 0.1.1 documentation</title>
|
||
|
||
|
||
|
||
<link rel="stylesheet" href="_static/css/theme.css" type="text/css" />
|
||
<link rel="stylesheet" href="_static/pygments.css" type="text/css" />
|
||
|
||
|
||
|
||
|
||
|
||
|
||
|
||
<!--[if lt IE 9]>
|
||
<script src="_static/js/html5shiv.min.js"></script>
|
||
<![endif]-->
|
||
|
||
|
||
<script type="text/javascript" id="documentation_options" data-url_root="./" src="_static/documentation_options.js"></script>
|
||
<script src="_static/jquery.js"></script>
|
||
<script src="_static/underscore.js"></script>
|
||
<script src="_static/doctools.js"></script>
|
||
<script src="_static/language_data.js"></script>
|
||
|
||
<script type="text/javascript" src="_static/js/theme.js"></script>
|
||
|
||
|
||
<link rel="index" title="Index" href="genindex.html" />
|
||
<link rel="search" title="Search" href="search.html" />
|
||
<link rel="next" title="Chapter 6 - Sqlite & MacOS/Mobile/Browsers" href="ch06_databases.html" />
|
||
<link rel="prev" title="Chapter 2 - Registry Parsing" href="ch02_registry.html" />
|
||
|
||
<!-- Global site tag (gtag.js) - Google Analytics -->
|
||
<script async src="https://www.googletagmanager.com/gtag/js?id=UA-17386833-12"></script>
|
||
<script>
|
||
window.dataLayer = window.dataLayer || [];
|
||
function gtag(){dataLayer.push(arguments);}
|
||
gtag('js', new Date());
|
||
|
||
gtag('config', 'UA-17386833-12');
|
||
</script>
|
||
|
||
</head>
|
||
|
||
<body class="wy-body-for-nav">
|
||
|
||
|
||
<div class="wy-grid-for-nav">
|
||
|
||
<nav data-toggle="wy-nav-shift" class="wy-nav-side">
|
||
<div class="wy-side-scroll">
|
||
<div class="wy-side-nav-search" >
|
||
|
||
|
||
|
||
<a href="index.html" class="icon icon-home" alt="Documentation Home"> Python Forensics Handbook
|
||
|
||
|
||
|
||
</a>
|
||
|
||
|
||
|
||
|
||
<div class="version">
|
||
0.1.1
|
||
</div>
|
||
|
||
|
||
|
||
|
||
<div role="search">
|
||
<form id="rtd-search-form" class="wy-form" action="search.html" method="get">
|
||
<input type="text" name="q" placeholder="Search docs" />
|
||
<input type="hidden" name="check_keywords" value="yes" />
|
||
<input type="hidden" name="area" value="default" />
|
||
</form>
|
||
</div>
|
||
|
||
|
||
</div>
|
||
|
||
|
||
<div class="wy-menu wy-menu-vertical" data-spy="affix" role="navigation" aria-label="main navigation">
|
||
|
||
|
||
|
||
|
||
|
||
|
||
<p class="caption"><span class="caption-text">Table of Contents:</span></p>
|
||
<ul class="current">
|
||
<li class="toctree-l1"><a class="reference internal" href="ch01_essentials.html">Chapter 1 - Essential Scripts</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="ch02_registry.html">Chapter 2 - Registry Parsing</a></li>
|
||
<li class="toctree-l1 current"><a class="current reference internal" href="#">Chapter 3 - Windows Event Log Parsing</a><ul>
|
||
<li class="toctree-l2"><a class="reference internal" href="#module-pyforhandbook.ch03_event_logs.using_python_evtx">Section 3.1 - Using python-evtx</a><ul>
|
||
<li class="toctree-l3"><a class="reference internal" href="#open-windows-event-logs-evtx">Open Windows Event Logs (EVTX)</a></li>
|
||
<li class="toctree-l3"><a class="reference internal" href="#iterate-over-record-xml-data-evtx">Iterate over record XML data (EVTX)</a></li>
|
||
<li class="toctree-l3"><a class="reference internal" href="#filtering-records-within-events-logs">Filtering records within events logs</a></li>
|
||
<li class="toctree-l3"><a class="reference internal" href="#docstring-references">Docstring References</a></li>
|
||
</ul>
|
||
</li>
|
||
<li class="toctree-l2"><a class="reference internal" href="#indices-and-tables">Indices and tables</a></li>
|
||
</ul>
|
||
</li>
|
||
<li class="toctree-l1"><a class="reference internal" href="ch06_databases.html">Chapter 6 - Sqlite & MacOS/Mobile/Browsers</a></li>
|
||
</ul>
|
||
|
||
|
||
|
||
</div>
|
||
|
||
</div>
|
||
</nav>
|
||
|
||
<section data-toggle="wy-nav-shift" class="wy-nav-content-wrap">
|
||
|
||
|
||
<nav class="wy-nav-top" aria-label="top navigation">
|
||
|
||
<i data-toggle="wy-nav-top" class="fa fa-bars"></i>
|
||
<a href="index.html">Python Forensics Handbook</a>
|
||
|
||
</nav>
|
||
|
||
|
||
<div class="wy-nav-content">
|
||
|
||
<div class="rst-content">
|
||
|
||
|
||
|
||
|
||
|
||
|
||
|
||
|
||
|
||
|
||
|
||
|
||
|
||
|
||
|
||
|
||
|
||
<div role="navigation" aria-label="breadcrumbs navigation">
|
||
|
||
<ul class="wy-breadcrumbs">
|
||
|
||
<li><a href="index.html" class="icon icon-home"></a> »</li>
|
||
|
||
<li>Chapter 3 - Windows Event Log Parsing</li>
|
||
|
||
|
||
<li class="wy-breadcrumbs-aside">
|
||
|
||
|
||
<a href="_sources/ch03_event_logs.rst.txt" rel="nofollow"> View page source</a>
|
||
|
||
|
||
</li>
|
||
|
||
</ul>
|
||
|
||
|
||
<hr/>
|
||
</div>
|
||
<div role="main" class="document" itemscope="itemscope" itemtype="http://schema.org/Article">
|
||
<div itemprop="articleBody">
|
||
|
||
<div class="section" id="chapter-3-windows-event-log-parsing">
|
||
<h1>Chapter 3 - Windows Event Log Parsing<a class="headerlink" href="#chapter-3-windows-event-log-parsing" title="Permalink to this headline">¶</a></h1>
|
||
<div class="toctree-wrapper compound">
|
||
</div>
|
||
<div class="section" id="module-pyforhandbook.ch03_event_logs.using_python_evtx">
|
||
<span id="section-3-1-using-python-evtx"></span><h2>Section 3.1 - Using python-evtx<a class="headerlink" href="#module-pyforhandbook.ch03_event_logs.using_python_evtx" title="Permalink to this headline">¶</a></h2>
|
||
<p>Example for opening EVTX files, iterating over events, and filtering events.</p>
|
||
<p>Demonstrates how to open an EVTX file and get basic details about the event log.
|
||
This section makes use of python-evtx, a python library for reading event log
|
||
files. To install, run <code class="docutils literal notranslate"><span class="pre">pip</span> <span class="pre">install</span> <span class="pre">python-evtx</span></code>.</p>
|
||
<p>Other libraries for parsing these event logs exist and we welcome others to
|
||
add snippets that showcase how to make use of them in reading EVTX files.</p>
|
||
<p>Example Usage:</p>
|
||
<blockquote>
|
||
<div><p><code class="docutils literal notranslate"><span class="pre">$</span> <span class="pre">python</span> <span class="pre">using_python_evtx.py</span> <span class="pre">System.evtx</span></code></p>
|
||
</div></blockquote>
|
||
<p>References:</p>
|
||
<ul class="simple">
|
||
<li><p><a class="reference external" href="https://github.com/williballenthin/python-evtx">https://github.com/williballenthin/python-evtx</a></p></li>
|
||
</ul>
|
||
<div class="section" id="open-windows-event-logs-evtx">
|
||
<h3>Open Windows Event Logs (EVTX)<a class="headerlink" href="#open-windows-event-logs-evtx" title="Permalink to this headline">¶</a></h3>
|
||
<p>This function shows an example of opening an EVTX file and parsing out several
|
||
header metadata parameters about the file.</p>
|
||
<div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="k">def</span> <span class="nf">open_evtx</span><span class="p">(</span><span class="n">input_file</span><span class="p">):</span>
|
||
<span class="sd">"""Opens a Windows Event Log and displays common log parameters.</span>
|
||
|
||
<span class="sd"> Arguments:</span>
|
||
<span class="sd"> input_file (str): Path to evtx file to open</span>
|
||
|
||
<span class="sd"> Examples:</span>
|
||
<span class="sd"> >>> open_evtx("System.evtx")</span>
|
||
<span class="sd"> File version (major): 3</span>
|
||
<span class="sd"> File version (minor): 1</span>
|
||
<span class="sd"> File is ditry: True</span>
|
||
<span class="sd"> File is full: False</span>
|
||
<span class="sd"> Next record number: 10549</span>
|
||
|
||
<span class="sd"> """</span>
|
||
|
||
<span class="k">with</span> <span class="n">evtx</span><span class="o">.</span><span class="n">Evtx</span><span class="p">(</span><span class="n">input_file</span><span class="p">)</span> <span class="k">as</span> <span class="n">open_log</span><span class="p">:</span>
|
||
<span class="n">header</span> <span class="o">=</span> <span class="n">open_log</span><span class="o">.</span><span class="n">get_file_header</span><span class="p">()</span>
|
||
<span class="n">properties</span> <span class="o">=</span> <span class="n">OrderedDict</span><span class="p">(</span>
|
||
<span class="p">[</span>
|
||
<span class="p">(</span><span class="s2">"major_version"</span><span class="p">,</span> <span class="s2">"File version (major)"</span><span class="p">),</span>
|
||
<span class="p">(</span><span class="s2">"minor_version"</span><span class="p">,</span> <span class="s2">"File version (minor)"</span><span class="p">),</span>
|
||
<span class="p">(</span><span class="s2">"is_dirty"</span><span class="p">,</span> <span class="s2">"File is dirty"</span><span class="p">),</span>
|
||
<span class="p">(</span><span class="s2">"is_full"</span><span class="p">,</span> <span class="s2">"File is full"</span><span class="p">),</span>
|
||
<span class="p">(</span><span class="s2">"next_record_number"</span><span class="p">,</span> <span class="s2">"Next record number"</span><span class="p">),</span>
|
||
<span class="p">]</span>
|
||
<span class="p">)</span>
|
||
|
||
<span class="k">for</span> <span class="n">key</span><span class="p">,</span> <span class="n">value</span> <span class="ow">in</span> <span class="n">properties</span><span class="o">.</span><span class="n">items</span><span class="p">():</span>
|
||
<span class="nb">print</span><span class="p">(</span><span class="sa">f</span><span class="s2">"</span><span class="si">{</span><span class="n">value</span><span class="si">}</span><span class="s2">: </span><span class="si">{</span><span class="nb">getattr</span><span class="p">(</span><span class="n">header</span><span class="p">,</span> <span class="n">key</span><span class="p">)()</span><span class="si">}</span><span class="s2">"</span><span class="p">)</span>
|
||
</pre></div>
|
||
</div>
|
||
</div>
|
||
<div class="section" id="iterate-over-record-xml-data-evtx">
|
||
<h3>Iterate over record XML data (EVTX)<a class="headerlink" href="#iterate-over-record-xml-data-evtx" title="Permalink to this headline">¶</a></h3>
|
||
<p>In this function, we iterate over the records within an EVTX file and expose
|
||
the raw XML. This leverages a yield generator for
|
||
low impact on resources.</p>
|
||
<p>Additionally, if you would like to parse the XML, or interact with the child
|
||
elements, you can enable it by assigning the <cite>parse_xml</cite> parameter as True,
|
||
which will then call the <code class="docutils literal notranslate"><span class="pre">.lxml()</span></code> method on the individual event record.
|
||
This requires the installation of the lxml Library, as it returns a lxml.etree
|
||
object that you can interact with.</p>
|
||
<div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="k">def</span> <span class="nf">get_events</span><span class="p">(</span><span class="n">input_file</span><span class="p">,</span> <span class="n">parse_xml</span><span class="o">=</span><span class="kc">False</span><span class="p">):</span>
|
||
<span class="sd">"""Opens a Windows Event Log and returns XML information from</span>
|
||
<span class="sd"> the event record.</span>
|
||
|
||
<span class="sd"> Arguments:</span>
|
||
<span class="sd"> input_file (str): Path to evtx file to open</span>
|
||
<span class="sd"> parse_xml (bool): If True, return an lxml object, otherwise a string</span>
|
||
|
||
<span class="sd"> Yields:</span>
|
||
<span class="sd"> (generator): XML information in object or string format</span>
|
||
|
||
<span class="sd"> Examples:</span>
|
||
<span class="sd"> >>> for event_xml in enumerate(get_events("System.evtx")):</span>
|
||
<span class="sd"> >>> print(event_xml)</span>
|
||
|
||
<span class="sd"> """</span>
|
||
<span class="k">with</span> <span class="n">evtx</span><span class="o">.</span><span class="n">Evtx</span><span class="p">(</span><span class="n">input_file</span><span class="p">)</span> <span class="k">as</span> <span class="n">event_log</span><span class="p">:</span>
|
||
<span class="k">for</span> <span class="n">record</span> <span class="ow">in</span> <span class="n">event_log</span><span class="o">.</span><span class="n">records</span><span class="p">():</span>
|
||
<span class="k">if</span> <span class="n">parse_xml</span><span class="p">:</span>
|
||
<span class="k">yield</span> <span class="n">record</span><span class="o">.</span><span class="n">lxml</span><span class="p">()</span>
|
||
<span class="k">else</span><span class="p">:</span>
|
||
<span class="k">yield</span> <span class="n">record</span><span class="o">.</span><span class="n">xml</span><span class="p">()</span>
|
||
</pre></div>
|
||
</div>
|
||
</div>
|
||
<div class="section" id="filtering-records-within-events-logs">
|
||
<h3>Filtering records within events logs<a class="headerlink" href="#filtering-records-within-events-logs" title="Permalink to this headline">¶</a></h3>
|
||
<p>Now that we have <a class="reference internal" href="#pyforhandbook.ch03_event_logs.using_python_evtx.get_events" title="pyforhandbook.ch03_event_logs.using_python_evtx.get_events"><code class="xref py py-func docutils literal notranslate"><span class="pre">get_events()</span></code></a>, we can begin to perform operations on
|
||
the newly accessible data. In this function, we extract information from the
|
||
LXML object, and use that to filter results based on Event ID and other fields
|
||
within the results. You can easily extend this to support other fields,
|
||
filters, and return values. Some examples include:</p>
|
||
<ul class="simple">
|
||
<li><p>extracting all login and logoff events, with their session identifiers,
|
||
then calculating the session durations</p></li>
|
||
<li><p>Identify PowerShell events and expose arguments for further processing
|
||
(ie. Base64 decoding, shellcode analysis)</p></li>
|
||
</ul>
|
||
<div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="k">def</span> <span class="nf">filter_events_json</span><span class="p">(</span><span class="n">event_data</span><span class="p">,</span> <span class="n">event_ids</span><span class="p">,</span> <span class="n">fields</span><span class="o">=</span><span class="kc">None</span><span class="p">):</span>
|
||
<span class="sd">"""Provide events where the event id is found within the provided list</span>
|
||
<span class="sd"> of event ids. If found, it will return a JSON formatted object per event.</span>
|
||
|
||
<span class="sd"> If a list of fields are provided, it will filter the resulting JSON event</span>
|
||
<span class="sd"> object to contain only those fields.</span>
|
||
|
||
<span class="sd"> Arguments:</span>
|
||
<span class="sd"> event_data (genertor): Iterable containing event data as XML. Preferably</span>
|
||
<span class="sd"> the result of the :func:`get_events()` method.</span>
|
||
<span class="sd"> event_ids (list): A list of event identifiers. Each element should be a</span>
|
||
<span class="sd"> string value, even though the identifier is an integer.</span>
|
||
<span class="sd"> fields (list): Collection of fields from the XML data to include in the</span>
|
||
<span class="sd"> JSON output. Only supports top-level fields.</span>
|
||
|
||
<span class="sd"> Yields:</span>
|
||
<span class="sd"> (dict): A dictionary containing the filtered record information</span>
|
||
|
||
<span class="sd"> Example:</span>
|
||
|
||
<span class="sd"> >>> filtered_logins = filter_events_json(</span>
|
||
<span class="sd"> >>> get_events("System.evtx", parse_xml=True),</span>
|
||
<span class="sd"> >>> event_ids=['4624', '4625'],</span>
|
||
<span class="sd"> >>> fields=["SubjectUserName", "SubjectUserSid",</span>
|
||
<span class="sd"> >>> "SubjectDomainName", "TargetUserName", "TargetUserSid",</span>
|
||
<span class="sd"> >>> "TargetDomainName", "WorkstationName", "IpAddress",</span>
|
||
<span class="sd"> >>> "IpPort", "ProcessName"]</span>
|
||
<span class="sd"> >>> )</span>
|
||
<span class="sd"> >>> for filtered_login in filtered_logins:</span>
|
||
<span class="sd"> >>> print(json.dumps(filtered_login, indent=2))</span>
|
||
|
||
<span class="sd"> """</span>
|
||
<span class="k">for</span> <span class="n">evt</span> <span class="ow">in</span> <span class="n">event_data</span><span class="p">:</span>
|
||
<span class="n">system_tag</span> <span class="o">=</span> <span class="n">evt</span><span class="o">.</span><span class="n">find</span><span class="p">(</span><span class="s2">"System"</span><span class="p">,</span> <span class="n">evt</span><span class="o">.</span><span class="n">nsmap</span><span class="p">)</span>
|
||
<span class="n">event_id</span> <span class="o">=</span> <span class="n">system_tag</span><span class="o">.</span><span class="n">find</span><span class="p">(</span><span class="s2">"EventID"</span><span class="p">,</span> <span class="n">evt</span><span class="o">.</span><span class="n">nsmap</span><span class="p">)</span>
|
||
<span class="k">if</span> <span class="n">event_id</span><span class="o">.</span><span class="n">text</span> <span class="ow">in</span> <span class="n">event_ids</span><span class="p">:</span>
|
||
<span class="n">event_data</span> <span class="o">=</span> <span class="n">evt</span><span class="o">.</span><span class="n">find</span><span class="p">(</span><span class="s2">"EventData"</span><span class="p">,</span> <span class="n">evt</span><span class="o">.</span><span class="n">nsmap</span><span class="p">)</span>
|
||
<span class="n">json_data</span> <span class="o">=</span> <span class="p">{}</span>
|
||
<span class="k">for</span> <span class="n">data</span> <span class="ow">in</span> <span class="n">event_data</span><span class="o">.</span><span class="n">getchildren</span><span class="p">():</span>
|
||
<span class="k">if</span> <span class="ow">not</span> <span class="n">fields</span> <span class="ow">or</span> <span class="n">data</span><span class="o">.</span><span class="n">attrib</span><span class="p">[</span><span class="s2">"Name"</span><span class="p">]</span> <span class="ow">in</span> <span class="n">fields</span><span class="p">:</span>
|
||
<span class="c1"># If we don't have a specified field filter list, print all</span>
|
||
<span class="c1"># Otherwise filter for only those fields within the list</span>
|
||
<span class="n">json_data</span><span class="p">[</span><span class="n">data</span><span class="o">.</span><span class="n">attrib</span><span class="p">[</span><span class="s2">"Name"</span><span class="p">]]</span> <span class="o">=</span> <span class="n">data</span><span class="o">.</span><span class="n">text</span>
|
||
|
||
<span class="k">yield</span> <span class="n">json_data</span>
|
||
</pre></div>
|
||
</div>
|
||
</div>
|
||
<div class="section" id="docstring-references">
|
||
<h3>Docstring References<a class="headerlink" href="#docstring-references" title="Permalink to this headline">¶</a></h3>
|
||
<dl class="py function">
|
||
<dt id="pyforhandbook.ch03_event_logs.using_python_evtx.filter_events_json">
|
||
<code class="sig-name descname">filter_events_json</code><span class="sig-paren">(</span><em class="sig-param"><span class="n">event_data</span></em>, <em class="sig-param"><span class="n">event_ids</span></em>, <em class="sig-param"><span class="n">fields</span><span class="o">=</span><span class="default_value">None</span></em><span class="sig-paren">)</span><a class="headerlink" href="#pyforhandbook.ch03_event_logs.using_python_evtx.filter_events_json" title="Permalink to this definition">¶</a></dt>
|
||
<dd><p>Provide events where the event id is found within the provided list
|
||
of event ids. If found, it will return a JSON formatted object per event.</p>
|
||
<p>If a list of fields are provided, it will filter the resulting JSON event
|
||
object to contain only those fields.</p>
|
||
<dl class="field-list simple">
|
||
<dt class="field-odd">Parameters</dt>
|
||
<dd class="field-odd"><ul class="simple">
|
||
<li><p><strong>event_data</strong> (<em>genertor</em>) – Iterable containing event data as XML. Preferably
|
||
the result of the <a class="reference internal" href="#pyforhandbook.ch03_event_logs.using_python_evtx.get_events" title="pyforhandbook.ch03_event_logs.using_python_evtx.get_events"><code class="xref py py-func docutils literal notranslate"><span class="pre">get_events()</span></code></a> method.</p></li>
|
||
<li><p><strong>event_ids</strong> (<em>list</em>) – A list of event identifiers. Each element should be a
|
||
string value, even though the identifier is an integer.</p></li>
|
||
<li><p><strong>fields</strong> (<em>list</em>) – Collection of fields from the XML data to include in the
|
||
JSON output. Only supports top-level fields.</p></li>
|
||
</ul>
|
||
</dd>
|
||
<dt class="field-even">Yields</dt>
|
||
<dd class="field-even"><p><em>(dict)</em> – A dictionary containing the filtered record information</p>
|
||
</dd>
|
||
</dl>
|
||
<p class="rubric">Example</p>
|
||
<div class="doctest highlight-default notranslate"><div class="highlight"><pre><span></span><span class="gp">>>> </span><span class="n">filtered_logins</span> <span class="o">=</span> <span class="n">filter_events_json</span><span class="p">(</span>
|
||
<span class="gp">>>> </span> <span class="n">get_events</span><span class="p">(</span><span class="s2">"System.evtx"</span><span class="p">,</span> <span class="n">parse_xml</span><span class="o">=</span><span class="kc">True</span><span class="p">),</span>
|
||
<span class="gp">>>> </span> <span class="n">event_ids</span><span class="o">=</span><span class="p">[</span><span class="s1">'4624'</span><span class="p">,</span> <span class="s1">'4625'</span><span class="p">],</span>
|
||
<span class="gp">>>> </span> <span class="n">fields</span><span class="o">=</span><span class="p">[</span><span class="s2">"SubjectUserName"</span><span class="p">,</span> <span class="s2">"SubjectUserSid"</span><span class="p">,</span>
|
||
<span class="gp">>>> </span> <span class="s2">"SubjectDomainName"</span><span class="p">,</span> <span class="s2">"TargetUserName"</span><span class="p">,</span> <span class="s2">"TargetUserSid"</span><span class="p">,</span>
|
||
<span class="gp">>>> </span> <span class="s2">"TargetDomainName"</span><span class="p">,</span> <span class="s2">"WorkstationName"</span><span class="p">,</span> <span class="s2">"IpAddress"</span><span class="p">,</span>
|
||
<span class="gp">>>> </span> <span class="s2">"IpPort"</span><span class="p">,</span> <span class="s2">"ProcessName"</span><span class="p">]</span>
|
||
<span class="gp">>>> </span><span class="p">)</span>
|
||
<span class="gp">>>> </span><span class="k">for</span> <span class="n">filtered_login</span> <span class="ow">in</span> <span class="n">filtered_logins</span><span class="p">:</span>
|
||
<span class="gp">>>> </span> <span class="nb">print</span><span class="p">(</span><span class="n">json</span><span class="o">.</span><span class="n">dumps</span><span class="p">(</span><span class="n">filtered_login</span><span class="p">,</span> <span class="n">indent</span><span class="o">=</span><span class="mi">2</span><span class="p">))</span>
|
||
</pre></div>
|
||
</div>
|
||
</dd></dl>
|
||
|
||
<dl class="py function">
|
||
<dt id="pyforhandbook.ch03_event_logs.using_python_evtx.get_events">
|
||
<code class="sig-name descname">get_events</code><span class="sig-paren">(</span><em class="sig-param"><span class="n">input_file</span></em>, <em class="sig-param"><span class="n">parse_xml</span><span class="o">=</span><span class="default_value">False</span></em><span class="sig-paren">)</span><a class="headerlink" href="#pyforhandbook.ch03_event_logs.using_python_evtx.get_events" title="Permalink to this definition">¶</a></dt>
|
||
<dd><p>Opens a Windows Event Log and returns XML information from
|
||
the event record.</p>
|
||
<dl class="field-list simple">
|
||
<dt class="field-odd">Parameters</dt>
|
||
<dd class="field-odd"><ul class="simple">
|
||
<li><p><strong>input_file</strong> (<em>str</em>) – Path to evtx file to open</p></li>
|
||
<li><p><strong>parse_xml</strong> (<em>bool</em>) – If True, return an lxml object, otherwise a string</p></li>
|
||
</ul>
|
||
</dd>
|
||
<dt class="field-even">Yields</dt>
|
||
<dd class="field-even"><p><em>(generator)</em> – XML information in object or string format</p>
|
||
</dd>
|
||
</dl>
|
||
<p class="rubric">Examples</p>
|
||
<div class="doctest highlight-default notranslate"><div class="highlight"><pre><span></span><span class="gp">>>> </span><span class="k">for</span> <span class="n">event_xml</span> <span class="ow">in</span> <span class="nb">enumerate</span><span class="p">(</span><span class="n">get_events</span><span class="p">(</span><span class="s2">"System.evtx"</span><span class="p">)):</span>
|
||
<span class="gp">>>> </span> <span class="nb">print</span><span class="p">(</span><span class="n">event_xml</span><span class="p">)</span>
|
||
</pre></div>
|
||
</div>
|
||
</dd></dl>
|
||
|
||
<dl class="py function">
|
||
<dt id="pyforhandbook.ch03_event_logs.using_python_evtx.open_evtx">
|
||
<code class="sig-name descname">open_evtx</code><span class="sig-paren">(</span><em class="sig-param"><span class="n">input_file</span></em><span class="sig-paren">)</span><a class="headerlink" href="#pyforhandbook.ch03_event_logs.using_python_evtx.open_evtx" title="Permalink to this definition">¶</a></dt>
|
||
<dd><p>Opens a Windows Event Log and displays common log parameters.</p>
|
||
<dl class="field-list simple">
|
||
<dt class="field-odd">Parameters</dt>
|
||
<dd class="field-odd"><p><strong>input_file</strong> (<em>str</em>) – Path to evtx file to open</p>
|
||
</dd>
|
||
</dl>
|
||
<p class="rubric">Examples</p>
|
||
<div class="doctest highlight-default notranslate"><div class="highlight"><pre><span></span><span class="gp">>>> </span><span class="n">open_evtx</span><span class="p">(</span><span class="s2">"System.evtx"</span><span class="p">)</span>
|
||
<span class="go">File version (major): 3</span>
|
||
<span class="go">File version (minor): 1</span>
|
||
<span class="go">File is ditry: True</span>
|
||
<span class="go">File is full: False</span>
|
||
<span class="go">Next record number: 10549</span>
|
||
</pre></div>
|
||
</div>
|
||
</dd></dl>
|
||
|
||
</div>
|
||
</div>
|
||
<div class="section" id="indices-and-tables">
|
||
<h2>Indices and tables<a class="headerlink" href="#indices-and-tables" title="Permalink to this headline">¶</a></h2>
|
||
<ul class="simple">
|
||
<li><p><a class="reference internal" href="genindex.html"><span class="std std-ref">Index</span></a></p></li>
|
||
<li><p><a class="reference internal" href="py-modindex.html"><span class="std std-ref">Module Index</span></a></p></li>
|
||
<li><p><a class="reference internal" href="search.html"><span class="std std-ref">Search Page</span></a></p></li>
|
||
</ul>
|
||
</div>
|
||
</div>
|
||
|
||
|
||
</div>
|
||
|
||
</div>
|
||
<footer>
|
||
|
||
<div class="rst-footer-buttons" role="navigation" aria-label="footer navigation">
|
||
|
||
<a href="ch06_databases.html" class="btn btn-neutral float-right" title="Chapter 6 - Sqlite & MacOS/Mobile/Browsers" accesskey="n" rel="next">Next <span class="fa fa-arrow-circle-right"></span></a>
|
||
|
||
|
||
<a href="ch02_registry.html" class="btn btn-neutral float-left" title="Chapter 2 - Registry Parsing" accesskey="p" rel="prev"><span class="fa fa-arrow-circle-left"></span> Previous</a>
|
||
|
||
</div>
|
||
|
||
|
||
<hr/>
|
||
|
||
<div role="contentinfo">
|
||
<p>
|
||
|
||
© Copyright 2020, Chapin Bryce
|
||
|
||
</p>
|
||
</div>
|
||
|
||
|
||
|
||
Built with <a href="http://sphinx-doc.org/">Sphinx</a> using a
|
||
|
||
<a href="https://github.com/rtfd/sphinx_rtd_theme">theme</a>
|
||
|
||
provided by <a href="https://readthedocs.org">Read the Docs</a>.
|
||
|
||
</footer>
|
||
|
||
</div>
|
||
</div>
|
||
|
||
</section>
|
||
|
||
</div>
|
||
|
||
|
||
<script type="text/javascript">
|
||
jQuery(function () {
|
||
SphinxRtdTheme.Navigation.enable(true);
|
||
});
|
||
</script>
|
||
|
||
|
||
|
||
|
||
|
||
|
||
</body>
|
||
</html> |