Winevt_Logs_Analysis - Searching .Evtx Logs For Remote Connections
2023-2-5 19:30:0 Author: www.kitploit.com(查看原文) 阅读量:31 收藏


Simple script for the purpose of finding remote connections to Windows machine and ideally some public IPs. It checks for some EventIDs regarding remote logins and sessions.

You should pip install -r requirements.txt so the script can work and parse some of the .evtx files inside winevt folder.

The winevt/Logs folders and the script must have identical file path.

Execution Example

Result Example

Winevt_Logs_Analysis - Searching .Evtx Logs For Remote Connections Winevt_Logs_Analysis - Searching .Evtx Logs For Remote Connections Reviewed by Zion3R on 8:30 AM Rating: 5


文章来源: http://www.kitploit.com/2023/02/winevtlogsanalysis-searching-evtx-logs.html
如有侵权请联系:admin#unsafe.sh