Ethical Hacking Training at InfoSec Institute Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Workarounds for Windows Event File corruption |
|---|---|
| Date: | Wed, 19 Jan 2005 19:14:48 -0500 |
http://www.whitehats.ca/main/members/Malik/malik_eventlogs/malik_eventlogs.htmlThanks! That's a great resource. I love codeproject, they've often got stuff for use in forensics even though they're a developer site. I'll check this structure format against my log copy. I ended up getting the log date/times via booting an image of the original drive which I'd like to avoid in the future.
I know this thread is about dead, but I thought I would mention that I have taken it upon myself to try and take Malik's work and build on it to create a fully working event log parser that runs only on Linux. I have a more accurate picture now about how the log records are formatted, and am in the process of working out how to get the necessary message resources moved over to Linux. If anyone is interested in helping me on this project, or would just like to know more about the log record format, let me know. thanks, tim ----------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com
| Previous by Date: | FW: HTCIA webinar registration OPEN, Warren Kruse |
|---|---|
| Next by Date: | Re: Workarounds for Windows Event File corruption, Mario Horvat |
| Previous by Thread: | Re: Workarounds for Windows Event File corruption, Jeff Bryner |
| Next by Thread: | Re: Workarounds for Windows Event File corruption, Mario Horvat |
| Indexes: | [Date] [Thread] [Top] [All Lists] |