EricZimmerman / evtx

C# based evtx parser with lots of extras
MIT License
282 stars 59 forks source link

New maps #109

Closed AndrewRathbun closed 3 years ago

AndrewRathbun commented 3 years ago

Description

Added maps that were mentioned here: https://nasbench.medium.com/finding-forensic-goodness-in-obscure-windows-event-logs-60e978ea45a3

Checklist:

Please replace every instance of [ ] with [X]

Thank you for your submission and for contributing to the DFIR community!