EricZimmerman / evtx

C# based evtx parser with lots of extras
MIT License
272 stars 59 forks source link

New maps for NTDS/Computer account creation/MSSQLSERVER events #203

Closed forensenellanebbia closed 2 years ago

forensenellanebbia commented 2 years ago

Description

New maps for these events:

Test data used: Windows EVTX Samples

Checklist:

Please replace every instance of [ ] with [X] OR click on the checkboxes after you submit your PR

Thank you for your submission and for contributing to the DFIR community!