EricZimmerman / evtx

C# based evtx parser with lots of extras
MIT License
280 stars 59 forks source link

Sysmon 28 and 29 Maps #238

Closed reece394 closed 4 months ago

reece394 commented 4 months ago

Description

Closes #224. Based on work of @forensenellanebbia on Sysmon 27 with minor adjustments.

Checklist:

Please replace every instance of [ ] with [X] OR click on the checkboxes after you submit your PR

Thank you for your submission and for contributing to the DFIR community!