Open mgreen27 opened 2 years ago
We would like a VQL native EVTX carver.
Scan logical disk using yara for file type headers. Extract bytes and use binary parser for parsing out records/part records.
Windows.Carving.USN is a similar example.
This is a duplicate of #319
We would like a VQL native EVTX carver.
Scan logical disk using yara for file type headers. Extract bytes and use binary parser for parsing out records/part records.
Windows.Carving.USN is a similar example.