bodik / defender

notes on applied computer security
https://bodik.github.io/defender
11 stars 9 forks source link

Exported evtx file can be parsed #8

Closed apadrta closed 5 years ago

apadrta commented 5 years ago

Exported evtx file can be parsed (use -dir parameter); Z from timezone was removed (localtime of eventlog file is used).

bodik commented 5 years ago

thank you. according to analysis we'd prefer to more flexible param handling through hash initialized with LogName or Path in the process. that would allow to support other params in the future as well

bodik commented 5 years ago

thank you for nice contribution