1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
use crate::binxml::assemble::parse_tokens;
use crate::err::{
DeserializationError, DeserializationResult, EvtxError, Result, SerializationError,
};
use crate::json_output::JsonOutput;
use crate::model::deserialized::BinXMLDeserializedTokens;
use crate::xml_output::{BinXmlOutput, XmlOutput};
use crate::{EvtxChunk, ParserSettings};
use byteorder::ReadBytesExt;
use chrono::prelude::*;
use std::io::{Cursor, Read};
use std::sync::Arc;
pub type RecordId = u64;
#[derive(Debug, Clone)]
pub struct EvtxRecord<'a> {
pub chunk: &'a EvtxChunk<'a>,
pub event_record_id: RecordId,
pub timestamp: DateTime<Utc>,
pub tokens: Vec<BinXMLDeserializedTokens<'a>>,
pub settings: Arc<ParserSettings>,
}
#[derive(Debug, Clone, PartialEq)]
pub struct EvtxRecordHeader {
pub data_size: u32,
pub event_record_id: RecordId,
pub timestamp: DateTime<Utc>,
}
#[derive(Debug, Clone, PartialEq)]
pub struct SerializedEvtxRecord<T> {
pub event_record_id: RecordId,
pub timestamp: DateTime<Utc>,
pub data: T,
}
impl EvtxRecordHeader {
pub fn from_reader(input: &mut Cursor<&[u8]>) -> DeserializationResult<EvtxRecordHeader> {
let mut magic = [0_u8; 4];
input.take(4).read_exact(&mut magic)?;
if &magic != b"\x2a\x2a\x00\x00" {
return Err(DeserializationError::InvalidEvtxRecordHeaderMagic { magic });
}
let size = try_read!(input, u32)?;
let record_id = try_read!(input, u64)?;
let timestamp = try_read!(input, filetime)?;
Ok(EvtxRecordHeader {
data_size: size,
event_record_id: record_id,
timestamp,
})
}
pub fn record_data_size(&self) -> u32 {
self.data_size - 24 - 4
}
}
impl<'a> EvtxRecord<'a> {
pub fn into_output<T: BinXmlOutput>(self, output_builder: &mut T) -> Result<()> {
let event_record_id = self.event_record_id;
parse_tokens(self.tokens, &self.chunk, output_builder).map_err(|e| {
EvtxError::FailedToParseRecord {
record_id: event_record_id,
source: Box::new(e),
}
})?;
Ok(())
}
pub fn into_json_value(self) -> Result<SerializedEvtxRecord<serde_json::Value>> {
let mut output_builder = JsonOutput::new(&self.settings);
let event_record_id = self.event_record_id;
let timestamp = self.timestamp;
self.into_output(&mut output_builder)?;
Ok(SerializedEvtxRecord {
event_record_id,
timestamp,
data: output_builder.into_value()?,
})
}
pub fn into_json(self) -> Result<SerializedEvtxRecord<String>> {
let indent = self.settings.should_indent();
let record_with_json_value = self.into_json_value()?;
let data = if indent {
serde_json::to_string_pretty(&record_with_json_value.data)
.map_err(SerializationError::from)?
} else {
serde_json::to_string(&record_with_json_value.data).map_err(SerializationError::from)?
};
Ok(SerializedEvtxRecord {
event_record_id: record_with_json_value.event_record_id,
timestamp: record_with_json_value.timestamp,
data,
})
}
pub fn into_xml(self) -> Result<SerializedEvtxRecord<String>> {
let mut output_builder = XmlOutput::with_writer(Vec::new(), &self.settings);
let event_record_id = self.event_record_id;
let timestamp = self.timestamp;
self.into_output(&mut output_builder)?;
let data =
String::from_utf8(output_builder.into_writer()).map_err(SerializationError::from)?;
Ok(SerializedEvtxRecord {
event_record_id,
timestamp,
data,
})
}
}