Structs§
- Evtx
Chunk Header - Memory
Carved Record - A record found by scanning a raw memory buffer for EVTX record magic.
- Memory
Recovered Chunk - A chunk recovered from process memory (Event Log service VAD scan).
- Recovered
EtwEvent - An ETW event recovered from a session buffer in kernel memory.
- Recovered
EtwSession - An ETW session recovered from kernel memory (
_WMI_LOGGER_CONTEXTwalk).
Enums§
- EtwTampering
Indicator - ETW-level tampering indicators.
- Integrity
Anomaly - Structural integrity anomalies detected in an EVTX file.
Constants§
- RECORD_
MAGIC **\0\0— marks the start of every event record.
Functions§
- detect_
etw_ tampering - Detect ETW-level tampering indicators across the given sessions.
- identify_
eventlog_ sessions - Filter sessions whose name starts with
"EventLog-". - scan_
memory_ buffer - Scan an arbitrary byte buffer for EVTX record magic and recover plausible records.