-
Notifications
You must be signed in to change notification settings - Fork 3
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
EvtxECmd: Record error at offset #187
Comments
EvtxECmd 1.5.0.0 (.net6) even though it still shows version 1.0.0.0 when I
run "--version". I just downloaded it again from "Eric Zimmerman's tools"
page.
…On Wed, Apr 13, 2022 at 2:26 AM Andrew Rathbun ***@***.***> wrote:
Which version of evtxecmd are you using?
—
Reply to this email directly, view it on GitHub
<#187 (comment)>,
or unsubscribe
<https://github.com/notifications/unsubscribe-auth/AB7DL6N53ZJM3LYCBGBVPVLVEYIDTANCNFSM5TI6SQIQ>
.
You are receiving this because you authored the thread.Message ID:
***@***.***>
|
Are these forwarded event logs by chance? |
I'm sorry, I don't know. The readme in the repository doesn't say if the events were forwarded: But I get a similar issue when I try to parse another evtx file that I extracted from a VM running Win10 1809 (where there's no WEF): evtx_win10.zip |
For this, I get the following errors:
For this one, I get:
|
Description
When I try to parse some of evtx files from this set EVTX samples - EVTX-to-MITRE-Attack, EvtxECmd (latest version) displays some error messages and produces a blank CSV with just the header.
For instance, this is one the files I can't parse: ID1116-1117-Defender%20threat%20detected.evtx
I can view the contents of the evtx with Event Viewer or Get-WinEvent with no issues.
Debug message
Here's a snippet of the message:
The text was updated successfully, but these errors were encountered: