1. evtx

    A Fast (and safe) parser for the Windows XML Event Log (EVTX) format

    v0.11.1 4.3K #event-log #windows-events #xml-format #log-parser #intermediate-representation #multi-threading #cross-platform #json-output #event-logging #benchmark
  2. dfir-toolkit

    CLI tools for digital forensics and incident response

    v0.12.3 1.5K #digital-forensics #incident-response #dfir #toolkit #format
  3. dionysos

    Scanner for various IoCs

    v1.2.7 3.3K #ioc #forensics #security #cli
  4. utf16-simd

    SIMD-accelerated UTF-16/UTF-16LE -> UTF-8 escaping (JSON/XML)

    v0.1.0 #utf-16 #simd-accelerated #utf-16le #utf-8 #convert-json #xml #event-log #evtx #windows-event #json-output
  5. super_speedy_syslog_searcher

    Speedily search and merge log messages by datetime. DateTime filters may be passed to narrow the search. s4 aims to be very fast.

    v0.8.80 #log-parser #syslog #search #logging #merge
  6. evtx-msg

    enrich evtx entries with messages

    v1.0.1 250 #message #entries #evtx #enrich
  7. glancelog

    Rapid Log Analysis

    v2.3.0 #log-parser #log-analysis #log-entries #logging #graph #word-count #daemon #hash #embedded #postgresql
  8. panopticon-core

    An extensible data processing and templating engine

    v0.2.1 #templating #data-processing #pipeline #polars #etl
  9. exhume_artefacts

    This exhume module regroup all of the parsers maintained by the community to parse and extract artefact in a standardized way

    v0.2.0 #parser #pe #extract #json #record #artefacts #logging #path-parser #emit #evtx
  10. evtxview

    A cli tool to display Windows evtx files

    v0.0.5 260 #evtx #display #windows #command-line-tool #ratatui
  11. evtxtools

    tools for the analysis of evtx files

    v1.12.1 #evtx #analysis #file #timestamp #find #power-shell #exe #system32 #forensics
  12. imohash

    Fast hashing for large files

    v0.1.2 100 #murmur3 #encoding #hash #checksum #digest
  13. Try searching with DuckDuckGo or on crates.io.

  14. evtx2bodyfile

    Parses a lot of evtx files and prints a bodyfile

    v1.3.0 #evtx #bodyfile #lot-of-evtx #parser #print