언어/python

python winlog event

파아랑새 2018. 10. 10. 11:51
import Evtx.Evtx as evt
import Evtx.Views
import mmap
"""
FileHeader
"""
def main():
with open(file=r"C:\Users\sleep\Desktop\t_log.evtx",mode='r') as f:
buf=mmap.mmap(f.fileno(), 0, access=mmap.ACCESS_READ)
fh = evt.FileHeader(buf, 0x00)

for i in Evtx.Views.evtx_file_xml_view(fh):
print (i)

if __name__ == "__main__":
main()