Skip to main content

pyevtx-rs

Python bindings for https://github.com/omerbenamram/evtx/.

Installation

Available on PyPi - https://pypi.org/project/evtx/.

To install from PyPi - pip install evtx

Wheels

Wheels are currently automatically built for python 3.6,3.7,3.8,3.9 for all 64-bit platforms (Windows, macOS, and manylinux).

Installation from sources

Installation is possible for other platforms by installing from sources, this requires a rust compiler and setuptools-rust.

Run python setup.py install

Usage

The API surface is currently fairly limited (only yields events as XML/JSON documents), but is planned to be expanded in the future.

This will print each record as an XML string.

from evtx import PyEvtxParser


def main():
    parser = PyEvtxParser("./samples/Security_short_selected.evtx")
    for record in parser.records():
        print(f'Event Record ID: {record["event_record_id"]}')
        print(f'Event Timestamp: {record["timestamp"]}')
        print(record['data'])
        print(f'------------------------------------------')

And this will print each record as a JSON string.

from evtx.parser import PyEvtxParser


def main():
    parser = PyEvtxParser("./samples/Security_short_selected.evtx")
    for record in parser.records_json():
        print(f'Event Record ID: {record["event_record_id"]}')
        print(f'Event Timestamp: {record["timestamp"]}')
        print(record['data'])
        print(f'------------------------------------------')

File-like objects are also supported.

from evtx.parser import PyEvtxParser


def main():
    a = open("./samples/Security_short_selected.evtx", 'rb')

    # io.BytesIO is also supported.
    parser = PyEvtxParser(a)
    for record in parser.records_json():
        print(f'Event Record ID: {record["event_record_id"]}')
        print(f'Event Timestamp: {record["timestamp"]}')
        print(record['data'])
        print(f'------------------------------------------')

Release files for evtx 0.7.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Built distributions (wheels)

Table of built distributions (wheels) for evtx 0.7.2
File
evtx-0.7.2-cp39-none-win_amd64.whl CPython 3.9 none Windows x86-64 Details
evtx-0.7.2-cp39-cp39-manylinux_2_24_x86_64.whl CPython 3.9 CPython 3.9 Linux glibc 2.24+ x86-64 Details
evtx-0.7.2-cp39-cp39-macosx_10_7_x86_64.whl CPython 3.9 CPython 3.9 macOS 10.7+ x86-64 Details
evtx-0.7.2-cp38-none-win_amd64.whl CPython 3.8 none Windows x86-64 Details
evtx-0.7.2-cp38-cp38-manylinux_2_24_x86_64.whl CPython 3.8 CPython 3.8 Linux glibc 2.24+ x86-64 Details
evtx-0.7.2-cp38-cp38-macosx_10_7_x86_64.whl CPython 3.8 CPython 3.8 macOS 10.7+ x86-64 Details
evtx-0.7.2-cp37-none-win_amd64.whl CPython 3.7 none Windows x86-64 Details
evtx-0.7.2-cp37-cp37m-manylinux_2_24_x86_64.whl CPython 3.7 CPython 3.7 pymalloc Linux glibc 2.24+ x86-64 Details
evtx-0.7.2-cp37-cp37m-macosx_10_7_x86_64.whl CPython 3.7 CPython 3.7 pymalloc macOS 10.7+ x86-64 Details
evtx-0.7.2-cp36-none-win_amd64.whl CPython 3.6 none Windows x86-64 Details
evtx-0.7.2-cp36-cp36m-manylinux_2_24_x86_64.whl CPython 3.6 CPython 3.6 pymalloc Linux glibc 2.24+ x86-64 Details
evtx-0.7.2-cp36-cp36m-macosx_10_7_x86_64.whl CPython 3.6 CPython 3.6 pymalloc macOS 10.7+ x86-64 Details

Total release size: 8.6 MB

Release files / evtx-0.7.2-cp39-none-win_amd64.whl

Download URL evtx-0.7.2-cp39-none-win_amd64.whl
Size 672.7 kB
Tags CPython 3.9 Windows x86-64
SHA-256 checksum
How to use checksums
7ba3cbb1b416a1c81e0629c400655ef79668265accaef358db05acae469092fe
BLAKE2b-256 checksum
How to use checksums
37e8fd2fe146c70fc2acd11e9d37b7dac7f1433b33270c16dafc701baa1c27dd
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via maturin/0.11.0

Release files / evtx-0.7.2-cp39-cp39-manylinux_2_24_x86_64.whl

Download URL evtx-0.7.2-cp39-cp39-manylinux_2_24_x86_64.whl
Size 756.6 kB
Tags CPython 3.9 Linux glibc 2.24+ x86-64
SHA-256 checksum
How to use checksums
7860efe4d6ab656ad2f34282424cfc5fb3617a85ce258c23f8c152f36dcb285e
BLAKE2b-256 checksum
How to use checksums
fe7e8a750a6664fa729b6be406ef47e533f06344c62bf31950deafe1f5f780a1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via maturin/0.11.0

Release files / evtx-0.7.2-cp39-cp39-macosx_10_7_x86_64.whl

Download URL evtx-0.7.2-cp39-cp39-macosx_10_7_x86_64.whl
Size 711.0 kB
Tags CPython 3.9 macOS 10.7+ x86-64
SHA-256 checksum
How to use checksums
e6c70f131d8cd2f3924558e1353af26526c7f2f0e8b995fc46c8c8a3295455dc
BLAKE2b-256 checksum
How to use checksums
82b19196a4c5891ee4804ef2415c6e52e381c738329ab6fbfc5f181a46b96e59
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via maturin/0.11.0

Release files / evtx-0.7.2-cp38-none-win_amd64.whl

Download URL evtx-0.7.2-cp38-none-win_amd64.whl
Size 672.7 kB
Tags CPython 3.8 Windows x86-64
SHA-256 checksum
How to use checksums
2e0ea37f8959e29332fa1603cf133b88592d47c3d09ac5e4e3f5482ab34efed2
BLAKE2b-256 checksum
How to use checksums
7750c75a94c6c164119ea77269c260739c7db22a0a3bff6b18627a18e3e6d0c1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via maturin/0.11.0

Release files / evtx-0.7.2-cp38-cp38-manylinux_2_24_x86_64.whl

Download URL evtx-0.7.2-cp38-cp38-manylinux_2_24_x86_64.whl
Size 754.5 kB
Tags CPython 3.8 Linux glibc 2.24+ x86-64
SHA-256 checksum
How to use checksums
8a6ca51697ff58e17e048479bff87525c4cff17be54f24a889381e9699e68f20
BLAKE2b-256 checksum
How to use checksums
9bd3c805e6634e51c61c862587148d5547c516e49ffdc56e038005d4f5478054
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via maturin/0.11.0

Release files / evtx-0.7.2-cp38-cp38-macosx_10_7_x86_64.whl

Download URL evtx-0.7.2-cp38-cp38-macosx_10_7_x86_64.whl
Size 711.0 kB
Tags CPython 3.8 macOS 10.7+ x86-64
SHA-256 checksum
How to use checksums
dcbc0288fead6ab38624b0bd0681daf294746fd45c10759396de5f7d66dec01c
BLAKE2b-256 checksum
How to use checksums
1c60d1520b22f1852677098ef79f9a258f36accc6cb065bf19a2a9e2db59564d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via maturin/0.11.0

Release files / evtx-0.7.2-cp37-none-win_amd64.whl

Download URL evtx-0.7.2-cp37-none-win_amd64.whl
Size 672.7 kB
Tags CPython 3.7 Windows x86-64
SHA-256 checksum
How to use checksums
48485fe7c643ce9e615467677fcced59bdb22148ffa0d325901e9f4aa4ff761d
BLAKE2b-256 checksum
How to use checksums
fcc6cf1f123c1a444adac081bae8d5ea623fa33ba71aee62a8902f24ee458f85
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via maturin/0.11.0

Release files / evtx-0.7.2-cp37-cp37m-manylinux_2_24_x86_64.whl

Download URL evtx-0.7.2-cp37-cp37m-manylinux_2_24_x86_64.whl
Size 754.5 kB
Tags CPython 3.7 CPython 3.7 pymalloc Linux glibc 2.24+ x86-64
SHA-256 checksum
How to use checksums
0d05552bdfeefb97c439f105da6b62863eea2d4ec4e78893b408452cfe0f56bd
BLAKE2b-256 checksum
How to use checksums
81be9fe0963d899261bf2a6bf17739034cf05c559f6e96b60da911444ba1a069
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via maturin/0.11.0

Release files / evtx-0.7.2-cp37-cp37m-macosx_10_7_x86_64.whl

Download URL evtx-0.7.2-cp37-cp37m-macosx_10_7_x86_64.whl
Size 711.1 kB
Tags CPython 3.7 CPython 3.7 pymalloc macOS 10.7+ x86-64
SHA-256 checksum
How to use checksums
3923968aceaf7bef727ee31a083fd0724f0ef2d2514badb4e5c215342c695721
BLAKE2b-256 checksum
How to use checksums
14fd4d78f7ba8622b5fac12930f7e013f9ceafc942305e693100e9d4f857b607
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via maturin/0.11.0

Release files / evtx-0.7.2-cp36-none-win_amd64.whl

Download URL evtx-0.7.2-cp36-none-win_amd64.whl
Size 672.7 kB
Tags CPython 3.6 Windows x86-64
SHA-256 checksum
How to use checksums
f2348a55e500a74d587bc9915bdb8af83d063293f6f56e5f9be697ff88bbcd9c
BLAKE2b-256 checksum
How to use checksums
fa5f8d0c0a1fe0be0ed5ebaa1cf44ff510a677a8f29d80ed0ff3ed7ed1bd6fed
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via maturin/0.11.0

Release files / evtx-0.7.2-cp36-cp36m-manylinux_2_24_x86_64.whl

Download URL evtx-0.7.2-cp36-cp36m-manylinux_2_24_x86_64.whl
Size 756.8 kB
Tags CPython 3.6 CPython 3.6 pymalloc Linux glibc 2.24+ x86-64
SHA-256 checksum
How to use checksums
89adcca7a24eecd14eff49648b5f2f322802aebad6d51ad71493707c62019065
BLAKE2b-256 checksum
How to use checksums
6764f359236c8700387dd2711a7f59a16467b02e7a8bcd1a098d8794a5c590b3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via maturin/0.11.0

Release files / evtx-0.7.2-cp36-cp36m-macosx_10_7_x86_64.whl

Download URL evtx-0.7.2-cp36-cp36m-macosx_10_7_x86_64.whl
Size 711.1 kB
Tags CPython 3.6 CPython 3.6 pymalloc macOS 10.7+ x86-64
SHA-256 checksum
How to use checksums
17d4c0833a0cc5e68153d03816576d5d629cc1d63aa96ff5ecd2aaacf07fe10b
BLAKE2b-256 checksum
How to use checksums
653f68822c35e19cd76448cb71bd63cb95b77bd969392f805a5e14fbcd057cc2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via maturin/0.11.0

Release history Release notifications | RSS feed

0.13.0

7 release files

0.12.1

7 release files

0.12.0

7 release files

0.11.1

7 release files

0.8.9

7 release files

0.8.8

7 release files

0.8.7

7 release files

0.8.6

7 release files

0.8.4

5 release files

0.8.3

5 release files

0.8.2

4 release files

0.8.1

4 release files

0.8.0

18 release files

0.7.3

15 release files

This release

0.7.2 This release

12 release files

0.6.9

9 release files

0.6.8

1 release file

0.6.7

7 release files

0.6.6

7 release files

0.6.5

7 release files

0.6.3

7 release files

0.6.2

7 release files

0.5.1

7 release files

0.4.0

9 release files

0.3.2

10 release files

0.3.0

11 release files

0.2.7

7 release files

0.2.6

7 release files

0.2.5

7 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page