pyevtx-rs
Python bindings for https://github.com/omerbenamram/evtx/.
Installation
Available on PyPi - https://pypi.org/project/evtx/.
To install from PyPi - pip install evtx
Wheels
Wheels are currently automatically built for python 3.6,3.7,3.8,3.9 for all 64-bit platforms (Windows, macOS, and manylinux).
Installation from sources
Installation is possible for other platforms by installing from sources, this requires a rust compiler and setuptools-rust.
Run python setup.py install
Usage
The API surface is currently fairly limited (only yields events as XML/JSON documents), but is planned to be expanded in the future.
This will print each record as an XML string.
from evtx import PyEvtxParser
def main():
parser = PyEvtxParser("./samples/Security_short_selected.evtx")
for record in parser.records():
print(f'Event Record ID: {record["event_record_id"]}')
print(f'Event Timestamp: {record["timestamp"]}')
print(record['data'])
print(f'------------------------------------------')
And this will print each record as a JSON string.
from evtx.parser import PyEvtxParser
def main():
parser = PyEvtxParser("./samples/Security_short_selected.evtx")
for record in parser.records_json():
print(f'Event Record ID: {record["event_record_id"]}')
print(f'Event Timestamp: {record["timestamp"]}')
print(record['data'])
print(f'------------------------------------------')
File-like objects are also supported.
from evtx.parser import PyEvtxParser
def main():
a = open("./samples/Security_short_selected.evtx", 'rb')
# io.BytesIO is also supported.
parser = PyEvtxParser(a)
for record in parser.records_json():
print(f'Event Record ID: {record["event_record_id"]}')
print(f'Event Timestamp: {record["timestamp"]}')
print(record['data'])
print(f'------------------------------------------')
Release files for evtx 0.7.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Built distributions (wheels)
| File | Reset | |||
|---|---|---|---|---|
| evtx-0.7.2-cp39-none-win_amd64.whl | CPython 3.9 | none | Windows x86-64 | Details |
| evtx-0.7.2-cp39-cp39-manylinux_2_24_x86_64.whl | CPython 3.9 | CPython 3.9 | Linux glibc 2.24+ x86-64 | Details |
| evtx-0.7.2-cp39-cp39-macosx_10_7_x86_64.whl | CPython 3.9 | CPython 3.9 | macOS 10.7+ x86-64 | Details |
| evtx-0.7.2-cp38-none-win_amd64.whl | CPython 3.8 | none | Windows x86-64 | Details |
| evtx-0.7.2-cp38-cp38-manylinux_2_24_x86_64.whl | CPython 3.8 | CPython 3.8 | Linux glibc 2.24+ x86-64 | Details |
| evtx-0.7.2-cp38-cp38-macosx_10_7_x86_64.whl | CPython 3.8 | CPython 3.8 | macOS 10.7+ x86-64 | Details |
| evtx-0.7.2-cp37-none-win_amd64.whl | CPython 3.7 | none | Windows x86-64 | Details |
| evtx-0.7.2-cp37-cp37m-manylinux_2_24_x86_64.whl | CPython 3.7 | CPython 3.7 pymalloc | Linux glibc 2.24+ x86-64 | Details |
| evtx-0.7.2-cp37-cp37m-macosx_10_7_x86_64.whl | CPython 3.7 | CPython 3.7 pymalloc | macOS 10.7+ x86-64 | Details |
| evtx-0.7.2-cp36-none-win_amd64.whl | CPython 3.6 | none | Windows x86-64 | Details |
| evtx-0.7.2-cp36-cp36m-manylinux_2_24_x86_64.whl | CPython 3.6 | CPython 3.6 pymalloc | Linux glibc 2.24+ x86-64 | Details |
| evtx-0.7.2-cp36-cp36m-macosx_10_7_x86_64.whl | CPython 3.6 | CPython 3.6 pymalloc | macOS 10.7+ x86-64 | Details |
Total release size: 8.6 MB
Release files / evtx-0.7.2-cp39-none-win_amd64.whl
| Download URL | evtx-0.7.2-cp39-none-win_amd64.whl |
|---|---|
| Size | 672.7 kB |
| Tags | CPython 3.9 Windows x86-64 |
|
SHA-256 checksum How to use checksums |
7ba3cbb1b416a1c81e0629c400655ef79668265accaef358db05acae469092fe
|
|
BLAKE2b-256 checksum How to use checksums |
37e8fd2fe146c70fc2acd11e9d37b7dac7f1433b33270c16dafc701baa1c27dd
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
maturin/0.11.0
|
Release files / evtx-0.7.2-cp39-cp39-manylinux_2_24_x86_64.whl
| Download URL | evtx-0.7.2-cp39-cp39-manylinux_2_24_x86_64.whl |
|---|---|
| Size | 756.6 kB |
| Tags | CPython 3.9 Linux glibc 2.24+ x86-64 |
|
SHA-256 checksum How to use checksums |
7860efe4d6ab656ad2f34282424cfc5fb3617a85ce258c23f8c152f36dcb285e
|
|
BLAKE2b-256 checksum How to use checksums |
fe7e8a750a6664fa729b6be406ef47e533f06344c62bf31950deafe1f5f780a1
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
maturin/0.11.0
|
Release files / evtx-0.7.2-cp39-cp39-macosx_10_7_x86_64.whl
| Download URL | evtx-0.7.2-cp39-cp39-macosx_10_7_x86_64.whl |
|---|---|
| Size | 711.0 kB |
| Tags | CPython 3.9 macOS 10.7+ x86-64 |
|
SHA-256 checksum How to use checksums |
e6c70f131d8cd2f3924558e1353af26526c7f2f0e8b995fc46c8c8a3295455dc
|
|
BLAKE2b-256 checksum How to use checksums |
82b19196a4c5891ee4804ef2415c6e52e381c738329ab6fbfc5f181a46b96e59
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
maturin/0.11.0
|
Release files / evtx-0.7.2-cp38-none-win_amd64.whl
| Download URL | evtx-0.7.2-cp38-none-win_amd64.whl |
|---|---|
| Size | 672.7 kB |
| Tags | CPython 3.8 Windows x86-64 |
|
SHA-256 checksum How to use checksums |
2e0ea37f8959e29332fa1603cf133b88592d47c3d09ac5e4e3f5482ab34efed2
|
|
BLAKE2b-256 checksum How to use checksums |
7750c75a94c6c164119ea77269c260739c7db22a0a3bff6b18627a18e3e6d0c1
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
maturin/0.11.0
|
Release files / evtx-0.7.2-cp38-cp38-manylinux_2_24_x86_64.whl
| Download URL | evtx-0.7.2-cp38-cp38-manylinux_2_24_x86_64.whl |
|---|---|
| Size | 754.5 kB |
| Tags | CPython 3.8 Linux glibc 2.24+ x86-64 |
|
SHA-256 checksum How to use checksums |
8a6ca51697ff58e17e048479bff87525c4cff17be54f24a889381e9699e68f20
|
|
BLAKE2b-256 checksum How to use checksums |
9bd3c805e6634e51c61c862587148d5547c516e49ffdc56e038005d4f5478054
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
maturin/0.11.0
|
Release files / evtx-0.7.2-cp38-cp38-macosx_10_7_x86_64.whl
| Download URL | evtx-0.7.2-cp38-cp38-macosx_10_7_x86_64.whl |
|---|---|
| Size | 711.0 kB |
| Tags | CPython 3.8 macOS 10.7+ x86-64 |
|
SHA-256 checksum How to use checksums |
dcbc0288fead6ab38624b0bd0681daf294746fd45c10759396de5f7d66dec01c
|
|
BLAKE2b-256 checksum How to use checksums |
1c60d1520b22f1852677098ef79f9a258f36accc6cb065bf19a2a9e2db59564d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
maturin/0.11.0
|
Release files / evtx-0.7.2-cp37-none-win_amd64.whl
| Download URL | evtx-0.7.2-cp37-none-win_amd64.whl |
|---|---|
| Size | 672.7 kB |
| Tags | CPython 3.7 Windows x86-64 |
|
SHA-256 checksum How to use checksums |
48485fe7c643ce9e615467677fcced59bdb22148ffa0d325901e9f4aa4ff761d
|
|
BLAKE2b-256 checksum How to use checksums |
fcc6cf1f123c1a444adac081bae8d5ea623fa33ba71aee62a8902f24ee458f85
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
maturin/0.11.0
|
Release files / evtx-0.7.2-cp37-cp37m-manylinux_2_24_x86_64.whl
| Download URL | evtx-0.7.2-cp37-cp37m-manylinux_2_24_x86_64.whl |
|---|---|
| Size | 754.5 kB |
| Tags | CPython 3.7 CPython 3.7 pymalloc Linux glibc 2.24+ x86-64 |
|
SHA-256 checksum How to use checksums |
0d05552bdfeefb97c439f105da6b62863eea2d4ec4e78893b408452cfe0f56bd
|
|
BLAKE2b-256 checksum How to use checksums |
81be9fe0963d899261bf2a6bf17739034cf05c559f6e96b60da911444ba1a069
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
maturin/0.11.0
|
Release files / evtx-0.7.2-cp37-cp37m-macosx_10_7_x86_64.whl
| Download URL | evtx-0.7.2-cp37-cp37m-macosx_10_7_x86_64.whl |
|---|---|
| Size | 711.1 kB |
| Tags | CPython 3.7 CPython 3.7 pymalloc macOS 10.7+ x86-64 |
|
SHA-256 checksum How to use checksums |
3923968aceaf7bef727ee31a083fd0724f0ef2d2514badb4e5c215342c695721
|
|
BLAKE2b-256 checksum How to use checksums |
14fd4d78f7ba8622b5fac12930f7e013f9ceafc942305e693100e9d4f857b607
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
maturin/0.11.0
|
Release files / evtx-0.7.2-cp36-none-win_amd64.whl
| Download URL | evtx-0.7.2-cp36-none-win_amd64.whl |
|---|---|
| Size | 672.7 kB |
| Tags | CPython 3.6 Windows x86-64 |
|
SHA-256 checksum How to use checksums |
f2348a55e500a74d587bc9915bdb8af83d063293f6f56e5f9be697ff88bbcd9c
|
|
BLAKE2b-256 checksum How to use checksums |
fa5f8d0c0a1fe0be0ed5ebaa1cf44ff510a677a8f29d80ed0ff3ed7ed1bd6fed
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
maturin/0.11.0
|
Release files / evtx-0.7.2-cp36-cp36m-manylinux_2_24_x86_64.whl
| Download URL | evtx-0.7.2-cp36-cp36m-manylinux_2_24_x86_64.whl |
|---|---|
| Size | 756.8 kB |
| Tags | CPython 3.6 CPython 3.6 pymalloc Linux glibc 2.24+ x86-64 |
|
SHA-256 checksum How to use checksums |
89adcca7a24eecd14eff49648b5f2f322802aebad6d51ad71493707c62019065
|
|
BLAKE2b-256 checksum How to use checksums |
6764f359236c8700387dd2711a7f59a16467b02e7a8bcd1a098d8794a5c590b3
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
maturin/0.11.0
|
Release files / evtx-0.7.2-cp36-cp36m-macosx_10_7_x86_64.whl
| Download URL | evtx-0.7.2-cp36-cp36m-macosx_10_7_x86_64.whl |
|---|---|
| Size | 711.1 kB |
| Tags | CPython 3.6 CPython 3.6 pymalloc macOS 10.7+ x86-64 |
|
SHA-256 checksum How to use checksums |
17d4c0833a0cc5e68153d03816576d5d629cc1d63aa96ff5ecd2aaacf07fe10b
|
|
BLAKE2b-256 checksum How to use checksums |
653f68822c35e19cd76448cb71bd63cb95b77bd969392f805a5e14fbcd057cc2
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
maturin/0.11.0
|