velociraptor
velociraptor copied to clipboard
Native EVTX carving
We would like a VQL native EVTX carver.
Scan logical disk using yara for file type headers. Extract bytes and use binary parser for parsing out records/part records.
Windows.Carving.USN is a similar example.
This is a duplicate of #319
This is a duplicate of #319