Skip to content
This repository has been archived by the owner on Aug 17, 2022. It is now read-only.

certsocietegenerale/event2timeline

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

31 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Event2Timeline

Event2Timeline is a free tool based on D3js to graph Microsoft Windows sessions events. It parses both EVTX event logs from post Vista systems (Vista, Windows 7, Windows 8), and CSV exports of the legacy EVT log files.

How to install

  • Clone the git repository

  • Create a virtual environment with virtualenv and activate it (optional)

  • Install requirements with pip install -r requirements.txt

Alternatively:

How to run

For old EVT files:

  • Convert your eventlogs to CSV format. You can use the free Microsoft Log Parser 2.2.

  • Run event2timeline.py -c -f csv_filename.csv

  • Open timeline/timeline-sessions.html in your favorite browser

The timeline is divided into two parts: a large timeline, and a smaller one. You can select what events to display on the large timeline by dragging your mouse on the smaller timeline. Events encompassed in the selected timespan will be displayed on the bigger timeline.

Post-Vista EVTX files are supported. Just run event2timeline.py -e -f Security.evtx

Example

Rendering example

License

This work is licensed under the GPL License http://www.gnu.org/licenses/gpl.txt

About

Simple Microsoft Windows sessions event logs visualization

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published