forensicseasy

Manager

duckerz

Task: Find the DriveName for a suspicious HarddiskVolume4 device in a Windows Event Log. Solution: Parse the EVTX file with python-evtx, search for events containing HarddiskVolume4, and extract the Volume GUID from the DriveName field in NTFS EventID 98 records.

$ ls tags/ techniques/
evtx_parsingxml_searchguid_extraction

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]