$ cat writeup.md…
$ cat writeup.md…
duckerz
Task: Find the DriveName for a suspicious HarddiskVolume4 device in a Windows Event Log. Solution: Parse the EVTX file with python-evtx, search for events containing HarddiskVolume4, and extract the Volume GUID from the DriveName field in NTFS EventID 98 records.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar