Wevol is a C program for parsing and sorting through event records in the Windows Event .evtx files.
- CMake - https://cmake.org/ - build system
- Check - https://libcheck.github.io/check/ - unit testing framework
Currently, I am creating the API and the tests for reading in evtx files. I have also moved development to a seperate branch to keep main clean.
- Write and test API for decoding evtx log format.
- Reimplament needed functions from Microsoft's Event Log API:
- OpenBackupEventLog()
- CloseEventLog()
- ReadEventLog()
- Create basic CLI with the following features:
- Specify one or more evtx log files to view a record list from
- Specify a record within a log to view the details of
- Create an API for decoding the older evt log format.
- Create an interactive CLI to enable easier exploring and searching of logs.
- Create an optional GUI to make usage more convinient.