Skip to content

Read the chunks a dirty event log's header does not count - #350

Merged
abrignoni merged 2 commits into
mainfrom
fix/evtx-uncounted-chunks
Sep 27, 2026
Merged

abrignoni merged 2 commits into
mainfrom
fix/evtx-uncounted-chunks

Conversation

@abrignoni

Copy link
Copy Markdown
Owner

Reads the chunks a dirty event log's header does not count.

  • python-evtx stops at the file header's chunk count, and on a log marked dirty the newest records sit in the chunks past it (libyal describes this case)
  • A later chunk is read when its signature and both checksums match; a record number already read is skipped
  • Every event log artifact now reads through the shared log_records

Notes and sample_data are updated for the 20 artifacts whose rows changed on LoneWolf, PC-MUS-001 and Szechuan.

🤖 Generated with Claude Code

abrignoni and others added 2 commits September 27, 2026 17:07
python-evtx reads only as many chunks as an event log's file header counts.
On a log marked dirty that count can be lower than the chunks the file holds,
and the newest records sit in the chunks past it. log_records also reads
those chunks when they carry the chunk signature and both checksums match,
skipping any record number already read, and every event log artifact now
reads through it.

On LoneWolf and Szechuan the System and Security logs, and on PC-MUS-001 the
System log, held 255 to 4,173 records in chunks their headers did not count.
The notes and sample_data of the 20 artifacts whose rows changed are updated
to match.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
python-evtx declares record_num on each Record instance at run time, so
pylint, which can see the class when python-evtx is installed, reports it
as a missing member.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@abrignoni
abrignoni merged commit bf594e1 into main Sep 27, 2026
11 checks passed
@abrignoni
abrignoni deleted the fix/evtx-uncounted-chunks branch September 27, 2026 21:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant