Read the chunks a dirty event log's header does not count - #350
Merged
Merged
Conversation
python-evtx reads only as many chunks as an event log's file header counts. On a log marked dirty that count can be lower than the chunks the file holds, and the newest records sit in the chunks past it. log_records also reads those chunks when they carry the chunk signature and both checksums match, skipping any record number already read, and every event log artifact now reads through it. On LoneWolf and Szechuan the System and Security logs, and on PC-MUS-001 the System log, held 255 to 4,173 records in chunks their headers did not count. The notes and sample_data of the 20 artifacts whose rows changed are updated to match. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
python-evtx declares record_num on each Record instance at run time, so pylint, which can see the class when python-evtx is installed, reports it as a missing member. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Reads the chunks a dirty event log's header does not count.
log_recordsNotes and sample_data are updated for the 20 artifacts whose rows changed on LoneWolf, PC-MUS-001 and Szechuan.
🤖 Generated with Claude Code