[{"title":"( 79 个子文件 5.53MB ) evtx:Windows XML事件日志(EVTX)格式的快速(安全)解析器","children":[{"title":"evtx-master","children":[{"title":"LICENSE-MIT <span style='color:#111;'> 1.05KB </span>","children":null,"spread":false},{"title":"LICENSE-APACHE <span style='color:#111;'> 11.09KB </span>","children":null,"spread":false},{"title":"profile_vtune.ps1 <span style='color:#111;'> 549B </span>","children":null,"spread":false},{"title":"eventvwr.ico <span style='color:#111;'> 63.91KB </span>","children":null,"spread":false},{"title":"Cargo.lock <span style='color:#111;'> 36.24KB </span>","children":null,"spread":false},{"title":".github","children":[{"title":"workflows","children":[{"title":"test.yml <span style='color:#111;'> 437B </span>","children":null,"spread":false},{"title":"release.yml <span style='color:#111;'> 4.43KB </span>","children":null,"spread":false}],"spread":true}],"spread":true},{"title":"tests","children":[{"title":"test_cli.rs <span style='color:#111;'> 1.80KB </span>","children":null,"spread":false},{"title":"test_record_separate_json.rs <span style='color:#111;'> 1.05KB </span>","children":null,"spread":false},{"title":"test_cli_interactive.rs <span style='color:#111;'> 2.55KB </span>","children":null,"spread":false},{"title":"fixtures.rs <span style='color:#111;'> 2.51KB </span>","children":null,"spread":false},{"title":"test_full_samples.rs <span style='color:#111;'> 4.57KB </span>","children":null,"spread":false},{"title":"test_record_samples.rs <span style='color:#111;'> 8.28KB </span>","children":null,"spread":false}],"spread":true},{"title":"src","children":[{"title":"bin","children":[{"title":"evtx_dump.rs <span style='color:#111;'> 12.74KB </span>","children":null,"spread":false}],"spread":true},{"title":"evtx_record.rs <span style='color:#111;'> 4.12KB </span>","children":null,"spread":false},{"title":"model","children":[{"title":"raw.rs <span style='color:#111;'> 2.42KB </span>","children":null,"spread":false},{"title":"deserialized.rs <span style='color:#111;'> 2.68KB </span>","children":null,"spread":false},{"title":"mod.rs <span style='color:#111;'> 62B </span>","children":null,"spread":false},{"title":"xml.rs <span style='color:#111;'> 3.50KB </span>","children":null,"spread":false}],"spread":true},{"title":"string_cache.rs <span style='color:#111;'> 1.48KB </span>","children":null,"spread":false},{"title":"evtx_chunk.rs <span style='color:#111;'> 14.75KB </span>","children":null,"spread":false},{"title":"xml_output.rs <span style='color:#111;'> 5.39KB </span>","children":null,"spread":false},{"title":"template_cache.rs <span style='color:#111;'> 1.85KB </span>","children":null,"spread":false},{"title":"binxml","children":[{"title":"mod.rs <span style='color:#111;'> 108B </span>","children":null,"spread":false},{"title":"tokens.rs <span style='color:#111;'> 10.09KB </span>","children":null,"spread":false},{"title":"deserializer.rs <span style='color:#111;'> 10.61KB </span>","children":null,"spread":false},{"title":"assemble.rs <span style='color:#111;'> 15.05KB </span>","children":null,"spread":false},{"title":"value_variant.rs <span style='color:#111;'> 26.12KB </span>","children":null,"spread":false},{"title":"name.rs <span style='color:#111;'> 3.00KB </span>","children":null,"spread":false}],"spread":false},{"title":"json_output.rs <span style='color:#111;'> 18.08KB </span>","children":null,"spread":false},{"title":"evtx_file_header.rs <span style='color:#111;'> 3.69KB </span>","children":null,"spread":false},{"title":"evtx_parser.rs <span style='color:#111;'> 23.52KB </span>","children":null,"spread":false},{"title":"benches","children":[{"title":"benchmark.rs <span style='color:#111;'> 1.43KB </span>","children":null,"spread":false}],"spread":false},{"title":"lib.rs <span style='color:#111;'> 1.79KB </span>","children":null,"spread":false},{"title":"macros.rs <span style='color:#111;'> 6.48KB </span>","children":null,"spread":false},{"title":"utils","children":[{"title":"mod.rs <span style='color:#111;'> 291B </span>","children":null,"spread":false},{"title":"binxml_utils.rs <span style='color:#111;'> 4.34KB </span>","children":null,"spread":false},{"title":"time.rs <span style='color:#111;'> 799B </span>","children":null,"spread":false},{"title":"hexdump.rs <span style='color:#111;'> 4.54KB </span>","children":null,"spread":false}],"spread":false},{"title":"err.rs <span style='color:#111;'> 9.01KB </span>","children":null,"spread":false}],"spread":false},{"title":"Cargo.toml <span style='color:#111;'> 2.08KB </span>","children":null,"spread":false},{"title":"samples","children":[{"title":"event_with_entity_ref.xml <span style='color:#111;'> 4.05KB </span>","children":null,"spread":false},{"title":"event_with_entity_ref_2.xml <span style='color:#111;'> 2.56KB </span>","children":null,"spread":false},{"title":"application_event_1_separate_attributes.json <span style='color:#111;'> 1005B </span>","children":null,"spread":false},{"title":"2-system-Security-dirty.evtx <span style='color:#111;'> 12.07MB </span>","children":null,"spread":false},{"title":"E_Windows_system32_winevt_logs_Microsoft-Windows-Shell-Core%4Operational.evtx <span style='color:#111;'> 1.00MB </span>","children":null,"spread":false},{"title":"E_ShadowCopy6_windows_system32_winevt_logs_Microsoft-Windows-CAPI2%4Operational.evtx <span style='color:#111;'> 1.00MB </span>","children":null,"spread":false},{"title":"sysmon.evtx <span style='color:#111;'> 1.07MB </span>","children":null,"spread":false},{"title":"event_with_text_and_attributes.xml <span style='color:#111;'> 709B </span>","children":null,"spread":false},{"title":"2-vss_0-Microsoft-Windows-RemoteDesktopServices-RdpCoreTS%4Operational.evtx <span style='color:#111;'> 1.00MB </span>","children":null,"spread":false},{"title":"event_with_template_as_substitution.xml <span style='color:#111;'> 1.16KB </span>","children":null,"spread":false},{"title":"event_with_multiple_nodes_same_name.json <span style='color:#111;'> 4.33KB </span>","children":null,"spread":false},{"title":"sample_with_a_bad_chunk_magic.evtx <span style='color:#111;'> 1.00MB </span>","children":null,"spread":false},{"title":"Microsoft-Windows-LanguagePackSetup%4Operational.evtx <span style='color:#111;'> 68.00KB </span>","children":null,"spread":false},{"title":"2-vss_0-Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx <span style='color:#111;'> 1.00MB </span>","children":null,"spread":false},{"title":"Archive-ForwardedEvents-test.evtx <span style='color:#111;'> 4.13MB </span>","children":null,"spread":false},{"title":"new-user-security.evtx <span style='color:#111;'> 68.00KB </span>","children":null,"spread":false},{"title":"binxml.dat <span style='color:#111;'> 1.52KB </span>","children":null,"spread":false},{"title":"event_with_text_and_attributes.json <span style='color:#111;'> 795B </span>","children":null,"spread":false},{"title":"event_with_multiple_nodes_same_name_separate_attr.json <span style='color:#111;'> 4.05KB </span>","children":null,"spread":false},{"title":"Application.evtx <span style='color:#111;'> 4.00MB </span>","children":null,"spread":false},{"title":"security.evtx <span style='color:#111;'> 2.07MB </span>","children":null,"spread":false},{"title":"2-vss_7-System.evtx <span style='color:#111;'> 1.07MB </span>","children":null,"spread":false},{"title":"2-system-Microsoft-Windows-LiveId%4Operational.evtx <span style='color:#111;'> 1.00MB </span>","children":null,"spread":false},{"title":"Microsoft-Windows-HelloForBusiness%4Operational.evtx <span style='color:#111;'> 68.00KB </span>","children":null,"spread":false},{"title":"system.evtx <span style='color:#111;'> 1.07MB </span>","children":null,"spread":false},{"title":"security_big_sample.evtx <span style='color:#111;'> 30.07MB </span>","children":null,"spread":false},{"title":"security_event_1.json <span style='color:#111;'> 864B </span>","children":null,"spread":false},{"title":"Security_short_selected.evtx <span style='color:#111;'> 68.00KB </span>","children":null,"spread":false},{"title":"Application_no_crc32.evtx <span style='color:#111;'> 68.00KB </span>","children":null,"spread":false},{"title":"security_event_1.xml <span style='color:#111;'> 857B </span>","children":null,"spread":false},{"title":"event_with_eventdata.json <span style='color:#111;'> 1.31KB </span>","children":null,"spread":false},{"title":"sample-with-irregular-bool-values.evtx <span style='color:#111;'> 2.07MB </span>","children":null,"spread":false},{"title":"E_Windows_system32_winevt_logs_Microsoft-Windows-CAPI2%4Operational.evtx <span style='color:#111;'> 1.00MB </span>","children":null,"spread":false},{"title":"event_with_eventdata.xml <span style='color:#111;'> 1.54KB </span>","children":null,"spread":false}],"spread":false},{"title":".gitignore <span style='color:#111;'> 48B </span>","children":null,"spread":false},{"title":"CHANGELOG.md <span style='color:#111;'> 9.93KB </span>","children":null,"spread":false},{"title":"release.py <span style='color:#111;'> 258B </span>","children":null,"spread":false},{"title":"README.md <span style='color:#111;'> 6.79KB </span>","children":null,"spread":false}],"spread":false}],"spread":true}]