Skip to content

v1.0.0

Latest

Choose a tag to compare

@0xHasanM 0xHasanM released this 17 Feb 18:37
· 3 commits to main since this release
f8b4b99

LogonSessionAuditor

This tool parses Windows EVTX logs to extract login and logout sessions from a security.evtx file. It uses a Tkinter GUI to let you select the EVTX file and specify a time for correlating login and logout events.

Features

  • Extract login (EventID 4624) and logout events (EventID 4634, 4647)
  • Correlate sessions based on a specified UTC time
  • Output the correlated sessions to a CSV file

Requirements

Install the required packages using:

pip install -r requirements.txt

Executable Version

Web-based Flask app is available in the latest release.

Contributing

Contributions are welcome! Feel free to fork the repository, make improvements, and submit a pull request.

License

This project is open-source and available under the MIT License.

Contributors