AVvXsEgc772rCUbvf89xsBcsZM HLngIxNttLzMIQlS1TZ00P6LgfViU5R9KgGmqgb1T2TG04h SUoyfF I4oEkFjaRwg9vpbuYKGBiHwMJRToYrVK9PDHbO1rhlR4BgTfyg11Yk1qsOAw4wxHueavx6V3uraOcbYWUM3I3t56VEQZpalUIbRp4qfDjuvAZSXQ=w640 h208

Simple script for the purpose of finding remote connections to Windows machine and ideally some public IPs. It checks for some EventIDs regarding remote logins and sessions.

You should pip install -r requirements.txt so the script can work and parse some of the .evtx files inside winevt folder.

The winevt/Logs folders and the script must have identical file path.

Execution Example

AVvXsEjYl8lPZLIe3AFfPvcgTvKBp7bLjn8SWp6h7o5fKyjZEEKZickcxVYmhdIhuB8EtSdacAaFLbBQ4dTNs72mPaE0NYAZ9Cif7JBBSrE06Wj8S0IfIq48FnG47oTrB9OObg0e2UGsRIVu9eJer85uxVir1lBhLds IK5Xfcm1D48kpnN6xwv3fIyHeCP7vA=w640 h138

Result Example

AVvXsEgc772rCUbvf89xsBcsZM HLngIxNttLzMIQlS1TZ00P6LgfViU5R9KgGmqgb1T2TG04h SUoyfF I4oEkFjaRwg9vpbuYKGBiHwMJRToYrVK9PDHbO1rhlR4BgTfyg11Yk1qsOAw4wxHueavx6V3uraOcbYWUM3I3t56VEQZpalUIbRp4qfDjuvAZSXQ=w640 h208

administrator

Leave a Reply

Your email address will not be published. Required fields are marked *

fb logo
recover dogecoin from a scam
recover ethereum from a scammer
hire a hacker to hack iphone
hire a hacker to hack snapchat
hire a hacker to hack a windows computer
error: Content is protected !!