Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

EVTX created can't be opened by the Windows Event Viewer #2

Open
Folteto opened this issue Aug 21, 2024 · 0 comments
Open

EVTX created can't be opened by the Windows Event Viewer #2

Folteto opened this issue Aug 21, 2024 · 0 comments

Comments

@Folteto
Copy link

Folteto commented Aug 21, 2024

All the evtx I've been trying to create from XML are corrupted and can't be properly opened by the Windows Event Viewer : the first events look OK but then an event is infinitely cloned and the wizard says that the etvx is damaged.
See the screenshot below for how it looks (sorry it's in french).
image

The same happens for the xml files I have on my side or the xml files created by create_eventlog.py.
I think there's an issue with the chunks. I have this behaviour only with evtx that have a number of chunks > 1.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant