Security project · case file
Windows Log Triage
Installable EVTX/Sysmon triage with parser-completeness metadata, validated IOCs, lightweight rules, and protected reports.
- Status
- Tested portfolio tool
- Role
- Tool developer and security analyst
- Tools
- Python, EVTX, Sysmon, PowerShell, Jinja2, HTML, JSON, CSV
- Last reviewed
- 2026-09-01
- Verified result
- Produces escaped HTML and machine-readable reports while exposing records read, records skipped, parse errors, and parser backend.
Executive summary
Windows Log Triage processes EVTX and Sysmon evidence into normalized events, IOC candidates, lightweight behavior leads, process/network summaries, and portable reports.
The tool makes incomplete analysis visible. Its JSON result records the parser backend, records read, records skipped, and parse-error count. Rules are triage heuristics rather than full Sigma coverage or detection verdicts.
Security engineering work
- Split reading, normalization, IOC extraction, rules, analysis, reporting, and CLI behavior into focused modules.
- Passes EVTX paths to PowerShell through an environment variable and uses
-LiteralPathinstead of interpolating paths into commands. - Surfaces PowerShell subprocess failures.
- Imports
xmltodictindependently frompython-evtxso fallback behavior is explicit. - Validates IPv4 candidates with Python’s
ipaddressmodule. - Rejects non-positive
--max-per-filevalues. - Escapes attacker-controlled evidence in HTML and applies restrictive browser protections.
- Labels intentionally limited processing through completeness metadata rather than silently presenting partial results as complete.
Measured validation
A clean-wheel run against sanitized EVTX data recorded:
| Metric | Result |
|---|---|
| Records read | 5 |
| Records skipped | 0 |
| Parse errors | 0 |
Repository CI builds and installs the package, exercises winlog-triage and python -m winlog_triage, runs the complete test suite across supported Python versions, and feeds the stable aggregate quality gate.
Sanitized demonstration
Outputs and limitations
- JSON: complete machine-readable summary and parsing metadata
- CSV: representative normalized event rows
- HTML: escaped summary and evidence fields with restrictive browser protections
Reports may contain sensitive usernames, hostnames, command lines, paths, and indicators. Do not execute commands or browse extracted indicators. Preserve original EVTX evidence separately.