Security project · case file

Windows Log Triage

Installable EVTX/Sysmon triage with parser-completeness metadata, validated IOCs, lightweight rules, and protected reports.

Status
Tested portfolio tool
Role
Tool developer and security analyst
Tools
Python, EVTX, Sysmon, PowerShell, Jinja2, HTML, JSON, CSV
Last reviewed
2026-09-01
Verified result
Produces escaped HTML and machine-readable reports while exposing records read, records skipped, parse errors, and parser backend.

Executive summary

Windows Log Triage processes EVTX and Sysmon evidence into normalized events, IOC candidates, lightweight behavior leads, process/network summaries, and portable reports.

The tool makes incomplete analysis visible. Its JSON result records the parser backend, records read, records skipped, and parse-error count. Rules are triage heuristics rather than full Sigma coverage or detection verdicts.

Security engineering work

  • Split reading, normalization, IOC extraction, rules, analysis, reporting, and CLI behavior into focused modules.
  • Passes EVTX paths to PowerShell through an environment variable and uses -LiteralPath instead of interpolating paths into commands.
  • Surfaces PowerShell subprocess failures.
  • Imports xmltodict independently from python-evtx so fallback behavior is explicit.
  • Validates IPv4 candidates with Python’s ipaddress module.
  • Rejects non-positive --max-per-file values.
  • Escapes attacker-controlled evidence in HTML and applies restrictive browser protections.
  • Labels intentionally limited processing through completeness metadata rather than silently presenting partial results as complete.

Measured validation

A clean-wheel run against sanitized EVTX data recorded:

Metric Result
Records read 5
Records skipped 0
Parse errors 0

Repository CI builds and installs the package, exercises winlog-triage and python -m winlog_triage, runs the complete test suite across supported Python versions, and feeds the stable aggregate quality gate.

Sanitized demonstration

Outputs and limitations

  • JSON: complete machine-readable summary and parsing metadata
  • CSV: representative normalized event rows
  • HTML: escaped summary and evidence fields with restrictive browser protections

Reports may contain sensitive usernames, hostnames, command lines, paths, and indicators. Do not execute commands or browse extracted indicators. Preserve original EVTX evidence separately.

Evidence