import ctypes, sys import os from evtx import PyEvtxParser import shutil
defmain(): shutil.copy("C:/Windows/System32/winevt/Logs/System.evtx", "D:/项目/Windows取证/data_file/System.evtx") parser = PyEvtxParser("D:/项目/Windows取证/data_file/System.evtx") for record in parser.records(): if record["event_record_id"] == 6005: print(f'Event Record ID: {record["event_record_id"]}') print(f'Event Timestamp: {record["timestamp"]}') print(record['data']) print(f'------------------------------------------') break else: print(f'Event Record ID: {record["event_record_id"]}')