etl-parser
Event Trace Log file reader in pure Python
etl-parser is a pure Python 3 parser library for ETL Windows log files. ETL is the default format for ETW as well as the default format for the Kernel logger.
etl-parser has no system dependencies, and will work well on both Windows and Linux.
Since this format is not documented, we merged information from the blog of Geoff Chappel and reverse engineering activities conducted by Airbus CERT team.
What is ETL and why is it a pain to work with? Consider ETL as a container, like AVI is for video files. Reading ETL is similarly frustrating as reading an AVI file without the right codec.
etl-parser tries to solve this problem by including parsers for the following well known log formats:
ETW manifest base provider
TraceLogging
MOF for kernel log
How to use etl-parser?
etl-parser offers two scripts. The fir