EventLogMonitor hooks into Windows Event Logs and displays new events as they are written to the log
A Rust parser for Windows Jumplist artifact
A Rust parser for Notepad TabState artifact
Rhaegal is a tool used to scan Windows Event Logs for suspicious logs. Rhaegal uses custom rule format to detect suspicious/malicious logs