O'Reilly logo

Mastering Windows Network Forensics and Investigation, 2nd Edition by Scott Pearson, Ryan Johnson, Steve Bunting, Steven Anson

Stay ahead with the world's most comprehensive technology and business learning platform.

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, tutorials, and more.

Start Free Trial

No credit card required

Repairing Windows XP/2003 Corrupted Event Log Databases

At this stage, you should have a clear understanding of the circumstances that will cause a Windows XP and Server 2003 event log file to be reported as corrupt by a utility that relies on the Windows event log service API. In short, this will occur when the four critical fields appearing in both the header and the floating footer are out of synch and when the file status byte is other than 0x00 or 0x08. It stands to reason, then, that the tweak required to render such a file viewable is to copy the four fields from the floating footer and paste them into the corresponding fields in the header and to change the file status byte to 0x08 (or 0x00).

All Hail EVTX
Since the EVTX file format ...

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, interactive tutorials, and more.

Start Free Trial

No credit card required