plaso.parsers package
Subpackages
- plaso.parsers.bencode_plugins package
- plaso.parsers.cookie_plugins package
- Submodules
- plaso.parsers.cookie_plugins.ganalytics module
- plaso.parsers.cookie_plugins.interface module
- plaso.parsers.cookie_plugins.manager module
- Module contents
- plaso.parsers.czip_plugins package
- Submodules
- plaso.parsers.czip_plugins.interface module
- plaso.parsers.czip_plugins.oxml module
OpenXMLEventData
OpenXMLEventData.application
OpenXMLEventData.application_version
OpenXMLEventData.author
OpenXMLEventData.creation_time
OpenXMLEventData.digital_signature
OpenXMLEventData.edit_duration
OpenXMLEventData.hyperlinks_changed
OpenXMLEventData.last_printed_time
OpenXMLEventData.last_saved_by
OpenXMLEventData.links_up_to_date
OpenXMLEventData.modification_time
OpenXMLEventData.number_of_characters
OpenXMLEventData.number_of_characters_with_spaces
OpenXMLEventData.number_of_clips
OpenXMLEventData.number_of_hidden_slides
OpenXMLEventData.number_of_lines
OpenXMLEventData.number_of_pages
OpenXMLEventData.number_of_paragraphs
OpenXMLEventData.number_of_slides
OpenXMLEventData.number_of_words
OpenXMLEventData.revision_number
OpenXMLEventData.scale
OpenXMLEventData.security_flags
OpenXMLEventData.shared_doc
OpenXMLEventData.template
OpenXMLEventData.DATA_TYPE
OpenXMLPlugin
- Module contents
- plaso.parsers.esedb_plugins package
- Submodules
- plaso.parsers.esedb_plugins.file_history module
FileHistoryESEDBPlugin
FileHistoryNamespaceEventData
FileHistoryNamespaceEventData.creation_time
FileHistoryNamespaceEventData.file_attribute
FileHistoryNamespaceEventData.identifier
FileHistoryNamespaceEventData.modification_time
FileHistoryNamespaceEventData.original_filename
FileHistoryNamespaceEventData.parent_identifier
FileHistoryNamespaceEventData.usn_number
FileHistoryNamespaceEventData.DATA_TYPE
- plaso.parsers.esedb_plugins.interface module
- plaso.parsers.esedb_plugins.msie_webcache module
MsieWebCacheContainerEventData
MsieWebCacheContainerEventData.access_count
MsieWebCacheContainerEventData.access_time
MsieWebCacheContainerEventData.cached_filename
MsieWebCacheContainerEventData.cached_file_size
MsieWebCacheContainerEventData.cache_identifier
MsieWebCacheContainerEventData.container_identifier
MsieWebCacheContainerEventData.creation_time
MsieWebCacheContainerEventData.entry_identifier
MsieWebCacheContainerEventData.expiration_time
MsieWebCacheContainerEventData.file_extension
MsieWebCacheContainerEventData.modification_time
MsieWebCacheContainerEventData.post_check_time
MsieWebCacheContainerEventData.redirect_url
MsieWebCacheContainerEventData.request_headers
MsieWebCacheContainerEventData.response_headers
MsieWebCacheContainerEventData.synchronization_count
MsieWebCacheContainerEventData.synchronization_time
MsieWebCacheContainerEventData.url
MsieWebCacheContainerEventData.DATA_TYPE
MsieWebCacheContainersEventData
MsieWebCacheContainersEventData.access_time
MsieWebCacheContainersEventData.container_identifier
MsieWebCacheContainersEventData.directory
MsieWebCacheContainersEventData.name
MsieWebCacheContainersEventData.scavenge_time
MsieWebCacheContainersEventData.set_identifier
MsieWebCacheContainersEventData.DATA_TYPE
MsieWebCacheCookieData
MsieWebCacheCookieData.container_identifier
MsieWebCacheCookieData.cookie_hash
MsieWebCacheCookieData.cookie_name
MsieWebCacheCookieData.cookie_value_raw
MsieWebCacheCookieData.cookie_value
MsieWebCacheCookieData.entry_identifier
MsieWebCacheCookieData.expiration_time
MsieWebCacheCookieData.flags
MsieWebCacheCookieData.modification_time
MsieWebCacheCookieData.request_domain
MsieWebCacheCookieData.DATA_TYPE
MsieWebCacheESEDBPlugin
MsieWebCacheESEDBPlugin.DATA_FORMAT
MsieWebCacheESEDBPlugin.GetRawCookieValue()
MsieWebCacheESEDBPlugin.NAME
MsieWebCacheESEDBPlugin.OPTIONAL_TABLES
MsieWebCacheESEDBPlugin.ParseContainersTable()
MsieWebCacheESEDBPlugin.ParseLeakFilesTable()
MsieWebCacheESEDBPlugin.ParsePartitionsTable()
MsieWebCacheESEDBPlugin.REQUIRED_TABLES
MsieWebCacheLeakFilesEventData
MsieWebCachePartitionsEventData
- plaso.parsers.esedb_plugins.srum module
SRUMApplicationResourceUsageEventData
SRUMApplicationResourceUsageEventData.application
SRUMApplicationResourceUsageEventData.background_bytes_read
SRUMApplicationResourceUsageEventData.background_bytes_written
SRUMApplicationResourceUsageEventData.background_context_switches
SRUMApplicationResourceUsageEventData.background_cycle_time
SRUMApplicationResourceUsageEventData.background_number_for_flushes
SRUMApplicationResourceUsageEventData.background_number_for_read_operations
SRUMApplicationResourceUsageEventData.background_number_for_write_operations
SRUMApplicationResourceUsageEventData.face_time
SRUMApplicationResourceUsageEventData.foreground_bytes_read
SRUMApplicationResourceUsageEventData.foreground_bytes_written
SRUMApplicationResourceUsageEventData.foreground_context_switches
SRUMApplicationResourceUsageEventData.foreground_cycle_time
SRUMApplicationResourceUsageEventData.foreground_number_for_flushes
SRUMApplicationResourceUsageEventData.foreground_number_for_read_operations
SRUMApplicationResourceUsageEventData.foreground_number_for_write_operations
SRUMApplicationResourceUsageEventData.identifier
SRUMApplicationResourceUsageEventData.recorded_time
SRUMApplicationResourceUsageEventData.user_identifier
SRUMApplicationResourceUsageEventData.DATA_TYPE
SRUMNetworkConnectivityUsageEventData
SRUMNetworkConnectivityUsageEventData.application
SRUMNetworkConnectivityUsageEventData.identifier
SRUMNetworkConnectivityUsageEventData.interface_luid
SRUMNetworkConnectivityUsageEventData.last_connected_time
SRUMNetworkConnectivityUsageEventData.l2_profile_flags
SRUMNetworkConnectivityUsageEventData.l2_profile_identifier
SRUMNetworkConnectivityUsageEventData.recorded_time
SRUMNetworkConnectivityUsageEventData.user_identifier
SRUMNetworkConnectivityUsageEventData.DATA_TYPE
SRUMNetworkDataUsageEventData
SRUMNetworkDataUsageEventData.application
SRUMNetworkDataUsageEventData.bytes_received
SRUMNetworkDataUsageEventData.bytes_sent
SRUMNetworkDataUsageEventData.identifier
SRUMNetworkDataUsageEventData.interface_luid
SRUMNetworkDataUsageEventData.l2_profile_flags
SRUMNetworkDataUsageEventData.l2_profile_identifier
SRUMNetworkDataUsageEventData.recorded_time
SRUMNetworkDataUsageEventData.user_identifier
SRUMNetworkDataUsageEventData.DATA_TYPE
SystemResourceUsageMonitorESEDBPlugin
SystemResourceUsageMonitorESEDBPlugin.DATA_FORMAT
SystemResourceUsageMonitorESEDBPlugin.NAME
SystemResourceUsageMonitorESEDBPlugin.OPTIONAL_TABLES
SystemResourceUsageMonitorESEDBPlugin.ParseApplicationResourceUsage()
SystemResourceUsageMonitorESEDBPlugin.ParseNetworkConnectivityUsage()
SystemResourceUsageMonitorESEDBPlugin.ParseNetworkDataUsage()
SystemResourceUsageMonitorESEDBPlugin.REQUIRED_TABLES
- plaso.parsers.esedb_plugins.user_access_logging module
UserAccessLoggingClientsEventsData
UserAccessLoggingClientsEventsData.access_time
UserAccessLoggingClientsEventsData.authenticated_username
UserAccessLoggingClientsEventsData.client_name
UserAccessLoggingClientsEventsData.insert_time
UserAccessLoggingClientsEventsData.role_identifier
UserAccessLoggingClientsEventsData.role_name
UserAccessLoggingClientsEventsData.source_ip_address
UserAccessLoggingClientsEventsData.tenant_identifier
UserAccessLoggingClientsEventsData.total_accesses
UserAccessLoggingClientsEventsData.DATA_TYPE
UserAccessLoggingDNSEventData
UserAccessLoggingESEDBPlugin
UserAccessLoggingESEDBPlugin.DATA_FORMAT
UserAccessLoggingESEDBPlugin.NAME
UserAccessLoggingESEDBPlugin.ParseClientsTable()
UserAccessLoggingESEDBPlugin.ParseDNSTable()
UserAccessLoggingESEDBPlugin.ParseRoleAccessTable()
UserAccessLoggingESEDBPlugin.ParseVirtualMachinesTable()
UserAccessLoggingESEDBPlugin.REQUIRED_TABLES
UserAccessLoggingRoleAccessEventsData
UserAccessLoggingSystemIdentityEventdata
UserAccessLoggingVirtualMachinesEventData
UserAccessLoggingVirtualMachinesEventData.bios_identifier
UserAccessLoggingVirtualMachinesEventData.creation_time
UserAccessLoggingVirtualMachinesEventData.last_active_time
UserAccessLoggingVirtualMachinesEventData.serial_number
UserAccessLoggingVirtualMachinesEventData.vm_identifier
UserAccessLoggingVirtualMachinesEventData.DATA_TYPE
- Module contents
- plaso.parsers.jsonl_plugins package
- Submodules
- plaso.parsers.jsonl_plugins.aws_cloudtrail_log module
AWSCloudTrailEventData
AWSCloudTrailEventData.access_key
AWSCloudTrailEventData.account_identifier
AWSCloudTrailEventData.cloud_trail_event
AWSCloudTrailEventData.event_name
AWSCloudTrailEventData.event_source
AWSCloudTrailEventData.recorded_time
AWSCloudTrailEventData.resources
AWSCloudTrailEventData.source_ip
AWSCloudTrailEventData.user_identity_arn
AWSCloudTrailEventData.user_name
AWSCloudTrailEventData.DATA_TYPE
AWSCloudTrailLogJSONLPlugin
- plaso.parsers.jsonl_plugins.azure_activity_log module
AzureActivityLogEventData
AzureActivityLogEventData.caller
AzureActivityLogEventData.client_ip
AzureActivityLogEventData.correlation_identifier
AzureActivityLogEventData.event_data_identifier
AzureActivityLogEventData.event_name
AzureActivityLogEventData.level
AzureActivityLogEventData.operation_identifier
AzureActivityLogEventData.operation_name
AzureActivityLogEventData.recorded_time
AzureActivityLogEventData.resource_group
AzureActivityLogEventData.resource_identifier
AzureActivityLogEventData.resource_provider
AzureActivityLogEventData.resource_type
AzureActivityLogEventData.subscription_identifier
AzureActivityLogEventData.tenant_identifier
AzureActivityLogEventData.DATA_TYPE
AzureActivityLogJSONLPlugin
- plaso.parsers.jsonl_plugins.azure_application_gateway_log module
AzureApplicationGatewayAccessEventData
AzureApplicationGatewayAccessEventData.client_ip
AzureApplicationGatewayAccessEventData.client_port
AzureApplicationGatewayAccessEventData.client_response_time
AzureApplicationGatewayAccessEventData.host
AzureApplicationGatewayAccessEventData.http_method
AzureApplicationGatewayAccessEventData.http_status
AzureApplicationGatewayAccessEventData.http_version
AzureApplicationGatewayAccessEventData.instance_identifier
AzureApplicationGatewayAccessEventData.original_host
AzureApplicationGatewayAccessEventData.original_request_uri
AzureApplicationGatewayAccessEventData.received_bytes
AzureApplicationGatewayAccessEventData.recorded_time
AzureApplicationGatewayAccessEventData.request_query
AzureApplicationGatewayAccessEventData.request_uri
AzureApplicationGatewayAccessEventData.sent_bytes
AzureApplicationGatewayAccessEventData.server_response_latency
AzureApplicationGatewayAccessEventData.server_routed
AzureApplicationGatewayAccessEventData.server_status
AzureApplicationGatewayAccessEventData.ssl_cipher
AzureApplicationGatewayAccessEventData.ssl_client_certificate_fingerprint
AzureApplicationGatewayAccessEventData.ssl_client_certificate_issuer_name
AzureApplicationGatewayAccessEventData.ssl_client_verify
AzureApplicationGatewayAccessEventData.ssl_enabled
AzureApplicationGatewayAccessEventData.ssl_protocol
AzureApplicationGatewayAccessEventData.time_taken
AzureApplicationGatewayAccessEventData.transaction_id
AzureApplicationGatewayAccessEventData.user_agent
AzureApplicationGatewayAccessEventData.waf_evaluation_time
AzureApplicationGatewayAccessEventData.waf_mode
AzureApplicationGatewayAccessEventData.DATA_TYPE
AzureApplicationGatewayAccessLogJSONLPlugin
- plaso.parsers.jsonl_plugins.docker_container_config module
DockerContainerConfigurationEventData
DockerContainerConfigurationEventData.action
DockerContainerConfigurationEventData.container_identifier
DockerContainerConfigurationEventData.container_name
DockerContainerConfigurationEventData.creation_time
DockerContainerConfigurationEventData.end_time
DockerContainerConfigurationEventData.start_time
DockerContainerConfigurationEventData.DATA_TYPE
DockerContainerConfigurationJSONLPlugin
- plaso.parsers.jsonl_plugins.docker_container_log module
- plaso.parsers.jsonl_plugins.docker_layer_config module
- plaso.parsers.jsonl_plugins.gcp_log module
GCPLogEventData
GCPLogEventData.container
GCPLogEventData.event_subtype
GCPLogEventData.event_type
GCPLogEventData.filename
GCPLogEventData.firewall_rules
GCPLogEventData.firewall_source_ranges
GCPLogEventData.log_name
GCPLogEventData.message
GCPLogEventData.policy_deltas
GCPLogEventData.recorded_time
GCPLogEventData.request_account_identifier
GCPLogEventData.request_description
GCPLogEventData.request_direction
GCPLogEventData.request_email
GCPLogEventData.request_member
GCPLogEventData.request_metadata
GCPLogEventData.request_name
GCPLogEventData.request_target_tags
GCPLogEventData.resource_labels
GCPLogEventData.resource_name
GCPLogEventData.service_account_display_name
GCPLogEventData.service_name
GCPLogEventData.severity
GCPLogEventData.text_payload
GCPLogEventData.user
GCPLogEventData.DATA_TYPE
GCPLogJSONLPlugin
- plaso.parsers.jsonl_plugins.interface module
- plaso.parsers.jsonl_plugins.ios_app_privacy module
- plaso.parsers.jsonl_plugins.microsoft365_audit_log module
Microsoft365AuditLogEventData
Microsoft365AuditLogEventData.audit_record_identifier
Microsoft365AuditLogEventData.application_access_context
Microsoft365AuditLogEventData.client_ip
Microsoft365AuditLogEventData.object_identifier
Microsoft365AuditLogEventData.operation_name
Microsoft365AuditLogEventData.organization_identifier
Microsoft365AuditLogEventData.record_type
Microsoft365AuditLogEventData.recorded_time
Microsoft365AuditLogEventData.result_status
Microsoft365AuditLogEventData.scope
Microsoft365AuditLogEventData.user_identifier
Microsoft365AuditLogEventData.user_key
Microsoft365AuditLogEventData.user_type
Microsoft365AuditLogEventData.workload
Microsoft365AuditLogEventData.DATA_TYPE
Microsoft365AuditLogJSONLPlugin
- Module contents
- plaso.parsers.olecf_plugins package
- Submodules
- plaso.parsers.olecf_plugins.automatic_destinations module
AutomaticDestinationsDestListEntryEventData
AutomaticDestinationsDestListEntryEventData.birth_droid_file_identifier
AutomaticDestinationsDestListEntryEventData.birth_droid_volume_identifier
AutomaticDestinationsDestListEntryEventData.droid_file_identifier
AutomaticDestinationsDestListEntryEventData.droid_volume_identifier
AutomaticDestinationsDestListEntryEventData.entry_number
AutomaticDestinationsDestListEntryEventData.hostname
AutomaticDestinationsDestListEntryEventData.modification_time
AutomaticDestinationsDestListEntryEventData.offset
AutomaticDestinationsDestListEntryEventData.path
AutomaticDestinationsDestListEntryEventData.pin_status
AutomaticDestinationsDestListEntryEventData.DATA_TYPE
AutomaticDestinationsOLECFPlugin
- plaso.parsers.olecf_plugins.default module
- plaso.parsers.olecf_plugins.interface module
- plaso.parsers.olecf_plugins.summary module
DocumentSummaryInformationOLECFPlugin
OLECFDocumentSummaryInformation
OLECFDocumentSummaryInformationEventData
OLECFDocumentSummaryInformationEventData.application_version
OLECFDocumentSummaryInformationEventData.category
OLECFDocumentSummaryInformationEventData.codepage
OLECFDocumentSummaryInformationEventData.company
OLECFDocumentSummaryInformationEventData.content_status
OLECFDocumentSummaryInformationEventData.content_type
OLECFDocumentSummaryInformationEventData.document_parts
OLECFDocumentSummaryInformationEventData.document_version
OLECFDocumentSummaryInformationEventData.item_creation_time
OLECFDocumentSummaryInformationEventData.item_modification_time
OLECFDocumentSummaryInformationEventData.language
OLECFDocumentSummaryInformationEventData.links_up_to_date
OLECFDocumentSummaryInformationEventData.manager
OLECFDocumentSummaryInformationEventData.number_of_bytes
OLECFDocumentSummaryInformationEventData.number_of_characters_with_white_space
OLECFDocumentSummaryInformationEventData.number_of_clips
OLECFDocumentSummaryInformationEventData.number_of_hidden_slides
OLECFDocumentSummaryInformationEventData.number_of_lines
OLECFDocumentSummaryInformationEventData.number_of_notes
OLECFDocumentSummaryInformationEventData.number_of_paragraphs
OLECFDocumentSummaryInformationEventData.number_of_slides
OLECFDocumentSummaryInformationEventData.presentation_format
OLECFDocumentSummaryInformationEventData.scale
OLECFDocumentSummaryInformationEventData.shared_document
OLECFDocumentSummaryInformationEventData.DATA_TYPE
OLECFPropertySetStream
OLECFSummaryInformation
OLECFSummaryInformationEventData
OLECFSummaryInformationEventData.application
OLECFSummaryInformationEventData.author
OLECFSummaryInformationEventData.codepage
OLECFSummaryInformationEventData.comments
OLECFSummaryInformationEventData.creation_time
OLECFSummaryInformationEventData.edit_duration
OLECFSummaryInformationEventData.item_creation_time
OLECFSummaryInformationEventData.item_modification_time
OLECFSummaryInformationEventData.keywords
OLECFSummaryInformationEventData.last_printed_time
OLECFSummaryInformationEventData.last_saved_by
OLECFSummaryInformationEventData.last_save_time
OLECFSummaryInformationEventData.number_of_characters
OLECFSummaryInformationEventData.number_of_pages
OLECFSummaryInformationEventData.number_of_words
OLECFSummaryInformationEventData.revision_number
OLECFSummaryInformationEventData.security_flags
OLECFSummaryInformationEventData.subject
OLECFSummaryInformationEventData.template
OLECFSummaryInformationEventData.title
OLECFSummaryInformationEventData.DATA_TYPE
SummaryInformationOLECFPlugin
- Module contents
- plaso.parsers.plist_plugins package
- Submodules
- plaso.parsers.plist_plugins.airport module
- plaso.parsers.plist_plugins.apple_account module
- plaso.parsers.plist_plugins.bluetooth module
- plaso.parsers.plist_plugins.default module
- plaso.parsers.plist_plugins.install_history module
- plaso.parsers.plist_plugins.interface module
- plaso.parsers.plist_plugins.ios_carplay module
- plaso.parsers.plist_plugins.ios_identityservices module
- plaso.parsers.plist_plugins.ipod module
- plaso.parsers.plist_plugins.launchd module
- plaso.parsers.plist_plugins.macos_user module
MacOSUserEventData
MacOSUserEventData.fullname
MacOSUserEventData.home_directory
MacOSUserEventData.last_login_attempt_time
MacOSUserEventData.last_login_time
MacOSUserEventData.last_password_set_time
MacOSUserEventData.number_of_failed_login_attempts
MacOSUserEventData.password_hash
MacOSUserEventData.user_identifier
MacOSUserEventData.username
MacOSUserEventData.DATA_TYPE
MacOSUserPlistPlugin
- plaso.parsers.plist_plugins.safari_downloads module
- plaso.parsers.plist_plugins.safari_history module
- plaso.parsers.plist_plugins.software_update module
- plaso.parsers.plist_plugins.spotlight_searched_terms module
- plaso.parsers.plist_plugins.spotlight_volume module
- plaso.parsers.plist_plugins.time_machine module
- Module contents
- plaso.parsers.shared package
- plaso.parsers.sqlite_plugins package
- Submodules
- plaso.parsers.sqlite_plugins.android_calls module
- plaso.parsers.sqlite_plugins.android_hangouts module
- plaso.parsers.sqlite_plugins.android_sms module
- plaso.parsers.sqlite_plugins.android_tango module
AndroidTangoContactEventData
AndroidTangoContactEventData.access_time
AndroidTangoContactEventData.birthday
AndroidTangoContactEventData.distance
AndroidTangoContactEventData.first_name
AndroidTangoContactEventData.friend_request_message
AndroidTangoContactEventData.friend_request_time
AndroidTangoContactEventData.friend_request_type
AndroidTangoContactEventData.gender
AndroidTangoContactEventData.is_friend
AndroidTangoContactEventData.last_active_time
AndroidTangoContactEventData.last_name
AndroidTangoContactEventData.status
AndroidTangoContactEventData.DATA_TYPE
AndroidTangoConversationEventData
AndroidTangoMessageEventData
AndroidTangoProfilePlugin
AndroidTangoTCPlugin
- plaso.parsers.sqlite_plugins.android_twitter module
AndroidTwitterContactEventData
AndroidTwitterContactEventData.creation_time
AndroidTwitterContactEventData.description
AndroidTwitterContactEventData.followers
AndroidTwitterContactEventData.friends
AndroidTwitterContactEventData.friendship_time
AndroidTwitterContactEventData.identifier
AndroidTwitterContactEventData.image_url
AndroidTwitterContactEventData.location
AndroidTwitterContactEventData.modification_time
AndroidTwitterContactEventData.name
AndroidTwitterContactEventData.query
AndroidTwitterContactEventData.statuses
AndroidTwitterContactEventData.user_identifier
AndroidTwitterContactEventData.username
AndroidTwitterContactEventData.web_url
AndroidTwitterContactEventData.DATA_TYPE
AndroidTwitterPlugin
AndroidTwitterSearchEventData
AndroidTwitterStatusEventData
AndroidTwitterStatusEventData.author_identifier
AndroidTwitterStatusEventData.content
AndroidTwitterStatusEventData.creation_time
AndroidTwitterStatusEventData.favorited
AndroidTwitterStatusEventData.identifier
AndroidTwitterStatusEventData.query
AndroidTwitterStatusEventData.retweeted
AndroidTwitterStatusEventData.username
AndroidTwitterStatusEventData.DATA_TYPE
- plaso.parsers.sqlite_plugins.android_webview module
AndroidWebViewCookieEventData
AndroidWebViewCookieEventData.cookie_name
AndroidWebViewCookieEventData.data
AndroidWebViewCookieEventData.expiration_time
AndroidWebViewCookieEventData.host
AndroidWebViewCookieEventData.offset
AndroidWebViewCookieEventData.path
AndroidWebViewCookieEventData.query
AndroidWebViewCookieEventData.secure
AndroidWebViewCookieEventData.url
AndroidWebViewCookieEventData.DATA_TYPE
AndroidWebViewPlugin
- plaso.parsers.sqlite_plugins.android_webviewcache module
- plaso.parsers.sqlite_plugins.chrome_autofill module
- plaso.parsers.sqlite_plugins.chrome_cookies module
BaseChromeCookiePlugin
Chrome17CookiePlugin
Chrome66CookiePlugin
ChromeCookieEventData
ChromeCookieEventData.access_time
ChromeCookieEventData.cookie_name
ChromeCookieEventData.creation_time
ChromeCookieEventData.data
ChromeCookieEventData.expiration_time
ChromeCookieEventData.host
ChromeCookieEventData.httponly
ChromeCookieEventData.path
ChromeCookieEventData.persistent
ChromeCookieEventData.query
ChromeCookieEventData.secure
ChromeCookieEventData.url
ChromeCookieEventData.DATA_TYPE
- plaso.parsers.sqlite_plugins.chrome_extension_activity module
ChromeExtensionActivityEventData
ChromeExtensionActivityEventData.action_type
ChromeExtensionActivityEventData.activity_id
ChromeExtensionActivityEventData.api_name
ChromeExtensionActivityEventData.arg_url
ChromeExtensionActivityEventData.args
ChromeExtensionActivityEventData.extension_id
ChromeExtensionActivityEventData.other
ChromeExtensionActivityEventData.page_title
ChromeExtensionActivityEventData.page_url
ChromeExtensionActivityEventData.query
ChromeExtensionActivityEventData.recorded_time
ChromeExtensionActivityEventData.DATA_TYPE
ChromeExtensionActivityPlugin
- plaso.parsers.sqlite_plugins.chrome_history module
BaseGoogleChromeHistoryPlugin
ChromeHistoryFileDownloadedEventData
ChromeHistoryFileDownloadedEventData.danger_type
ChromeHistoryFileDownloadedEventData.end_time
ChromeHistoryFileDownloadedEventData.full_path
ChromeHistoryFileDownloadedEventData.interrupt_reason
ChromeHistoryFileDownloadedEventData.offset
ChromeHistoryFileDownloadedEventData.opened
ChromeHistoryFileDownloadedEventData.query
ChromeHistoryFileDownloadedEventData.received_bytes
ChromeHistoryFileDownloadedEventData.start_time
ChromeHistoryFileDownloadedEventData.state
ChromeHistoryFileDownloadedEventData.total_bytes
ChromeHistoryFileDownloadedEventData.url
ChromeHistoryFileDownloadedEventData.DATA_TYPE
ChromeHistoryPageVisitedEventData
ChromeHistoryPageVisitedEventData.from_visit
ChromeHistoryPageVisitedEventData.last_visited_time
ChromeHistoryPageVisitedEventData.offset
ChromeHistoryPageVisitedEventData.page_transition_type
ChromeHistoryPageVisitedEventData.query
ChromeHistoryPageVisitedEventData.title
ChromeHistoryPageVisitedEventData.typed_count
ChromeHistoryPageVisitedEventData.url
ChromeHistoryPageVisitedEventData.url_hidden
ChromeHistoryPageVisitedEventData.visit_count
ChromeHistoryPageVisitedEventData.visit_source
ChromeHistoryPageVisitedEventData.DATA_TYPE
GoogleChrome27HistoryPlugin
GoogleChrome8HistoryPlugin
- plaso.parsers.sqlite_plugins.dropbox module
- plaso.parsers.sqlite_plugins.edge_load_statistics module
- plaso.parsers.sqlite_plugins.firefox_cookies module
BaseFirefoxCookiePlugin
FirefoxCookie10Plugin
FirefoxCookie2Plugin
FirefoxCookieEventData
FirefoxCookieEventData.access_time
FirefoxCookieEventData.cookie_name
FirefoxCookieEventData.creation_time
FirefoxCookieEventData.data
FirefoxCookieEventData.expiration_time
FirefoxCookieEventData.httponly
FirefoxCookieEventData.host
FirefoxCookieEventData.offset
FirefoxCookieEventData.path
FirefoxCookieEventData.query
FirefoxCookieEventData.secure
FirefoxCookieEventData.DATA_TYPE
- plaso.parsers.sqlite_plugins.firefox_downloads module
FirefoxDownloadEventData
FirefoxDownloadEventData.end_time
FirefoxDownloadEventData.full_path
FirefoxDownloadEventData.mime_type
FirefoxDownloadEventData.name
FirefoxDownloadEventData.offset
FirefoxDownloadEventData.query
FirefoxDownloadEventData.received_bytes
FirefoxDownloadEventData.referrer
FirefoxDownloadEventData.start_time
FirefoxDownloadEventData.temporary_location
FirefoxDownloadEventData.total_bytes
FirefoxDownloadEventData.url
FirefoxDownloadEventData.DATA_TYPE
FirefoxDownloadsPlugin
- plaso.parsers.sqlite_plugins.firefox_history module
FirefoxHistoryPlugin
FirefoxHistoryPlugin.DATA_FORMAT
FirefoxHistoryPlugin.NAME
FirefoxHistoryPlugin.ParseBookmarkAnnotationRow()
FirefoxHistoryPlugin.ParseBookmarkFolderRow()
FirefoxHistoryPlugin.ParseBookmarkRow()
FirefoxHistoryPlugin.ParsePageVisitedRow()
FirefoxHistoryPlugin.QUERIES
FirefoxHistoryPlugin.REQUIRED_STRUCTURE
FirefoxHistoryPlugin.SCHEMAS
FirefoxHistoryPlugin.URL_CACHE_QUERY
FirefoxPlacesBookmarkAnnotationEventData
FirefoxPlacesBookmarkAnnotationEventData.added_time
FirefoxPlacesBookmarkAnnotationEventData.content
FirefoxPlacesBookmarkAnnotationEventData.modification_time
FirefoxPlacesBookmarkAnnotationEventData.offset
FirefoxPlacesBookmarkAnnotationEventData.query
FirefoxPlacesBookmarkAnnotationEventData.title
FirefoxPlacesBookmarkAnnotationEventData.url
FirefoxPlacesBookmarkAnnotationEventData.DATA_TYPE
FirefoxPlacesBookmarkEventData
FirefoxPlacesBookmarkEventData.added_time
FirefoxPlacesBookmarkEventData.host
FirefoxPlacesBookmarkEventData.modification_time
FirefoxPlacesBookmarkEventData.offset
FirefoxPlacesBookmarkEventData.places_title
FirefoxPlacesBookmarkEventData.query
FirefoxPlacesBookmarkEventData.title
FirefoxPlacesBookmarkEventData.type
FirefoxPlacesBookmarkEventData.url
FirefoxPlacesBookmarkEventData.visit_count
FirefoxPlacesBookmarkEventData.DATA_TYPE
FirefoxPlacesBookmarkFolderEventData
FirefoxPlacesPageVisitedEventData
FirefoxPlacesPageVisitedEventData.from_visit
FirefoxPlacesPageVisitedEventData.hidden
FirefoxPlacesPageVisitedEventData.host
FirefoxPlacesPageVisitedEventData.last_visited_time
FirefoxPlacesPageVisitedEventData.offset
FirefoxPlacesPageVisitedEventData.query
FirefoxPlacesPageVisitedEventData.title
FirefoxPlacesPageVisitedEventData.typed
FirefoxPlacesPageVisitedEventData.url
FirefoxPlacesPageVisitedEventData.visit_count
FirefoxPlacesPageVisitedEventData.visit_type
FirefoxPlacesPageVisitedEventData.DATA_TYPE
- plaso.parsers.sqlite_plugins.gdrive module
GoogleDrivePlugin
GoogleDrivePlugin.CLOUD_PATH_CACHE_QUERY
GoogleDrivePlugin.DATA_FORMAT
GoogleDrivePlugin.GetCloudPath()
GoogleDrivePlugin.GetLocalPath()
GoogleDrivePlugin.LOCAL_PATH_CACHE_QUERY
GoogleDrivePlugin.NAME
GoogleDrivePlugin.ParseCloudEntryRow()
GoogleDrivePlugin.ParseLocalEntryRow()
GoogleDrivePlugin.QUERIES
GoogleDrivePlugin.REQUIRED_STRUCTURE
GoogleDrivePlugin.SCHEMAS
GoogleDriveSnapshotCloudEntryEventData
GoogleDriveSnapshotCloudEntryEventData.creation_time
GoogleDriveSnapshotCloudEntryEventData.doc_type
GoogleDriveSnapshotCloudEntryEventData.modification_time
GoogleDriveSnapshotCloudEntryEventData.path
GoogleDriveSnapshotCloudEntryEventData.query
GoogleDriveSnapshotCloudEntryEventData.shared
GoogleDriveSnapshotCloudEntryEventData.size
GoogleDriveSnapshotCloudEntryEventData.url
GoogleDriveSnapshotCloudEntryEventData.DATA_TYPE
GoogleDriveSnapshotLocalEntryEventData
- plaso.parsers.sqlite_plugins.imessage module
IMessageEventData
IMessageEventData.attachment_location
IMessageEventData.client_version
IMessageEventData.creation_time
IMessageEventData.imessage_id
IMessageEventData.message_type
IMessageEventData.offset
IMessageEventData.query
IMessageEventData.read_receipt
IMessageEventData.service
IMessageEventData.text
IMessageEventData.DATA_TYPE
IMessagePlugin
- plaso.parsers.sqlite_plugins.interface module
- plaso.parsers.sqlite_plugins.ios_datausage module
- plaso.parsers.sqlite_plugins.ios_kik module
- plaso.parsers.sqlite_plugins.ios_netusage module
IOSNetusagePlugin
IOSNetusageProcessEventData
IOSNetusageProcessEventData.process_name
IOSNetusageProcessEventData.start_time
IOSNetusageProcessEventData.wifi_in
IOSNetusageProcessEventData.wifi_out
IOSNetusageProcessEventData.wired_in
IOSNetusageProcessEventData.wired_out
IOSNetusageProcessEventData.wireless_wan_in
IOSNetusageProcessEventData.wireless_wan_out
IOSNetusageProcessEventData.DATA_TYPE
IOSNetusageRouteEventData
- plaso.parsers.sqlite_plugins.ios_powerlog module
IOSPowerlogApplicationUsageEventData
IOSPowerlogApplicationUsagePlugin
IOSPowerlogApplicationUsagePlugin.DATA_FORMAT
IOSPowerlogApplicationUsagePlugin.NAME
IOSPowerlogApplicationUsagePlugin.ParseApplicationRunTime()
IOSPowerlogApplicationUsagePlugin.QUERIES
IOSPowerlogApplicationUsagePlugin.REQUIRED_STRUCTURE
IOSPowerlogApplicationUsagePlugin.REQUIRES_SCHEMA_MATCH
IOSPowerlogApplicationUsagePlugin.SCHEMAS
- plaso.parsers.sqlite_plugins.ios_screentime module
IOSScreenTimeEventData
IOSScreenTimeEventData.bundle_identifier
IOSScreenTimeEventData.device_identifier
IOSScreenTimeEventData.device_name
IOSScreenTimeEventData.domain
IOSScreenTimeEventData.start_time
IOSScreenTimeEventData.total_time
IOSScreenTimeEventData.user_family_name
IOSScreenTimeEventData.user_given_name
IOSScreenTimeEventData.DATA_TYPE
IOSScreenTimePlugin
- plaso.parsers.sqlite_plugins.ios_twitter module
IOSTwitterContactEventData
IOSTwitterContactEventData.creation_time
IOSTwitterContactEventData.description
IOSTwitterContactEventData.followers_count
IOSTwitterContactEventData.following_count
IOSTwitterContactEventData.following
IOSTwitterContactEventData.location
IOSTwitterContactEventData.modification_time
IOSTwitterContactEventData.name
IOSTwitterContactEventData.profile_url
IOSTwitterContactEventData.query
IOSTwitterContactEventData.screen_name
IOSTwitterContactEventData.url
IOSTwitterContactEventData.DATA_TYPE
IOSTwitterPlugin
IOSTwitterStatusEventData
IOSTwitterStatusEventData.creation_time
IOSTwitterStatusEventData.favorite_count
IOSTwitterStatusEventData.favorited
IOSTwitterStatusEventData.modification_time
IOSTwitterStatusEventData.name
IOSTwitterStatusEventData.query
IOSTwitterStatusEventData.retweet_count
IOSTwitterStatusEventData.text
IOSTwitterStatusEventData.user_identifier
IOSTwitterStatusEventData.DATA_TYPE
- plaso.parsers.sqlite_plugins.kodi module
- plaso.parsers.sqlite_plugins.ls_quarantine module
- plaso.parsers.sqlite_plugins.mackeeper_cache module
MacKeeperCacheEventData
MacKeeperCacheEventData.added_time
MacKeeperCacheEventData.description
MacKeeperCacheEventData.event_type
MacKeeperCacheEventData.offset
MacKeeperCacheEventData.query
MacKeeperCacheEventData.record_id
MacKeeperCacheEventData.room
MacKeeperCacheEventData.text
MacKeeperCacheEventData.url
MacKeeperCacheEventData.user_name
MacKeeperCacheEventData.user_sid
MacKeeperCacheEventData.DATA_TYPE
MacKeeperCachePlugin
- plaso.parsers.sqlite_plugins.macos_appusage module
MacOSApplicationUsageEventData
MacOSApplicationUsageEventData.application
MacOSApplicationUsageEventData.application_version
MacOSApplicationUsageEventData.bundle_identifier
MacOSApplicationUsageEventData.count
MacOSApplicationUsageEventData.event
MacOSApplicationUsageEventData.last_used_time
MacOSApplicationUsageEventData.query
MacOSApplicationUsageEventData.DATA_TYPE
MacOSApplicationUsagePlugin
- plaso.parsers.sqlite_plugins.macos_document_versions module
MacOSDocumentVersionsEventData
MacOSDocumentVersionsEventData.creation_time
MacOSDocumentVersionsEventData.last_seen_time
MacOSDocumentVersionsEventData.name
MacOSDocumentVersionsEventData.path
MacOSDocumentVersionsEventData.query
MacOSDocumentVersionsEventData.user_sid
MacOSDocumentVersionsEventData.version_path
MacOSDocumentVersionsEventData.DATA_TYPE
MacOSDocumentVersionsPlugin
- plaso.parsers.sqlite_plugins.macos_knowledgec module
MacOSKnowledgeCApplicationEventData
MacOSKnowledgeCPlugin
MacOSKnowledgeCSafariEventData
MacOSKnowledgeCSafariEventData.bundle_identifier
MacOSKnowledgeCSafariEventData.creation_time
MacOSKnowledgeCSafariEventData.duration
MacOSKnowledgeCSafariEventData.end_time
MacOSKnowledgeCSafariEventData.start_time
MacOSKnowledgeCSafariEventData.title
MacOSKnowledgeCSafariEventData.url
MacOSKnowledgeCSafariEventData.DATA_TYPE
- plaso.parsers.sqlite_plugins.macos_notes module
- plaso.parsers.sqlite_plugins.macos_notification_center module
- plaso.parsers.sqlite_plugins.macos_tcc module
- plaso.parsers.sqlite_plugins.safari module
SafariHistoryPageVisitedEventData
SafariHistoryPageVisitedEventData.host
SafariHistoryPageVisitedEventData.last_visited_time
SafariHistoryPageVisitedEventData.offset
SafariHistoryPageVisitedEventData.query
SafariHistoryPageVisitedEventData.title
SafariHistoryPageVisitedEventData.url
SafariHistoryPageVisitedEventData.visit_count
SafariHistoryPageVisitedEventData.was_http_non_get
SafariHistoryPageVisitedEventData.DATA_TYPE
SafariHistoryPluginSqlite
- plaso.parsers.sqlite_plugins.skype module
SkypeAccountEventData
SkypeAccountEventData.authentication_request_time
SkypeAccountEventData.authentication_request_sent_time
SkypeAccountEventData.country
SkypeAccountEventData.display_name
SkypeAccountEventData.email
SkypeAccountEventData.last_online_time
SkypeAccountEventData.last_used_time
SkypeAccountEventData.mood_change_time
SkypeAccountEventData.offset
SkypeAccountEventData.profile_change_time
SkypeAccountEventData.query
SkypeAccountEventData.username
SkypeAccountEventData.DATA_TYPE
SkypeCallEventData
SkypeCallEventData.attempt_time
SkypeCallEventData.call_type
SkypeCallEventData.dst_call
SkypeCallEventData.duration
SkypeCallEventData.end_time
SkypeCallEventData.offset
SkypeCallEventData.query
SkypeCallEventData.src_call
SkypeCallEventData.start_time
SkypeCallEventData.user_start_call
SkypeCallEventData.video_conference
SkypeCallEventData.DATA_TYPE
SkypeChatEventData
SkypePlugin
SkypePlugin.DATA_FORMAT
SkypePlugin.NAME
SkypePlugin.ParseAccountInformation()
SkypePlugin.ParseCall()
SkypePlugin.ParseChat()
SkypePlugin.ParseFileTransfer()
SkypePlugin.ParseSMS()
SkypePlugin.QUERIES
SkypePlugin.QUERY_DEST_FROM_TRANSFER
SkypePlugin.QUERY_SOURCE_FROM_TRANSFER
SkypePlugin.REQUIRED_STRUCTURE
SkypePlugin.SCHEMAS
SkypeSMSEventData
SkypeTransferFileEventData
SkypeTransferFileEventData.accept_time
SkypeTransferFileEventData.destination
SkypeTransferFileEventData.end_time
SkypeTransferFileEventData.offset
SkypeTransferFileEventData.query
SkypeTransferFileEventData.source
SkypeTransferFileEventData.start_time
SkypeTransferFileEventData.transfer_status
SkypeTransferFileEventData.transferred_filename
SkypeTransferFileEventData.transferred_filepath
SkypeTransferFileEventData.transferred_filesize
SkypeTransferFileEventData.DATA_TYPE
- plaso.parsers.sqlite_plugins.windows_eventtranscript module
EventTranscriptPlugin
WindowsEventTranscriptEventData
WindowsEventTranscriptEventData.application_name
WindowsEventTranscriptEventData.application_root_directory
WindowsEventTranscriptEventData.application_version
WindowsEventTranscriptEventData.compressed_payload_size
WindowsEventTranscriptEventData.event_keywords
WindowsEventTranscriptEventData.event_name_hash
WindowsEventTranscriptEventData.event_name
WindowsEventTranscriptEventData.friendly_logging_binary_name
WindowsEventTranscriptEventData.ikey
WindowsEventTranscriptEventData.is_core
WindowsEventTranscriptEventData.logging_binary_name
WindowsEventTranscriptEventData.name
WindowsEventTranscriptEventData.producer_identifier
WindowsEventTranscriptEventData.provider_group_identifier
WindowsEventTranscriptEventData.recorded_time
WindowsEventTranscriptEventData.user_identifier
WindowsEventTranscriptEventData.version
WindowsEventTranscriptEventData.DATA_TYPE
- plaso.parsers.sqlite_plugins.windows_timeline module
- plaso.parsers.sqlite_plugins.zeitgeist module
- Module contents
- plaso.parsers.text_plugins package
- Submodules
- plaso.parsers.text_plugins.android_logcat module
AndroidLogcatEventData
AndroidLogcatEventData.component_tag
AndroidLogcatEventData.file_offset
AndroidLogcatEventData.message
AndroidLogcatEventData.pid
AndroidLogcatEventData.priority
AndroidLogcatEventData.recorded_time
AndroidLogcatEventData.thread_identifier
AndroidLogcatEventData.user_identifier
AndroidLogcatEventData.DATA_TYPE
AndroidLogcatTextPlugin
- plaso.parsers.text_plugins.apache_access module
ApacheAccessLogEventData
ApacheAccessLogEventData.http_request_referer
ApacheAccessLogEventData.http_request
ApacheAccessLogEventData.http_request_user_agent
ApacheAccessLogEventData.http_response_bytes
ApacheAccessLogEventData.http_response_code
ApacheAccessLogEventData.ip_address
ApacheAccessLogEventData.port_number
ApacheAccessLogEventData.recorded_time
ApacheAccessLogEventData.remote_name
ApacheAccessLogEventData.server_name
ApacheAccessLogEventData.user_name
ApacheAccessLogEventData.DATA_TYPE
ApacheAccessLogTextPlugin
- plaso.parsers.text_plugins.apt_history module
- plaso.parsers.text_plugins.aws_elb_access module
AWSELBEventData
AWSELBEventData.actions_executed
AWSELBEventData.alpn_back_end_protocol
AWSELBEventData.alpn_client_preference_list
AWSELBEventData.alpn_front_end_protocol
AWSELBEventData.chosen_cert_arn
AWSELBEventData.chosen_cert_serial
AWSELBEventData.classification
AWSELBEventData.classification_reason
AWSELBEventData.connection_duration
AWSELBEventData.destination_group_arn
AWSELBEventData.destination_ip_address
AWSELBEventData.destination_list
AWSELBEventData.destination_port
AWSELBEventData.destination_processing_duration
AWSELBEventData.destination_status_code
AWSELBEventData.destination_status_code_list
AWSELBEventData.domain_name
AWSELBEventData.error_reason
AWSELBEventData.handshake_duration
AWSELBEventData.incoming_tls_alert
AWSELBEventData.listener
AWSELBEventData.matched_rule_priority
AWSELBEventData.received_bytes
AWSELBEventData.redirect_url
AWSELBEventData.request_processing_duration
AWSELBEventData.request_time
AWSELBEventData.request_type
AWSELBEventData.resource_identifier
AWSELBEventData.response_processing_duration
AWSELBEventData.response_time
AWSELBEventData.sent_bytes
AWSELBEventData.ssl_cipher
AWSELBEventData.ssl_protocol
AWSELBEventData.source_ip_address
AWSELBEventData.source_port
AWSELBEventData.tls_cipher
AWSELBEventData.tls_named_group
AWSELBEventData.tls_protocol_version
AWSELBEventData.trace_identifier
AWSELBEventData.user_agent
AWSELBEventData.version
AWSELBEventData.DATA_TYPE
AWSELBTextPlugin
- plaso.parsers.text_plugins.bash_history module
- plaso.parsers.text_plugins.confluence_access module
ConfluenceAccessEventData
ConfluenceAccessEventData.forwarded_for
ConfluenceAccessEventData.http_request_method
ConfluenceAccessEventData.http_request_referer
ConfluenceAccessEventData.http_request_uri
ConfluenceAccessEventData.http_request_user_agent
ConfluenceAccessEventData.http_response_bytes
ConfluenceAccessEventData.http_response_code
ConfluenceAccessEventData.http_version
ConfluenceAccessEventData.process_duration
ConfluenceAccessEventData.recorded_time
ConfluenceAccessEventData.remote_name
ConfluenceAccessEventData.thread_name
ConfluenceAccessEventData.user_name
ConfluenceAccessEventData.DATA_TYPE
ConfluenceAccessTextPlugin
- plaso.parsers.text_plugins.dpkg module
- plaso.parsers.text_plugins.gdrive_synclog module
- plaso.parsers.text_plugins.google_logging module
- plaso.parsers.text_plugins.iis module
IISEventData
IISEventData.cs_cookie
IISEventData.cs_host
IISEventData.cs_referrer
IISEventData.cs_uri_query
IISEventData.cs_username
IISEventData.dest_ip
IISEventData.dest_port
IISEventData.http_method
IISEventData.http_status
IISEventData.last_written_time
IISEventData.protocol_version
IISEventData.received_bytes
IISEventData.requested_uri_stem
IISEventData.s_computername
IISEventData.sc_substatus
IISEventData.sc_win32_status
IISEventData.sent_bytes
IISEventData.source_ip
IISEventData.s_sitename
IISEventData.time_taken
IISEventData.user_agent
IISEventData.DATA_TYPE
WinIISTextPlugin
- plaso.parsers.text_plugins.interface module
- plaso.parsers.text_plugins.ios_lockdownd module
- plaso.parsers.text_plugins.ios_logd module
- plaso.parsers.text_plugins.ios_sysdiag_log module
- plaso.parsers.text_plugins.macos_appfirewall module
- plaso.parsers.text_plugins.macos_securityd module
MacOSSecuritydLogEventData
MacOSSecuritydLogEventData.added_time
MacOSSecuritydLogEventData.caller
MacOSSecuritydLogEventData.facility
MacOSSecuritydLogEventData.level
MacOSSecuritydLogEventData.message
MacOSSecuritydLogEventData.security_api
MacOSSecuritydLogEventData.sender
MacOSSecuritydLogEventData.sender_pid
MacOSSecuritydLogEventData.DATA_TYPE
MacOSSecuritydLogTextPlugin
- plaso.parsers.text_plugins.macos_wifi module
- plaso.parsers.text_plugins.popcontest module
- plaso.parsers.text_plugins.postgresql module
- plaso.parsers.text_plugins.powershell_transcript module
PowerShellTranscriptLogEventData
PowerShellTranscriptLogEventData.build_version
PowerShellTranscriptLogEventData.clr_version
PowerShellTranscriptLogEventData.commands
PowerShellTranscriptLogEventData.compatible_versions
PowerShellTranscriptLogEventData.configuration_name
PowerShellTranscriptLogEventData.edition
PowerShellTranscriptLogEventData.host_application
PowerShellTranscriptLogEventData.machine
PowerShellTranscriptLogEventData.process_identifier
PowerShellTranscriptLogEventData.remoting_protocol_version
PowerShellTranscriptLogEventData.runas_user
PowerShellTranscriptLogEventData.serialization_version
PowerShellTranscriptLogEventData.start_time
PowerShellTranscriptLogEventData.username
PowerShellTranscriptLogEventData.version
PowerShellTranscriptLogEventData.ws_man_stack_version
PowerShellTranscriptLogEventData.DATA_TYPE
PowerShellTranscriptLogTextPlugin
- plaso.parsers.text_plugins.santa module
SantaExecutionEventData
SantaExecutionEventData.action
SantaExecutionEventData.certificate_common_name
SantaExecutionEventData.certificate_hash
SantaExecutionEventData.decision
SantaExecutionEventData.gid
SantaExecutionEventData.group
SantaExecutionEventData.last_run_time
SantaExecutionEventData.long_reason
SantaExecutionEventData.mode
SantaExecutionEventData.pid
SantaExecutionEventData.pid_version
SantaExecutionEventData.ppid
SantaExecutionEventData.process_arguments
SantaExecutionEventData.process_hash
SantaExecutionEventData.process_path
SantaExecutionEventData.reason
SantaExecutionEventData.uid
SantaExecutionEventData.user
SantaExecutionEventData.DATA_TYPE
SantaFileSystemEventData
SantaFileSystemEventData.action
SantaFileSystemEventData.file_new_path
SantaFileSystemEventData.file_path
SantaFileSystemEventData.gid
SantaFileSystemEventData.group
SantaFileSystemEventData.last_written_time
SantaFileSystemEventData.pid
SantaFileSystemEventData.pid_version
SantaFileSystemEventData.ppid
SantaFileSystemEventData.process_path
SantaFileSystemEventData.process
SantaFileSystemEventData.uid
SantaFileSystemEventData.user
SantaFileSystemEventData.DATA_TYPE
SantaMountEventData
SantaMountEventData.action
SantaMountEventData.appearance_time
SantaMountEventData.bsd_name
SantaMountEventData.bus
SantaMountEventData.dmg_path
SantaMountEventData.fs
SantaMountEventData.last_written_time
SantaMountEventData.model
SantaMountEventData.mount
SantaMountEventData.serial
SantaMountEventData.volume
SantaMountEventData.DATA_TYPE
SantaProcessExitEventData
SantaTextPlugin
- plaso.parsers.text_plugins.sccm module
- plaso.parsers.text_plugins.selinux module
- plaso.parsers.text_plugins.setupapi module
- plaso.parsers.text_plugins.skydrivelog module
- plaso.parsers.text_plugins.snort_fastlog module
SnortFastAlertEventData
SnortFastAlertEventData.classification
SnortFastAlertEventData.destination_ip
SnortFastAlertEventData.destination_port
SnortFastAlertEventData.last_written_time
SnortFastAlertEventData.message
SnortFastAlertEventData.priority
SnortFastAlertEventData.rule_identifier
SnortFastAlertEventData.source_ip
SnortFastAlertEventData.source_port
SnortFastAlertEventData.DATA_TYPE
SnortFastLogTextPlugin
- plaso.parsers.text_plugins.sophos_av module
- plaso.parsers.text_plugins.syslog module
- plaso.parsers.text_plugins.viminfo module
- plaso.parsers.text_plugins.vsftpd module
- plaso.parsers.text_plugins.winfirewall module
WinFirewallEventData
WinFirewallEventData.action
WinFirewallEventData.destination_ip
WinFirewallEventData.destination_port
WinFirewallEventData.icmp_code
WinFirewallEventData.icmp_type
WinFirewallEventData.information
WinFirewallEventData.last_written_time
WinFirewallEventData.packet_size
WinFirewallEventData.path
WinFirewallEventData.protocol
WinFirewallEventData.source_ip
WinFirewallEventData.source_port
WinFirewallEventData.tcp_ack
WinFirewallEventData.tcp_flags
WinFirewallEventData.tcp_sequence_number
WinFirewallEventData.tcp_window_size
WinFirewallEventData.DATA_TYPE
WinFirewallLogTextPlugin
- plaso.parsers.text_plugins.xchatlog module
- plaso.parsers.text_plugins.xchatscrollback module
- plaso.parsers.text_plugins.zsh_extended_history module
- Module contents
- plaso.parsers.winreg_plugins package
- Submodules
- plaso.parsers.winreg_plugins.amcache module
AMCacheFileEventData
AMCacheFileEventData.company_name
AMCacheFileEventData.file_creation_time
AMCacheFileEventData.file_description
AMCacheFileEventData.file_modification_time
AMCacheFileEventData.file_reference
AMCacheFileEventData.file_size
AMCacheFileEventData.file_version
AMCacheFileEventData.full_path
AMCacheFileEventData.installation_time
AMCacheFileEventData.language_code
AMCacheFileEventData.last_written_time
AMCacheFileEventData.link_time
AMCacheFileEventData.msi_installation_time
AMCacheFileEventData.product_name
AMCacheFileEventData.program_identifier
AMCacheFileEventData.sha1
AMCacheFileEventData.DATA_TYPE
AMCachePlugin
AMCacheProgramEventData
AMCacheProgramEventData.entry_type
AMCacheProgramEventData.file_paths
AMCacheProgramEventData.files
AMCacheProgramEventData.installation_time
AMCacheProgramEventData.language_code
AMCacheProgramEventData.msi_package_code
AMCacheProgramEventData.msi_product_code
AMCacheProgramEventData.name
AMCacheProgramEventData.package_code
AMCacheProgramEventData.product_code
AMCacheProgramEventData.publisher
AMCacheProgramEventData.uninstall_key
AMCacheProgramEventData.version
AMCacheProgramEventData.DATA_TYPE
- plaso.parsers.winreg_plugins.appcompatcache module
- plaso.parsers.winreg_plugins.bagmru module
- plaso.parsers.winreg_plugins.bam module
- plaso.parsers.winreg_plugins.ccleaner module
- plaso.parsers.winreg_plugins.default module
- plaso.parsers.winreg_plugins.interface module
- plaso.parsers.winreg_plugins.lfu module
- plaso.parsers.winreg_plugins.mountpoints module
- plaso.parsers.winreg_plugins.mrulist module
- plaso.parsers.winreg_plugins.mrulistex module
- plaso.parsers.winreg_plugins.msie_zones module
- plaso.parsers.winreg_plugins.network_drives module
- plaso.parsers.winreg_plugins.networks module
NetworksWindowsRegistryPlugin
WindowsRegistryNetworkListEventData
WindowsRegistryNetworkListEventData.connection_type
WindowsRegistryNetworkListEventData.creation_time
WindowsRegistryNetworkListEventData.default_gateway_mac
WindowsRegistryNetworkListEventData.description
WindowsRegistryNetworkListEventData.dns_suffix
WindowsRegistryNetworkListEventData.last_connected_time
WindowsRegistryNetworkListEventData.ssid
WindowsRegistryNetworkListEventData.DATA_TYPE
- plaso.parsers.winreg_plugins.officemru module
- plaso.parsers.winreg_plugins.outlook module
- plaso.parsers.winreg_plugins.programscache module
- plaso.parsers.winreg_plugins.run module
- plaso.parsers.winreg_plugins.sam_users module
SAMUsersWindowsRegistryEventData
SAMUsersWindowsRegistryEventData.account_rid
SAMUsersWindowsRegistryEventData.comments
SAMUsersWindowsRegistryEventData.fullname
SAMUsersWindowsRegistryEventData.key_path
SAMUsersWindowsRegistryEventData.last_login_time
SAMUsersWindowsRegistryEventData.last_password_set_time
SAMUsersWindowsRegistryEventData.last_written_time
SAMUsersWindowsRegistryEventData.login_count
SAMUsersWindowsRegistryEventData.username
SAMUsersWindowsRegistryEventData.DATA_TYPE
SAMUsersWindowsRegistryPlugin
- plaso.parsers.winreg_plugins.services module
ServicesPlugin
WindowsRegistryServiceEventData
WindowsRegistryServiceEventData.error_control
WindowsRegistryServiceEventData.image_path
WindowsRegistryServiceEventData.key_path
WindowsRegistryServiceEventData.last_written_time
WindowsRegistryServiceEventData.name
WindowsRegistryServiceEventData.object_name
WindowsRegistryServiceEventData.service_dll
WindowsRegistryServiceEventData.service_type
WindowsRegistryServiceEventData.start_type
WindowsRegistryServiceEventData.values
WindowsRegistryServiceEventData.values
WindowsRegistryServiceEventData.DATA_TYPE
- plaso.parsers.winreg_plugins.shutdown module
- plaso.parsers.winreg_plugins.task_scheduler module
- plaso.parsers.winreg_plugins.terminal_server module
- plaso.parsers.winreg_plugins.timezone module
- plaso.parsers.winreg_plugins.typedurls module
- plaso.parsers.winreg_plugins.usb module
- plaso.parsers.winreg_plugins.usbstor module
USBStorDeviceInstanceEventData
USBStorDeviceInstanceEventData.device_last_arrival_time
USBStorDeviceInstanceEventData.device_last_removal_time
USBStorDeviceInstanceEventData.device_type
USBStorDeviceInstanceEventData.display_name
USBStorDeviceInstanceEventData.key_path
USBStorDeviceInstanceEventData.driver_first_installation_time
USBStorDeviceInstanceEventData.driver_last_installation_time
USBStorDeviceInstanceEventData.firmware_time
USBStorDeviceInstanceEventData.product
USBStorDeviceInstanceEventData.revision
USBStorDeviceInstanceEventData.vendor
USBStorDeviceInstanceEventData.DATA_TYPE
USBStorPlugin
- plaso.parsers.winreg_plugins.userassist module
UserAssistPlugin
UserAssistWindowsRegistryEventData
UserAssistWindowsRegistryEventData.application_focus_count
UserAssistWindowsRegistryEventData.application_focus_duration
UserAssistWindowsRegistryEventData.entry_index
UserAssistWindowsRegistryEventData.key_path
UserAssistWindowsRegistryEventData.last_execution_time
UserAssistWindowsRegistryEventData.number_of_executions
UserAssistWindowsRegistryEventData.value_name
UserAssistWindowsRegistryEventData.DATA_TYPE
UserAssistWindowsRegistryKeyPathFilter
- plaso.parsers.winreg_plugins.windows_version module
WindowsRegistryInstallationEventData
WindowsRegistryInstallationEventData.build_number
WindowsRegistryInstallationEventData.installation_time
WindowsRegistryInstallationEventData.key_path
WindowsRegistryInstallationEventData.owner
WindowsRegistryInstallationEventData.product_name
WindowsRegistryInstallationEventData.service_pack
WindowsRegistryInstallationEventData.version
WindowsRegistryInstallationEventData.DATA_TYPE
WindowsVersionPlugin
- plaso.parsers.winreg_plugins.winlogon module
- plaso.parsers.winreg_plugins.winrar module
- Module contents
Submodules
plaso.parsers.android_app_usage module
Parser for the Android usage history (usage-history.xml) files.
- class plaso.parsers.android_app_usage.AndroidAppUsageEventData(*args: Any, **kwargs: Any)[source]
Bases:
EventData
Android application usage event data.
- component
name of the individual component of the application.
- Type
str
- last_resume_time
date and time the application was last resumed.
- Type
dfdatetime.DateTimeValues
- package
name of the Android application.
- Type
str
- DATA_TYPE = 'android:app_usage'
- class plaso.parsers.android_app_usage.AndroidAppUsageParser[source]
Bases:
FileObjectParser
Parses the Android usage history (usage-history.xml) file.
- DATA_FORMAT = 'Android usage history (usage-history.xml) file'
- NAME = 'android_app_usage'
- ParseFileObject(parser_mediator, file_object)[source]
Parses an Android usage-history file-like object.
- Parameters
parser_mediator (ParserMediator) – mediates interactions between parsers and other components, such as storage and dfvfs.
file_object (dfvfs.FileIO) – file-like object.
- Raises
WrongParser – when the file cannot be parsed.
plaso.parsers.asl module
The Apple System Log (ASL) file parser.
- class plaso.parsers.asl.ASLEventData(*args: Any, **kwargs: Any)[source]
Bases:
EventData
Apple System Log (ASL) event data.
- computer_name
name of the host.
- Type
str
- extra_information
extra fields associated to the event.
- Type
str
- facility
facility.
- Type
str
- group_identifier
group identifier (GID).
- Type
int
- level
level of criticality of the event.
- Type
str
- message
message of the event.
- Type
str
- message_identifier
message identifier.
- Type
int
- process_identifier
process identifier (PID).
- Type
int
- read_group_identifier
the group identifier that can read this file, where -1 represents all.
- Type
int
- read_user_identifier
user identifier that can read this file, where -1 represents all.
- Type
int
- record_position
position of the event record.
- Type
int
- sender
sender or process that created the event.
- Type
str
- user_identifier
user identifier (UID).
- Type
int
- written_time
entry written date and time.
- Type
dfdatetime.DateTimeValues
- DATA_TYPE = 'macos:asl:entry'
- class plaso.parsers.asl.ASLFileEventData(*args: Any, **kwargs: Any)[source]
Bases:
EventData
Apple System Log (ASL) file event data.
- creation_time
creation date and time.
- Type
dfdatetime.DateTimeValues
- format_version
ASL file format version.
- Type
int
- is_dirty
True if the last log entry offset does not match value in file header and the file is considered dirty.
- Type
bool
- DATA_TYPE = 'macos:asl:file'
- class plaso.parsers.asl.ASLParser[source]
Bases:
FileObjectParser
,DtFabricHelper
Parser for Apple System Log (ASL) files.
- DATA_FORMAT = 'Apple System Log (ASL) file'
- classmethod GetFormatSpecification()[source]
Retrieves the format specification.
- Returns
format specification.
- Return type
- NAME = 'asl_log'
- ParseFileObject(parser_mediator, file_object)[source]
Parses an ASL file-like object.
- Parameters
parser_mediator (ParserMediator) – mediates interactions between parsers and other components, such as storage and dfVFS.
file_object (dfvfs.FileIO) – file-like object.
- Raises
WrongParser – when the file cannot be parsed.
plaso.parsers.bencode_parser module
Parser for bencoded files.
- class plaso.parsers.bencode_parser.BencodeFile[source]
Bases:
object
Bencode file.
- GetValues()[source]
Retrieves the values in the root of the bencode file.
- Returns
values.
- Return type
- IsEmpty()[source]
Determines if the bencode file has no values (is empty).
- Returns
True if the bencode file is empty, False otherwise.
- Return type
bool
- Open(file_object)[source]
Opens a bencode file.
- Parameters
file_object (dfvfs.FileIO) – file-like object.
- Raises
IOError – if the file-like object cannot be read.
OSError – if the file-like object cannot be read.
ValueError – if the file-like object is missing.
- property keys
names of all the keys.
- Type
set[str]
- class plaso.parsers.bencode_parser.BencodeParser[source]
Bases:
FileObjectParser
Parser for bencoded files.
- DATA_FORMAT = 'Bencoded file'
- NAME = 'bencode'
- ParseFileObject(parser_mediator, file_object)[source]
Parses a bencoded file-like object.
- Parameters
parser_mediator (ParserMediator) – mediates interactions between parsers and other components, such as storage and dfvfs.
file_object (dfvfs.FileIO) – a file-like object.
- Raises
WrongParser – when the file cannot be parsed.
- class plaso.parsers.bencode_parser.BencodeValues(decoded_values)[source]
Bases:
object
Bencode values.
- GetDateTimeValue(name)[source]
Retrieves a date and time value.
- Parameters
name (str) – name of the value.
- Returns
date and time or None if not available.
- Return type
dfdatetime.PosixTime
plaso.parsers.bodyfile module
Parser for the Sleuthkit (TSK) bodyfile format.
Sleuthkit version 3 format: MD5|name|inode|mode_as_string|UID|GID|size|atime|mtime|ctime|crtime 0|/lost+found|11|d/drwx——|0|0|12288|1337961350|1337961350|1337961350|0
- More information about the format specifications can be read here:
- class plaso.parsers.bodyfile.BodyfileEventData(*args: Any, **kwargs: Any)[source]
Bases:
EventData
Bodyfile event data.
- access_time
file entry last access date and time.
- Type
dfdatetime.DateTimeValues
- change_time
file entry inode change (or metadata last modification) date and time.
- Type
dfdatetime.DateTimeValues
- creation_time
file entry creation date and time.
- Type
dfdatetime.DateTimeValues
- filename
name of the file.
- Type
str
- group_identifier
group identifier (GID), equivalent to st_gid.
- Type
int
- inode
“inode” of the file. Note that inode is an overloaded term in the context of a bodyfile and used for MFT entry index values as well.
- Type
int
- md5
MD5 hash of the file content, formatted as a hexadecimal string.
- Type
str
- mode_as_string
protection mode.
- Type
str
- modification_time
file entry last modification date and time.
- Type
dfdatetime.DateTimeValues
- offset
number of the corresponding line, from which the event data was extracted.
- Type
int
- owner_identifier
user identifier (UID or SID) of the owner.
- Type
str
- size
size of the file content.
- Type
int
- symbolic_link_target
path of the symbolic link target.
- Type
str
- DATA_TYPE = 'fs:bodyfile:entry'
- class plaso.parsers.bodyfile.BodyfileParser[source]
Bases:
FileObjectParser
SleuthKit bodyfile parser.
- DATA_FORMAT = 'SleuthKit version 3 bodyfile'
- NAME = 'bodyfile'
- ParseFileObject(parser_mediator, file_object)[source]
Parses a bodyfile file-like object.
- Parameters
parser_mediator (ParserMediator) – mediates interactions between parsers and other components, such as storage and dfVFS.
file_object (dfvfs.FileIO) – file-like object.
- Raises
WrongParser – when the file cannot be parsed.
plaso.parsers.bsm module
Basic Security Module (BSM) event auditing file parser.
- class plaso.parsers.bsm.BSMEventData(*args: Any, **kwargs: Any)[source]
Bases:
EventData
Basic Security Module (BSM) audit event data.
- event_type
identifier that represents the type of the event.
- Type
int
- extra_tokens
event extra tokens, which is a list of dictionaries that contain: {token type: {token values}}
- Type
list[dict[str, dict[str, str]]]
- offset
offset of the BSM record relative to the start of the file, from which the event data was extracted.
- Type
int
- record_length
record length in bytes (trailer number).
- Type
int
- return_value
processed return value and exit status.
- Type
str
- written_time
entry written date and time.
- Type
dfdatetime.DateTimeValues
- DATA_TYPE = 'bsm:entry'
- class plaso.parsers.bsm.BSMParser[source]
Bases:
FileObjectParser
,DtFabricHelper
Parser for Basic Security Module (BSM) event auditing files.
- DATA_FORMAT = 'Basic Security Module (BSM) event auditing file'
- NAME = 'bsm_log'
- ParseFileObject(parser_mediator, file_object)[source]
Parses a BSM file-like object.
- Parameters
parser_mediator (ParserMediator) – mediates interactions between parsers and other components, such as storage and dfvfs.
file_object (dfvfs.FileIO) – a file-like object.
- Raises
WrongParser – when the file cannot be parsed.
plaso.parsers.chrome_cache module
Parser for Google Chrome and Chromium Cache files.
- class plaso.parsers.chrome_cache.CacheAddress(cache_address)[source]
Bases:
object
Chrome cache address.
- block_number
block data file number.
- Type
int
- block_offset
offset within the block data file.
- Type
int
- block_size
block size.
- Type
int
- filename
name of the block data file.
- Type
str
- value
cache address.
- Type
int
- FILE_TYPE_BLOCK_1024 = 3
- FILE_TYPE_BLOCK_256 = 2
- FILE_TYPE_BLOCK_4096 = 4
- FILE_TYPE_BLOCK_RANKINGS = 1
- FILE_TYPE_SEPARATE = 0
- class plaso.parsers.chrome_cache.CacheEntry[source]
Bases:
object
Chrome cache entry.
- creation_time
creation time, in number of microseconds since January 1, 1601, 00:00:00 UTC.
- Type
int
- hash
super fast hash of the key.
- Type
int
- key
key.
- Type
bytes
- next
cache address of the next cache entry.
- Type
int
- original_url
original URL derived from the key.
- Type
str
- rankings_node
cache address of the rankings node.
- Type
int
- class plaso.parsers.chrome_cache.ChromeCacheDataBlockFileParser[source]
Bases:
FileObjectParser
,DtFabricHelper
Chrome cache data block file parser.
- ParseCacheEntry(file_object, block_offset)[source]
Parses a cache entry.
- Parameters
file_object (dfvfs.FileIO) – a file-like object to read from.
block_offset (int) – block offset of the cache entry.
- Returns
cache entry.
- Return type
- Raises
ParseError – if the cache entry cannot be read.
- ParseFileObject(parser_mediator, file_object)[source]
Parses a file-like object.
- Parameters
parser_mediator (ParserMediator) – a parser mediator.
file_object (dfvfs.FileIO) – a file-like object to parse.
- Raises
ParseError – when the file cannot be parsed.
- class plaso.parsers.chrome_cache.ChromeCacheEntryEventData(*args: Any, **kwargs: Any)[source]
Bases:
EventData
Chrome Cache event data.
- creation_time
creation date and time of the cache entry.
- Type
dfdatetime.DateTimeValues
- original_url
original URL.
- Type
str
- DATA_TYPE = 'chrome:cache:entry'
- class plaso.parsers.chrome_cache.ChromeCacheIndexFileParser[source]
Bases:
FileObjectParser
,DtFabricHelper
Chrome cache index file parser.
- creation_time
creation time, in number of microseconds since January 1, 1601, 00:00:00 UTC.
- Type
int
- index_table
the cache addresses which are stored in the index file.
- Type
list[CacheAddress]
- ParseFileObject(parser_mediator, file_object)[source]
Parses a file-like object.
- Parameters
parser_mediator (ParserMediator) – a parser mediator.
file_object (dfvfs.FileIO) – a file-like object to parse.
- Raises
ParseError – when the file cannot be parsed.
- class plaso.parsers.chrome_cache.ChromeCacheParser[source]
Bases:
FileEntryParser
Parses Chrome Cache files.
- DATA_FORMAT = 'Google Chrome or Chromium Cache file'
- classmethod GetFormatSpecification()[source]
Retrieves the format specification.
- Returns
format specification.
- Return type
- NAME = 'chrome_cache'
- ParseFileEntry(parser_mediator, file_entry)[source]
Parses Chrome Cache files.
- Parameters
parser_mediator (ParserMediator) – mediates interactions between parsers and other components, such as storage and dfVFS.
file_entry (dfvfs.FileEntry) – file entry.
- Raises
WrongParser – when the file cannot be parsed.
plaso.parsers.chrome_preferences module
A parser for the Chrome preferences file.
- class plaso.parsers.chrome_preferences.ChromeContentSettingsExceptionsEventData(*args: Any, **kwargs: Any)[source]
Bases:
EventData
Chrome content settings exceptions event data.
- last_visited_time
date and time the URL was last visited.
- Type
dfdatetime.DateTimeValues
- permission
permission.
- Type
str
- primary_url
primary URL.
- Type
str
- secondary_url
secondary URL.
- Type
str
- DATA_TYPE = 'chrome:preferences:content_settings:exceptions'
- class plaso.parsers.chrome_preferences.ChromeExtensionInstallationEventData(*args: Any, **kwargs: Any)[source]
Bases:
EventData
Chrome extension event data.
- extension_identifier
extension identifier.
- Type
str
- extension_name
extension name.
- Type
str
- installation_time
date and time the Chrome extension was installed.
- Type
dfdatetime.DateTimeValues
- path
path.
- Type
str
- DATA_TYPE = 'chrome:preferences:extension_installation'
- class plaso.parsers.chrome_preferences.ChromeExtensionsAutoupdaterEventData(*args: Any, **kwargs: Any)[source]
Bases:
EventData
Chrome Extension Autoupdater event data.
- message
message.
- Type
str
- recorded_time
date and time the entry was recorded.
- Type
dfdatetime.DateTimeValues
- DATA_TYPE = 'chrome:preferences:extensions_autoupdater'
- class plaso.parsers.chrome_preferences.ChromePreferencesParser[source]
Bases:
FileObjectParser
Parses Chrome Preferences files.
- DATA_FORMAT = 'Google Chrome Preferences file'
- NAME = 'chrome_preferences'
- ParseFileObject(parser_mediator, file_object)[source]
Parses a Chrome preferences file-like object.
- Parameters
parser_mediator (ParserMediator) – mediates interactions between parsers and other components, such as storage and dfvfs.
file_object (dfvfs.FileIO) – file-like object.
- Raises
WrongParser – when the file cannot be parsed.
- REQUIRED_KEYS = frozenset({'browser', 'extensions'})
plaso.parsers.cups_ipp module
The CUPS IPP files parser.
CUPS IPP version 1.0: * https://datatracker.ietf.org/doc/html/rfc2565 * https://datatracker.ietf.org/doc/html/rfc2566 * https://datatracker.ietf.org/doc/html/rfc2567 * https://datatracker.ietf.org/doc/html/rfc2568 * https://datatracker.ietf.org/doc/html/rfc2569 * https://datatracker.ietf.org/doc/html/rfc2639
CUPS IPP version 1.1: * https://datatracker.ietf.org/doc/html/rfc2910 * https://datatracker.ietf.org/doc/html/rfc2911 * https://datatracker.ietf.org/doc/html/rfc3196 * https://datatracker.ietf.org/doc/html/rfc3510
CUPS IPP version 2.0: * N/A
- class plaso.parsers.cups_ipp.CupsIppEventData(*args: Any, **kwargs: Any)[source]
Bases:
EventData
CUPS IPP event data.
- application
application that prints the document.
- Type
str
- computer_name
name of the computer.
- Type
str
- copies
number of copies.
- Type
int
- creation_time
date and time the print job was created (added).
- Type
dfdatetime.DateTimeValues
- doc_type
type of document.
- Type
str
- end_time
date and time the print job was stopped.
- Type
dfdatetime.DateTimeValues
- job_id
job identifier.
- Type
str
- job_name
job name.
- Type
str
- owner
real name of the user.
- Type
str
- printer_id
identification name of the print.
- Type
str
- start_time
date and time the print job was started.
- Type
dfdatetime.DateTimeValues
- uri
URL of the CUPS service.
- Type
str
- user
system user name.
- Type
str
- DATA_TYPE = 'cups:ipp:event'
- class plaso.parsers.cups_ipp.CupsIppParser[source]
Bases:
FileObjectParser
,DtFabricHelper
Parser for CUPS IPP files.
- DATA_FORMAT = 'CUPS IPP file'
- NAME = 'cups_ipp'
- ParseFileObject(parser_mediator, file_object)[source]
Parses a CUPS IPP file-like object.
- Parameters
parser_mediator (ParserMediator) – mediates interactions between parsers and other components, such as storage and dfvfs.
file_object (dfvfs.FileIO) – file-like object.
- Raises
WrongParser – when the file cannot be parsed.
plaso.parsers.custom_destinations module
Parser for custom destinations jump list (.customDestinations-ms) files.
- class plaso.parsers.custom_destinations.CustomDestinationsParser[source]
Bases:
FileObjectParser
,DtFabricHelper
Parses custom destinations jump list (.customDestinations-ms) files.
- DATA_FORMAT = 'Custom destinations jump list (.customDestinations-ms) file'
- classmethod GetFormatSpecification()[source]
Retrieves the format specification.
- Returns
format specification.
- Return type
- NAME = 'custom_destinations'
- ParseFileObject(parser_mediator, file_object)[source]
Parses a .customDestinations-ms file-like object.
- Parameters
parser_mediator (ParserMediator) – mediates interactions between parsers and other components, such as storage and dfvfs.
file_object (dfvfs.FileIO) – a file-like object.
- Raises
WrongParser – when the file cannot be parsed.
plaso.parsers.czip module
This file contains a parser for compound ZIP files.
- class plaso.parsers.czip.CompoundZIPParser[source]
Bases:
FileObjectParser
Shared functionality for parsing compound ZIP files.
Compound ZIP files are ZIP files used as containers to create another file format, as opposed to archives of unrelated files.
- DATA_FORMAT = 'Compound ZIP file'
- NAME = 'czip'
- ParseFileObject(parser_mediator, file_object)[source]
Parses a compound ZIP file-like object.
- Parameters
parser_mediator (ParserMediator) – mediates interactions between parsers and other components, such as storage and dfvfs.
file_object (dfvfs.FileIO) – a file-like object.
- Raises
WrongParser – when the file cannot be parsed.
plaso.parsers.dsv_parser module
Delimiter separated values (DSV) parser interface.
- class plaso.parsers.dsv_parser.DSVParser[source]
Bases:
FileObjectParser
Delimiter separated values (DSV) parser interface.
- COLUMNS = []
- DELIMITER = ','
- ESCAPE_CHARACTER = ''
- FIELD_SIZE_LIMIT = 131072
- classmethod GetFormatSpecification()[source]
Retrieves the format specification.
- Returns
format specification.
- Return type
- NUMBER_OF_HEADER_LINES = 0
- ParseFileObject(parser_mediator, file_object)[source]
Parses a DSV text file-like object.
- Parameters
parser_mediator (ParserMediator) – mediates interactions between parsers and other components, such as storage and dfvfs.
file_object (dfvfs.FileIO) – file-like object.
- Raises
WrongParser – when the file cannot be parsed.
- abstract ParseRow(parser_mediator, row_offset, row)[source]
Parses a line of the log file and produces events.
- Parameters
parser_mediator (ParserMediator) – mediates interactions between parsers and other components, such as storage and dfvfs.
row_offset (int) – offset of the line from which the row was extracted.
row (dict[str, str]) – fields of a single row, as specified in COLUMNS.
- QUOTE_CHAR = '"'
- abstract VerifyRow(parser_mediator, row)[source]
Verifies if a line of the file is in the expected format.
- Parameters
parser_mediator (ParserMediator) – mediates interactions between parsers and other components, such as storage and dfvfs.
row (dict[str, str]) – fields of a single row, as specified in COLUMNS.
- Returns
True if this is the correct parser, False otherwise.
- Return type
bool
plaso.parsers.esedb module
Parser for Extensible Storage Engine (ESE) database files (EDB).
- class plaso.parsers.esedb.ESEDBCache[source]
Bases:
BasePluginCache
A cache storing query results for ESEDB plugins.
- class plaso.parsers.esedb.ESEDBParser[source]
Bases:
FileObjectParser
Parses Extensible Storage Engine (ESE) database files (EDB).
- DATA_FORMAT = 'Extensible Storage Engine (ESE) Database File (EDB) format'
- classmethod GetFormatSpecification()[source]
Retrieves the format specification.
- Returns
format specification.
- Return type
- NAME = 'esedb'
- ParseFileObject(parser_mediator, file_object)[source]
Parses an ESE database file-like object.
- Parameters
parser_mediator (ParserMediator) – mediates interactions between parsers and other components, such as storage and dfvfs.
file_object (dfvfs.FileIO) – file-like object.
- class plaso.parsers.esedb.ESEDatabase[source]
Bases:
object
Extensible Storage Engine (ESE) database.
- GetTableByName(name)[source]
Retrieves a table by its name.
- Parameters
name (str) – name of the table.
- Returns
- the table with the corresponding name or None if there is
no table with the name.
- Return type
pyesedb.table
- Open(file_object)[source]
Opens an Extensible Storage Engine (ESE) database file.
- Parameters
file_object (dfvfs.FileIO) – file-like object.
- Raises
IOError – if the file-like object cannot be read.
OSError – if the file-like object cannot be read.
ValueError – if the file-like object is missing.
- property tables
names of all the tables.
- Type
list[str]
plaso.parsers.filestat module
File system stat object parser.
- class plaso.parsers.filestat.FileStatEventData(*args: Any, **kwargs: Any)[source]
Bases:
EventData
File system stat event data.
- access_time
file entry last access date and time.
- Type
dfdatetime.DateTimeValues
- added_time
file entry added date and time.
- Type
dfdatetime.DateTimeValues
- attribute_names
extended attribute names.
- Type
[str]
- backup_time
file entry backup date and time.
- Type
dfdatetime.DateTimeValues
- change_time
file entry inode change (or metadata last modification) date and time.
- Type
dfdatetime.DateTimeValues
- creation_time
file entry creation date and time.
- Type
dfdatetime.DateTimeValues
- deletion_time
file entry deletion date and time.
- Type
dfdatetime.DateTimeValues
- display_name
display name.
- Type
str
- file_entry_type
dfVFS file entry type.
- Type
int
- file_size
file size in bytes.
- Type
int
- file_system_type
file system type.
- Type
str
- filename
name of the file.
- Type
str
- group_identifier
group identifier (GID), equivalent to st_gid.
- Type
int
- inode
inode of the file.
- Type
int
- is_allocated
True if the file is allocated.
- Type
bool
- mode
access mode, equivalent to st_mode & 0x0fff.
- Type
int
- modification_time
file entry last modification date and time.
- Type
dfdatetime.DateTimeValues
- number_of_links
number of hard links, equivalent to st_nlink.
- Type
int
- owner_identifier
user identifier (UID) of the owner, equivalent to st_uid.
- Type
int
- DATA_TYPE = 'fs:stat'
- class plaso.parsers.filestat.FileStatParser[source]
Bases:
FileEntryParser
Parses file system stat object.
- DATA_FORMAT = 'file system stat information'
- NAME = 'filestat'
- ParseFileEntry(parser_mediator, file_entry)[source]
Parses a file entry.
- Parameters
parser_mediator (ParserMediator) – mediates interactions between parsers and other components, such as storage and dfVFS.
file_entry (dfvfs.FileEntry) – a file entry.
plaso.parsers.firefox_cache module
Implements a parser for Firefox cache 1 and 2 files.
- class plaso.parsers.firefox_cache.BaseFirefoxCacheParser[source]
Bases:
FileObjectParser
Parses Firefox cache files.
- class plaso.parsers.firefox_cache.FirefoxCache2Parser[source]
Bases:
BaseFirefoxCacheParser
,DtFabricHelper
Parses Firefox cache version 2 files (Firefox 32 or later).
- DATA_FORMAT = 'Mozilla Firefox Cache version 2 file (version 32 or later)'
- NAME = 'firefox_cache2'
- ParseFileObject(parser_mediator, file_object)[source]
Parses a Firefox cache file-like object.
- Parameters
parser_mediator (ParserMediator) – mediates interactions between parsers and other components, such as storage and dfVFS.
file_object (dfvfs.FileIO) – a file-like object.
- Raises
WrongParser – when the file cannot be parsed.
- class plaso.parsers.firefox_cache.FirefoxCacheEventData(*args: Any, **kwargs: Any)[source]
Bases:
EventData
Firefox cache event data.
- data_size
size of the cached data.
- Type
int
- expiration_time
date and time the cache entry expires.
- Type
dfdatetime.DateTimeValues
- fetch_count
number of times the cache entry was fetched.
- Type
int
- frequency
???
- Type
int
- info_size
size of the metadata.
- Type
int
- last_fetched_time
date and time the cache entry was last fetched.
- Type
dfdatetime.DateTimeValues
- last_modified_time
date and time the cache entry was last modified.
- Type
dfdatetime.DateTimeValues
- location
???
- Type
str
- request_method
HTTP request method.
- Type
str
- request_size
HTTP request byte size.
- Type
int
- response_code
HTTP response code.
- Type
int
- url
URL of original content.
- Type
str
- version
cache format version.
- Type
str
- DATA_TYPE = 'firefox:cache:record'
- class plaso.parsers.firefox_cache.FirefoxCacheParser[source]
Bases:
BaseFirefoxCacheParser
,DtFabricHelper
Parses Firefox cache version 1 files (Firefox 31 or earlier).
- DATA_FORMAT = 'Mozilla Firefox Cache version 1 file (version 31 or earlier)'
- FIREFOX_CACHE_CONFIG
alias of
firefox_cache_config
- NAME = 'firefox_cache'
- ParseFileObject(parser_mediator, file_object)[source]
Parses a Firefox cache file-like object.
- Parameters
parser_mediator (ParserMediator) – mediates interactions between parsers and other components, such as storage and dfVFS.
file_object (dfvfs.FileIO) – a file-like object.
- Raises
WrongParser – when the file cannot be parsed.
plaso.parsers.fish_history module
Parser for fish history files.
- class plaso.parsers.fish_history.FishHistoryEventData(*args: Any, **kwargs: Any)[source]
Bases:
EventData
Fish history log event data.
- command
command that was executed.
- Type
str
- written_time
date and time the entry was written.
- Type
dfdatetime.DateTimeValues
- DATA_TYPE = 'fish:history:entry'
- class plaso.parsers.fish_history.FishHistoryParser[source]
Bases:
FileObjectParser
Parses events from Fish history files.
- DATA_FORMAT = 'Fish history file'
- NAME = 'fish_history'
- ParseFileObject(parser_mediator, file_object)[source]
Parses a fish history file from a file-like object
- Parameters
parser_mediator (ParserMediator) – mediates interactions between parsers and other components, such as storage and dfvfs.
file_object (dfvfs.FileIO) – a file-like object.
- Raises
WrongParser – when the file cannot be parsed.
plaso.parsers.fseventsd module
Parsers for MacOS fseventsd files.
- class plaso.parsers.fseventsd.FseventsdEventData(*args: Any, **kwargs: Any)[source]
Bases:
EventData
MacOS file system event (fseventsd) event data
- event_identifier
the record event identifier.
- Type
int
- file_entry_modification_time
file entry last modification date and time.
- Type
dfdatetime.DateTimeValues
- flags
flags stored in the record.
- Type
int
- node_identifier
file system node identifier related to the file system event.
- Type
int
- path
path recorded in the fseventsd record.
- Type
str
- DATA_TYPE = 'macos:fseventsd:record'
- class plaso.parsers.fseventsd.FseventsdParser[source]
Bases:
FileObjectParser
,DtFabricHelper
Parser for fseventsd files.
This parser supports both version 1 and version 2 fseventsd files.
- DATA_FORMAT = 'MacOS File System Events Disk Log Stream (fseventsd) file'
- classmethod GetFormatSpecification()[source]
Retrieves the format specification.
- Returns
format specification.
- Return type
- NAME = 'fseventsd'
- ParseFileObject(parser_mediator, file_object)[source]
Parses an fseventsd file.
- Parameters
parser_mediator (ParserMediator) – parser mediator.
file_object (dfvfs.FileIO) – a file-like object.
- Raises
WrongParser – when the header cannot be parsed.
plaso.parsers.interface module
The parsers and plugins interface classes.
- class plaso.parsers.interface.BaseFileEntryFilter[source]
Bases:
object
File entry filter interface.
- class plaso.parsers.interface.BaseParser[source]
Bases:
object
The parser interface.
- ALL_PLUGINS = {'*'}
- DATA_FORMAT = ''
- classmethod DeregisterPlugin(plugin_class)[source]
Deregisters a plugin class.
The plugin classes are identified based on their lower case name.
- Parameters
plugin_class (type) – class of the plugin.
- Raises
KeyError – if plugin class is not set for the corresponding name.
- EnablePlugins(plugin_includes)[source]
Enables parser plugins.
- Parameters
plugin_includes (set[str]) – names of the plugins to enable, where set([‘*’]) represents all plugins. Note the default plugin, if it exists, is always enabled and cannot be disabled.
- FILTERS = frozenset({})
- classmethod GetFormatSpecification()[source]
Retrieves the format specification.
- Returns
a format specification or None if not available.
- Return type
- classmethod GetPluginNames()[source]
Retrieves the names of registered plugins.
- Returns
names of the plugins.
- Return type
list[str]
- classmethod GetPluginObjectByName