plaso.parsers package
Subpackages
- plaso.parsers.bencode_plugins package
- plaso.parsers.cookie_plugins package
- Submodules
- plaso.parsers.cookie_plugins.ganalytics module
GoogleAnalyticsUtmaEventData
GoogleAnalyticsUtmaEventData.cookie_name
GoogleAnalyticsUtmaEventData.domain_hash
GoogleAnalyticsUtmaEventData.sessions
GoogleAnalyticsUtmaEventData.url
GoogleAnalyticsUtmaEventData.visited_times
GoogleAnalyticsUtmaEventData.visitor_identifier
GoogleAnalyticsUtmaEventData.DATA_TYPE
GoogleAnalyticsUtmaEventData.__init__()
GoogleAnalyticsUtmaPlugin
GoogleAnalyticsUtmbEventData
GoogleAnalyticsUtmbPlugin
GoogleAnalyticsUtmtEventData
GoogleAnalyticsUtmtPlugin
GoogleAnalyticsUtmzEventData
GoogleAnalyticsUtmzEventData.cookie_name
GoogleAnalyticsUtmzEventData.domain_hash
GoogleAnalyticsUtmzEventData.last_visited_time
GoogleAnalyticsUtmzEventData.sessions
GoogleAnalyticsUtmzEventData.sources
GoogleAnalyticsUtmzEventData.url
GoogleAnalyticsUtmzEventData.DATA_TYPE
GoogleAnalyticsUtmzEventData.__init__()
GoogleAnalyticsUtmzPlugin
- plaso.parsers.cookie_plugins.interface module
- plaso.parsers.cookie_plugins.manager module
- Module contents
- plaso.parsers.czip_plugins package
- Submodules
- plaso.parsers.czip_plugins.interface module
- plaso.parsers.czip_plugins.oxml module
OpenXMLEventData
OpenXMLEventData.application
OpenXMLEventData.application_version
OpenXMLEventData.author
OpenXMLEventData.creation_time
OpenXMLEventData.digital_signature
OpenXMLEventData.edit_duration
OpenXMLEventData.hyperlinks_changed
OpenXMLEventData.last_printed_time
OpenXMLEventData.last_saved_by
OpenXMLEventData.links_up_to_date
OpenXMLEventData.modification_time
OpenXMLEventData.number_of_characters
OpenXMLEventData.number_of_characters_with_spaces
OpenXMLEventData.number_of_clips
OpenXMLEventData.number_of_hidden_slides
OpenXMLEventData.number_of_lines
OpenXMLEventData.number_of_pages
OpenXMLEventData.number_of_paragraphs
OpenXMLEventData.number_of_slides
OpenXMLEventData.number_of_words
OpenXMLEventData.revision_number
OpenXMLEventData.scale
OpenXMLEventData.security_flags
OpenXMLEventData.shared_doc
OpenXMLEventData.template
OpenXMLEventData.DATA_TYPE
OpenXMLEventData.__init__()
OpenXMLPlugin
- Module contents
- plaso.parsers.esedb_plugins package
- Submodules
- plaso.parsers.esedb_plugins.file_history module
FileHistoryESEDBPlugin
FileHistoryNamespaceEventData
FileHistoryNamespaceEventData.creation_time
FileHistoryNamespaceEventData.file_attribute
FileHistoryNamespaceEventData.identifier
FileHistoryNamespaceEventData.modification_time
FileHistoryNamespaceEventData.original_filename
FileHistoryNamespaceEventData.parent_identifier
FileHistoryNamespaceEventData.usn_number
FileHistoryNamespaceEventData.DATA_TYPE
FileHistoryNamespaceEventData.__init__()
- plaso.parsers.esedb_plugins.interface module
ESEDBPlugin
ESEDBPlugin.BINARY_DATA_COLUMN_TYPES
ESEDBPlugin.CheckRequiredTables()
ESEDBPlugin.DATA_FORMAT
ESEDBPlugin.FLOATING_POINT_COLUMN_TYPES
ESEDBPlugin.INTEGER_COLUMN_TYPES
ESEDBPlugin.NAME
ESEDBPlugin.OPTIONAL_TABLES
ESEDBPlugin.Process()
ESEDBPlugin.REQUIRED_TABLES
ESEDBPlugin.STRING_COLUMN_TYPES
ESEDBPlugin.__init__()
- plaso.parsers.esedb_plugins.msie_webcache module
MsieWebCacheContainerEventData
MsieWebCacheContainerEventData.access_count
MsieWebCacheContainerEventData.access_time
MsieWebCacheContainerEventData.cached_filename
MsieWebCacheContainerEventData.cached_file_size
MsieWebCacheContainerEventData.cache_identifier
MsieWebCacheContainerEventData.container_identifier
MsieWebCacheContainerEventData.creation_time
MsieWebCacheContainerEventData.entry_identifier
MsieWebCacheContainerEventData.expiration_time
MsieWebCacheContainerEventData.file_extension
MsieWebCacheContainerEventData.modification_time
MsieWebCacheContainerEventData.post_check_time
MsieWebCacheContainerEventData.redirect_url
MsieWebCacheContainerEventData.request_headers
MsieWebCacheContainerEventData.response_headers
MsieWebCacheContainerEventData.synchronization_count
MsieWebCacheContainerEventData.synchronization_time
MsieWebCacheContainerEventData.url
MsieWebCacheContainerEventData.DATA_TYPE
MsieWebCacheContainerEventData.__init__()
MsieWebCacheContainersEventData
MsieWebCacheContainersEventData.access_time
MsieWebCacheContainersEventData.container_identifier
MsieWebCacheContainersEventData.directory
MsieWebCacheContainersEventData.name
MsieWebCacheContainersEventData.scavenge_time
MsieWebCacheContainersEventData.set_identifier
MsieWebCacheContainersEventData.DATA_TYPE
MsieWebCacheContainersEventData.__init__()
MsieWebCacheCookieData
MsieWebCacheCookieData.container_identifier
MsieWebCacheCookieData.cookie_hash
MsieWebCacheCookieData.cookie_name
MsieWebCacheCookieData.cookie_value_raw
MsieWebCacheCookieData.cookie_value
MsieWebCacheCookieData.entry_identifier
MsieWebCacheCookieData.expiration_time
MsieWebCacheCookieData.flags
MsieWebCacheCookieData.modification_time
MsieWebCacheCookieData.request_domain
MsieWebCacheCookieData.DATA_TYPE
MsieWebCacheCookieData.__init__()
MsieWebCacheESEDBPlugin
MsieWebCacheESEDBPlugin.DATA_FORMAT
MsieWebCacheESEDBPlugin.GetRawCookieValue()
MsieWebCacheESEDBPlugin.NAME
MsieWebCacheESEDBPlugin.OPTIONAL_TABLES
MsieWebCacheESEDBPlugin.ParseContainersTable()
MsieWebCacheESEDBPlugin.ParseLeakFilesTable()
MsieWebCacheESEDBPlugin.ParsePartitionsTable()
MsieWebCacheESEDBPlugin.REQUIRED_TABLES
MsieWebCacheLeakFilesEventData
MsieWebCachePartitionsEventData
MsieWebCachePartitionsEventData.directory
MsieWebCachePartitionsEventData.partition_identifier
MsieWebCachePartitionsEventData.partition_type
MsieWebCachePartitionsEventData.scavenge_time
MsieWebCachePartitionsEventData.table_identifier
MsieWebCachePartitionsEventData.DATA_TYPE
MsieWebCachePartitionsEventData.__init__()
- plaso.parsers.esedb_plugins.srum module
SRUMApplicationResourceUsageEventData
SRUMApplicationResourceUsageEventData.application
SRUMApplicationResourceUsageEventData.background_bytes_read
SRUMApplicationResourceUsageEventData.background_bytes_written
SRUMApplicationResourceUsageEventData.background_context_switches
SRUMApplicationResourceUsageEventData.background_cycle_time
SRUMApplicationResourceUsageEventData.background_number_for_flushes
SRUMApplicationResourceUsageEventData.background_number_for_read_operations
SRUMApplicationResourceUsageEventData.background_number_for_write_operations
SRUMApplicationResourceUsageEventData.face_time
SRUMApplicationResourceUsageEventData.foreground_bytes_read
SRUMApplicationResourceUsageEventData.foreground_bytes_written
SRUMApplicationResourceUsageEventData.foreground_context_switches
SRUMApplicationResourceUsageEventData.foreground_cycle_time
SRUMApplicationResourceUsageEventData.foreground_number_for_flushes
SRUMApplicationResourceUsageEventData.foreground_number_for_read_operations
SRUMApplicationResourceUsageEventData.foreground_number_for_write_operations
SRUMApplicationResourceUsageEventData.identifier
SRUMApplicationResourceUsageEventData.recorded_time
SRUMApplicationResourceUsageEventData.user_identifier
SRUMApplicationResourceUsageEventData.DATA_TYPE
SRUMApplicationResourceUsageEventData.__init__()
SRUMNetworkConnectivityUsageEventData
SRUMNetworkConnectivityUsageEventData.application
SRUMNetworkConnectivityUsageEventData.identifier
SRUMNetworkConnectivityUsageEventData.interface_luid
SRUMNetworkConnectivityUsageEventData.last_connected_time
SRUMNetworkConnectivityUsageEventData.l2_profile_flags
SRUMNetworkConnectivityUsageEventData.l2_profile_identifier
SRUMNetworkConnectivityUsageEventData.recorded_time
SRUMNetworkConnectivityUsageEventData.user_identifier
SRUMNetworkConnectivityUsageEventData.DATA_TYPE
SRUMNetworkConnectivityUsageEventData.__init__()
SRUMNetworkDataUsageEventData
SRUMNetworkDataUsageEventData.application
SRUMNetworkDataUsageEventData.bytes_received
SRUMNetworkDataUsageEventData.bytes_sent
SRUMNetworkDataUsageEventData.identifier
SRUMNetworkDataUsageEventData.interface_luid
SRUMNetworkDataUsageEventData.l2_profile_flags
SRUMNetworkDataUsageEventData.l2_profile_identifier
SRUMNetworkDataUsageEventData.recorded_time
SRUMNetworkDataUsageEventData.user_identifier
SRUMNetworkDataUsageEventData.DATA_TYPE
SRUMNetworkDataUsageEventData.__init__()
SystemResourceUsageMonitorESEDBPlugin
SystemResourceUsageMonitorESEDBPlugin.DATA_FORMAT
SystemResourceUsageMonitorESEDBPlugin.NAME
SystemResourceUsageMonitorESEDBPlugin.OPTIONAL_TABLES
SystemResourceUsageMonitorESEDBPlugin.ParseApplicationResourceUsage()
SystemResourceUsageMonitorESEDBPlugin.ParseNetworkConnectivityUsage()
SystemResourceUsageMonitorESEDBPlugin.ParseNetworkDataUsage()
SystemResourceUsageMonitorESEDBPlugin.REQUIRED_TABLES
- plaso.parsers.esedb_plugins.user_access_logging module
UserAccessLoggingClientsEventsData
UserAccessLoggingClientsEventsData.access_time
UserAccessLoggingClientsEventsData.authenticated_username
UserAccessLoggingClientsEventsData.client_name
UserAccessLoggingClientsEventsData.insert_time
UserAccessLoggingClientsEventsData.role_identifier
UserAccessLoggingClientsEventsData.role_name
UserAccessLoggingClientsEventsData.source_ip_address
UserAccessLoggingClientsEventsData.tenant_identifier
UserAccessLoggingClientsEventsData.total_accesses
UserAccessLoggingClientsEventsData.DATA_TYPE
UserAccessLoggingClientsEventsData.__init__()
UserAccessLoggingDNSEventData
UserAccessLoggingESEDBPlugin
UserAccessLoggingESEDBPlugin.DATA_FORMAT
UserAccessLoggingESEDBPlugin.NAME
UserAccessLoggingESEDBPlugin.ParseClientsTable()
UserAccessLoggingESEDBPlugin.ParseDNSTable()
UserAccessLoggingESEDBPlugin.ParseRoleAccessTable()
UserAccessLoggingESEDBPlugin.ParseVirtualMachinesTable()
UserAccessLoggingESEDBPlugin.REQUIRED_TABLES
UserAccessLoggingESEDBPlugin.__init__()
UserAccessLoggingRoleAccessEventsData
UserAccessLoggingRoleAccessEventsData.first_seen_time
UserAccessLoggingRoleAccessEventsData.last_seen_time
UserAccessLoggingRoleAccessEventsData.role_identifier
UserAccessLoggingRoleAccessEventsData.role_name
UserAccessLoggingRoleAccessEventsData.DATA_TYPE
UserAccessLoggingRoleAccessEventsData.__init__()
UserAccessLoggingSystemIdentityEventdata
UserAccessLoggingSystemIdentityEventdata.creation_time
UserAccessLoggingSystemIdentityEventdata.operating_system_build
UserAccessLoggingSystemIdentityEventdata.system_dns_hostname
UserAccessLoggingSystemIdentityEventdata.system_domain_name
UserAccessLoggingSystemIdentityEventdata.DATA_TYPE
UserAccessLoggingSystemIdentityEventdata.__init__()
UserAccessLoggingVirtualMachinesEventData
UserAccessLoggingVirtualMachinesEventData.bios_identifier
UserAccessLoggingVirtualMachinesEventData.creation_time
UserAccessLoggingVirtualMachinesEventData.last_active_time
UserAccessLoggingVirtualMachinesEventData.serial_number
UserAccessLoggingVirtualMachinesEventData.vm_identifier
UserAccessLoggingVirtualMachinesEventData.DATA_TYPE
UserAccessLoggingVirtualMachinesEventData.__init__()
- Module contents
- plaso.parsers.jsonl_plugins package
- Submodules
- plaso.parsers.jsonl_plugins.aws_cloudtrail_log module
AWSCloudTrailEventData
AWSCloudTrailEventData.access_key
AWSCloudTrailEventData.account_identifier
AWSCloudTrailEventData.cloud_trail_event
AWSCloudTrailEventData.event_name
AWSCloudTrailEventData.event_source
AWSCloudTrailEventData.recorded_time
AWSCloudTrailEventData.resources
AWSCloudTrailEventData.source_ip
AWSCloudTrailEventData.user_identity_arn
AWSCloudTrailEventData.user_name
AWSCloudTrailEventData.DATA_TYPE
AWSCloudTrailEventData.__init__()
AWSCloudTrailLogJSONLPlugin
- plaso.parsers.jsonl_plugins.azure_activity_log module
AzureActivityLogEventData
AzureActivityLogEventData.caller
AzureActivityLogEventData.client_ip
AzureActivityLogEventData.correlation_identifier
AzureActivityLogEventData.event_data_identifier
AzureActivityLogEventData.event_name
AzureActivityLogEventData.level
AzureActivityLogEventData.operation_identifier
AzureActivityLogEventData.operation_name
AzureActivityLogEventData.recorded_time
AzureActivityLogEventData.resource_group
AzureActivityLogEventData.resource_identifier
AzureActivityLogEventData.resource_provider
AzureActivityLogEventData.resource_type
AzureActivityLogEventData.subscription_identifier
AzureActivityLogEventData.tenant_identifier
AzureActivityLogEventData.DATA_TYPE
AzureActivityLogEventData.__init__()
AzureActivityLogJSONLPlugin
- plaso.parsers.jsonl_plugins.azure_application_gateway_log module
AzureApplicationGatewayAccessEventData
AzureApplicationGatewayAccessEventData.client_ip
AzureApplicationGatewayAccessEventData.client_port
AzureApplicationGatewayAccessEventData.client_response_time
AzureApplicationGatewayAccessEventData.host
AzureApplicationGatewayAccessEventData.http_method
AzureApplicationGatewayAccessEventData.http_status
AzureApplicationGatewayAccessEventData.http_version
AzureApplicationGatewayAccessEventData.instance_identifier
AzureApplicationGatewayAccessEventData.original_host
AzureApplicationGatewayAccessEventData.original_request_uri
AzureApplicationGatewayAccessEventData.received_bytes
AzureApplicationGatewayAccessEventData.recorded_time
AzureApplicationGatewayAccessEventData.request_query
AzureApplicationGatewayAccessEventData.request_uri
AzureApplicationGatewayAccessEventData.sent_bytes
AzureApplicationGatewayAccessEventData.server_response_latency
AzureApplicationGatewayAccessEventData.server_routed
AzureApplicationGatewayAccessEventData.server_status
AzureApplicationGatewayAccessEventData.ssl_cipher
AzureApplicationGatewayAccessEventData.ssl_client_certificate_fingerprint
AzureApplicationGatewayAccessEventData.ssl_client_certificate_issuer_name
AzureApplicationGatewayAccessEventData.ssl_client_verify
AzureApplicationGatewayAccessEventData.ssl_enabled
AzureApplicationGatewayAccessEventData.ssl_protocol
AzureApplicationGatewayAccessEventData.time_taken
AzureApplicationGatewayAccessEventData.transaction_id
AzureApplicationGatewayAccessEventData.user_agent
AzureApplicationGatewayAccessEventData.waf_evaluation_time
AzureApplicationGatewayAccessEventData.waf_mode
AzureApplicationGatewayAccessEventData.DATA_TYPE
AzureApplicationGatewayAccessEventData.__init__()
AzureApplicationGatewayAccessLogJSONLPlugin
- plaso.parsers.jsonl_plugins.docker_container_config module
DockerContainerConfigurationEventData
DockerContainerConfigurationEventData.action
DockerContainerConfigurationEventData.container_identifier
DockerContainerConfigurationEventData.container_name
DockerContainerConfigurationEventData.creation_time
DockerContainerConfigurationEventData.end_time
DockerContainerConfigurationEventData.start_time
DockerContainerConfigurationEventData.DATA_TYPE
DockerContainerConfigurationEventData.__init__()
DockerContainerConfigurationJSONLPlugin
- plaso.parsers.jsonl_plugins.docker_container_log module
- plaso.parsers.jsonl_plugins.docker_layer_config module
- plaso.parsers.jsonl_plugins.gcp_log module
GCPLogEventData
GCPLogEventData.container
GCPLogEventData.event_subtype
GCPLogEventData.event_type
GCPLogEventData.filename
GCPLogEventData.firewall_rules
GCPLogEventData.firewall_source_ranges
GCPLogEventData.log_name
GCPLogEventData.message
GCPLogEventData.policy_deltas
GCPLogEventData.recorded_time
GCPLogEventData.request_account_identifier
GCPLogEventData.request_description
GCPLogEventData.request_direction
GCPLogEventData.request_email
GCPLogEventData.request_member
GCPLogEventData.request_metadata
GCPLogEventData.request_name
GCPLogEventData.request_target_tags
GCPLogEventData.resource_labels
GCPLogEventData.resource_name
GCPLogEventData.service_account_display_name
GCPLogEventData.service_name
GCPLogEventData.severity
GCPLogEventData.text_payload
GCPLogEventData.user
GCPLogEventData.DATA_TYPE
GCPLogEventData.__init__()
GCPLogJSONLPlugin
- plaso.parsers.jsonl_plugins.interface module
- plaso.parsers.jsonl_plugins.ios_app_privacy module
- plaso.parsers.jsonl_plugins.microsoft365_audit_log module
Microsoft365AuditLogEventData
Microsoft365AuditLogEventData.audit_record_identifier
Microsoft365AuditLogEventData.application_access_context
Microsoft365AuditLogEventData.client_ip
Microsoft365AuditLogEventData.object_identifier
Microsoft365AuditLogEventData.operation_name
Microsoft365AuditLogEventData.organization_identifier
Microsoft365AuditLogEventData.record_type
Microsoft365AuditLogEventData.recorded_time
Microsoft365AuditLogEventData.result_status
Microsoft365AuditLogEventData.scope
Microsoft365AuditLogEventData.user_identifier
Microsoft365AuditLogEventData.user_key
Microsoft365AuditLogEventData.user_type
Microsoft365AuditLogEventData.workload
Microsoft365AuditLogEventData.DATA_TYPE
Microsoft365AuditLogEventData.__init__()
Microsoft365AuditLogJSONLPlugin
- Module contents
- plaso.parsers.olecf_plugins package
- Submodules
- plaso.parsers.olecf_plugins.automatic_destinations module
AutomaticDestinationsDestListEntryEventData
AutomaticDestinationsDestListEntryEventData.birth_droid_file_identifier
AutomaticDestinationsDestListEntryEventData.birth_droid_volume_identifier
AutomaticDestinationsDestListEntryEventData.droid_file_identifier
AutomaticDestinationsDestListEntryEventData.droid_volume_identifier
AutomaticDestinationsDestListEntryEventData.entry_number
AutomaticDestinationsDestListEntryEventData.hostname
AutomaticDestinationsDestListEntryEventData.modification_time
AutomaticDestinationsDestListEntryEventData.offset
AutomaticDestinationsDestListEntryEventData.path
AutomaticDestinationsDestListEntryEventData.pin_status
AutomaticDestinationsDestListEntryEventData.DATA_TYPE
AutomaticDestinationsDestListEntryEventData.__init__()
AutomaticDestinationsOLECFPlugin
- plaso.parsers.olecf_plugins.default module
- plaso.parsers.olecf_plugins.interface module
- plaso.parsers.olecf_plugins.summary module
DocumentSummaryInformationOLECFPlugin
OLECFDocumentSummaryInformation
OLECFDocumentSummaryInformationEventData
OLECFDocumentSummaryInformationEventData.application_version
OLECFDocumentSummaryInformationEventData.category
OLECFDocumentSummaryInformationEventData.codepage
OLECFDocumentSummaryInformationEventData.company
OLECFDocumentSummaryInformationEventData.content_status
OLECFDocumentSummaryInformationEventData.content_type
OLECFDocumentSummaryInformationEventData.document_parts
OLECFDocumentSummaryInformationEventData.document_version
OLECFDocumentSummaryInformationEventData.item_creation_time
OLECFDocumentSummaryInformationEventData.item_modification_time
OLECFDocumentSummaryInformationEventData.language
OLECFDocumentSummaryInformationEventData.links_up_to_date
OLECFDocumentSummaryInformationEventData.manager
OLECFDocumentSummaryInformationEventData.number_of_bytes
OLECFDocumentSummaryInformationEventData.number_of_characters_with_white_space
OLECFDocumentSummaryInformationEventData.number_of_clips
OLECFDocumentSummaryInformationEventData.number_of_hidden_slides
OLECFDocumentSummaryInformationEventData.number_of_lines
OLECFDocumentSummaryInformationEventData.number_of_notes
OLECFDocumentSummaryInformationEventData.number_of_paragraphs
OLECFDocumentSummaryInformationEventData.number_of_slides
OLECFDocumentSummaryInformationEventData.presentation_format
OLECFDocumentSummaryInformationEventData.scale
OLECFDocumentSummaryInformationEventData.shared_document
OLECFDocumentSummaryInformationEventData.DATA_TYPE
OLECFDocumentSummaryInformationEventData.__init__()
OLECFPropertySetStream
OLECFSummaryInformation
OLECFSummaryInformationEventData
OLECFSummaryInformationEventData.application
OLECFSummaryInformationEventData.author
OLECFSummaryInformationEventData.codepage
OLECFSummaryInformationEventData.comments
OLECFSummaryInformationEventData.creation_time
OLECFSummaryInformationEventData.edit_duration
OLECFSummaryInformationEventData.item_creation_time
OLECFSummaryInformationEventData.item_modification_time
OLECFSummaryInformationEventData.keywords
OLECFSummaryInformationEventData.last_printed_time
OLECFSummaryInformationEventData.last_saved_by
OLECFSummaryInformationEventData.last_save_time
OLECFSummaryInformationEventData.number_of_characters
OLECFSummaryInformationEventData.number_of_pages
OLECFSummaryInformationEventData.number_of_words
OLECFSummaryInformationEventData.revision_number
OLECFSummaryInformationEventData.security_flags
OLECFSummaryInformationEventData.subject
OLECFSummaryInformationEventData.template
OLECFSummaryInformationEventData.title
OLECFSummaryInformationEventData.DATA_TYPE
OLECFSummaryInformationEventData.__init__()
SummaryInformationOLECFPlugin
- Module contents
- plaso.parsers.plist_plugins package
- Submodules
- plaso.parsers.plist_plugins.airport module
- plaso.parsers.plist_plugins.apple_account module
- plaso.parsers.plist_plugins.bluetooth module
MacOSBluetoothEventData
MacOSBluetoothEventData.device_identifier
MacOSBluetoothEventData.device_name
MacOSBluetoothEventData.inquiry_time
MacOSBluetoothEventData.is_paired
MacOSBluetoothEventData.name_update_time
MacOSBluetoothEventData.services_update_time
MacOSBluetoothEventData.DATA_TYPE
MacOSBluetoothEventData.__init__()
MacOSBluetoothPlistPlugin
- plaso.parsers.plist_plugins.default module
- plaso.parsers.plist_plugins.install_history module
- plaso.parsers.plist_plugins.interface module
- plaso.parsers.plist_plugins.ios_carplay module
- plaso.parsers.plist_plugins.ios_identityservices module
- plaso.parsers.plist_plugins.ipod module
IPodPlistEventData
IPodPlistEventData.device_class
IPodPlistEventData.device_identifier
IPodPlistEventData.family_identifier
IPodPlistEventData.firmware_version
IPodPlistEventData.imei
IPodPlistEventData.last_connected_time
IPodPlistEventData.serial_number
IPodPlistEventData.use_count
IPodPlistEventData.DATA_TYPE
IPodPlistEventData.__init__()
IPodPlugin
- plaso.parsers.plist_plugins.launchd module
- plaso.parsers.plist_plugins.macos_background_items module
MacOSBackgroundItemEventData
MacOSBackgroundItemEventData.name
MacOSBackgroundItemEventData.target_creation_time
MacOSBackgroundItemEventData.target_path
MacOSBackgroundItemEventData.volume_creation_time
MacOSBackgroundItemEventData.volume_flags
MacOSBackgroundItemEventData.volume_mount_point
MacOSBackgroundItemEventData.volume_name
MacOSBackgroundItemEventData.DATA_TYPE
MacOSBackgroundItemEventData.__init__()
MacOSBackgroundItemsPlistPlugin
- plaso.parsers.plist_plugins.macos_login_items module
MacOSLoginItemEventData
MacOSLoginItemEventData.hidden
MacOSLoginItemEventData.name
MacOSLoginItemEventData.target_creation_time
MacOSLoginItemEventData.target_path
MacOSLoginItemEventData.volume_creation_time
MacOSLoginItemEventData.volume_flags
MacOSLoginItemEventData.volume_mount_point
MacOSLoginItemEventData.volume_name
MacOSLoginItemEventData.DATA_TYPE
MacOSLoginItemEventData.__init__()
MacOSLoginItemsPlistPlugin
- plaso.parsers.plist_plugins.macos_login_window module
- plaso.parsers.plist_plugins.macos_startup_item module
- plaso.parsers.plist_plugins.macos_user module
MacOSUserEventData
MacOSUserEventData.fullname
MacOSUserEventData.home_directory
MacOSUserEventData.last_login_attempt_time
MacOSUserEventData.last_login_time
MacOSUserEventData.last_password_set_time
MacOSUserEventData.number_of_failed_login_attempts
MacOSUserEventData.password_hash
MacOSUserEventData.user_identifier
MacOSUserEventData.username
MacOSUserEventData.DATA_TYPE
MacOSUserEventData.__init__()
MacOSUserPlistPlugin
- plaso.parsers.plist_plugins.safari_downloads module
SafariDownloadEventData
SafariDownloadEventData.end_time
SafariDownloadEventData.full_path
SafariDownloadEventData.received_bytes
SafariDownloadEventData.remove_on_completion
SafariDownloadEventData.start_time
SafariDownloadEventData.total_bytes
SafariDownloadEventData.url
SafariDownloadEventData.DATA_TYPE
SafariDownloadEventData.__init__()
SafariDownloadsPlistPlugin
- plaso.parsers.plist_plugins.safari_history module
- plaso.parsers.plist_plugins.software_update module
- plaso.parsers.plist_plugins.spotlight_searched_terms module
- plaso.parsers.plist_plugins.spotlight_volume module
- plaso.parsers.plist_plugins.time_machine module
- Module contents
- plaso.parsers.shared package
- plaso.parsers.sqlite_plugins package
- Submodules
- plaso.parsers.sqlite_plugins.android_app_usage module
- plaso.parsers.sqlite_plugins.android_calls module
- plaso.parsers.sqlite_plugins.android_hangouts module
AndroidHangoutsMessageData
AndroidHangoutsMessageData.body
AndroidHangoutsMessageData.creation_time
AndroidHangoutsMessageData.message_status
AndroidHangoutsMessageData.message_type
AndroidHangoutsMessageData.offset
AndroidHangoutsMessageData.query
AndroidHangoutsMessageData.sender
AndroidHangoutsMessageData.DATA_TYPE
AndroidHangoutsMessageData.__init__()
AndroidHangoutsMessagePlugin
- plaso.parsers.sqlite_plugins.android_sms module
- plaso.parsers.sqlite_plugins.android_tango module
AndroidTangoContactEventData
AndroidTangoContactEventData.access_time
AndroidTangoContactEventData.birthday
AndroidTangoContactEventData.distance
AndroidTangoContactEventData.first_name
AndroidTangoContactEventData.friend_request_message
AndroidTangoContactEventData.friend_request_time
AndroidTangoContactEventData.friend_request_type
AndroidTangoContactEventData.gender
AndroidTangoContactEventData.is_friend
AndroidTangoContactEventData.last_active_time
AndroidTangoContactEventData.last_name
AndroidTangoContactEventData.status
AndroidTangoContactEventData.DATA_TYPE
AndroidTangoContactEventData.__init__()
AndroidTangoConversationEventData
AndroidTangoMessageEventData
AndroidTangoProfilePlugin
AndroidTangoTCPlugin
- plaso.parsers.sqlite_plugins.android_turbo module
- plaso.parsers.sqlite_plugins.android_twitter module
AndroidTwitterContactEventData
AndroidTwitterContactEventData.creation_time
AndroidTwitterContactEventData.description
AndroidTwitterContactEventData.followers
AndroidTwitterContactEventData.friends
AndroidTwitterContactEventData.friendship_time
AndroidTwitterContactEventData.identifier
AndroidTwitterContactEventData.image_url
AndroidTwitterContactEventData.location
AndroidTwitterContactEventData.modification_time
AndroidTwitterContactEventData.name
AndroidTwitterContactEventData.query
AndroidTwitterContactEventData.statuses
AndroidTwitterContactEventData.user_identifier
AndroidTwitterContactEventData.username
AndroidTwitterContactEventData.web_url
AndroidTwitterContactEventData.DATA_TYPE
AndroidTwitterContactEventData.__init__()
AndroidTwitterPlugin
AndroidTwitterSearchEventData
AndroidTwitterStatusEventData
AndroidTwitterStatusEventData.author_identifier
AndroidTwitterStatusEventData.content
AndroidTwitterStatusEventData.creation_time
AndroidTwitterStatusEventData.favorited
AndroidTwitterStatusEventData.identifier
AndroidTwitterStatusEventData.query
AndroidTwitterStatusEventData.retweeted
AndroidTwitterStatusEventData.username
AndroidTwitterStatusEventData.DATA_TYPE
AndroidTwitterStatusEventData.__init__()
- plaso.parsers.sqlite_plugins.android_webview module
AndroidWebViewCookieEventData
AndroidWebViewCookieEventData.cookie_name
AndroidWebViewCookieEventData.data
AndroidWebViewCookieEventData.expiration_time
AndroidWebViewCookieEventData.host
AndroidWebViewCookieEventData.offset
AndroidWebViewCookieEventData.path
AndroidWebViewCookieEventData.query
AndroidWebViewCookieEventData.secure
AndroidWebViewCookieEventData.url
AndroidWebViewCookieEventData.DATA_TYPE
AndroidWebViewCookieEventData.__init__()
AndroidWebViewPlugin
- plaso.parsers.sqlite_plugins.android_webviewcache module
- plaso.parsers.sqlite_plugins.chrome_autofill module
- plaso.parsers.sqlite_plugins.chrome_cookies module
BaseChromeCookiePlugin
Chrome17CookiePlugin
Chrome66CookiePlugin
ChromeCookieEventData
ChromeCookieEventData.access_time
ChromeCookieEventData.cookie_name
ChromeCookieEventData.creation_time
ChromeCookieEventData.data
ChromeCookieEventData.expiration_time
ChromeCookieEventData.host
ChromeCookieEventData.httponly
ChromeCookieEventData.path
ChromeCookieEventData.persistent
ChromeCookieEventData.query
ChromeCookieEventData.secure
ChromeCookieEventData.url
ChromeCookieEventData.DATA_TYPE
ChromeCookieEventData.__init__()
- plaso.parsers.sqlite_plugins.chrome_extension_activity module
ChromeExtensionActivityEventData
ChromeExtensionActivityEventData.action_type
ChromeExtensionActivityEventData.activity_id
ChromeExtensionActivityEventData.api_name
ChromeExtensionActivityEventData.arg_url
ChromeExtensionActivityEventData.args
ChromeExtensionActivityEventData.extension_id
ChromeExtensionActivityEventData.other
ChromeExtensionActivityEventData.page_title
ChromeExtensionActivityEventData.page_url
ChromeExtensionActivityEventData.query
ChromeExtensionActivityEventData.recorded_time
ChromeExtensionActivityEventData.DATA_TYPE
ChromeExtensionActivityEventData.__init__()
ChromeExtensionActivityPlugin
- plaso.parsers.sqlite_plugins.chrome_history module
BaseGoogleChromeHistoryPlugin
ChromeHistoryFileDownloadedEventData
ChromeHistoryFileDownloadedEventData.danger_type
ChromeHistoryFileDownloadedEventData.end_time
ChromeHistoryFileDownloadedEventData.full_path
ChromeHistoryFileDownloadedEventData.interrupt_reason
ChromeHistoryFileDownloadedEventData.offset
ChromeHistoryFileDownloadedEventData.opened
ChromeHistoryFileDownloadedEventData.query
ChromeHistoryFileDownloadedEventData.received_bytes
ChromeHistoryFileDownloadedEventData.start_time
ChromeHistoryFileDownloadedEventData.state
ChromeHistoryFileDownloadedEventData.total_bytes
ChromeHistoryFileDownloadedEventData.url
ChromeHistoryFileDownloadedEventData.DATA_TYPE
ChromeHistoryFileDownloadedEventData.__init__()
ChromeHistoryPageVisitedEventData
ChromeHistoryPageVisitedEventData.from_visit
ChromeHistoryPageVisitedEventData.last_visited_time
ChromeHistoryPageVisitedEventData.offset
ChromeHistoryPageVisitedEventData.page_transition_type
ChromeHistoryPageVisitedEventData.query
ChromeHistoryPageVisitedEventData.title
ChromeHistoryPageVisitedEventData.typed_count
ChromeHistoryPageVisitedEventData.url
ChromeHistoryPageVisitedEventData.url_hidden
ChromeHistoryPageVisitedEventData.visit_count
ChromeHistoryPageVisitedEventData.visit_source
ChromeHistoryPageVisitedEventData.DATA_TYPE
ChromeHistoryPageVisitedEventData.__init__()
GoogleChrome27HistoryPlugin
GoogleChrome8HistoryPlugin
- plaso.parsers.sqlite_plugins.dropbox module
DropboxSyncDatabasePlugin
DropboxSyncHistoryEventData
DropboxSyncHistoryEventData.event_type
DropboxSyncHistoryEventData.file_event_type
DropboxSyncHistoryEventData.direction
DropboxSyncHistoryEventData.file_identifier
DropboxSyncHistoryEventData.local_path
DropboxSyncHistoryEventData.recorded_time
DropboxSyncHistoryEventData.DATA_TYPE
DropboxSyncHistoryEventData.__init__()
- plaso.parsers.sqlite_plugins.edge_load_statistics module
EdgeLoadStatisticsPlugin
EdgeLoadStatisticsResourceEventData
EdgeLoadStatisticsResourceEventData.last_update
EdgeLoadStatisticsResourceEventData.query
EdgeLoadStatisticsResourceEventData.resource_hostname
EdgeLoadStatisticsResourceEventData.resource_type
EdgeLoadStatisticsResourceEventData.top_level_hostname
EdgeLoadStatisticsResourceEventData.DATA_TYPE
EdgeLoadStatisticsResourceEventData.__init__()
- plaso.parsers.sqlite_plugins.firefox_cookies module
BaseFirefoxCookiePlugin
FirefoxCookie10Plugin
FirefoxCookie2Plugin
FirefoxCookieEventData
FirefoxCookieEventData.access_time
FirefoxCookieEventData.cookie_name
FirefoxCookieEventData.creation_time
FirefoxCookieEventData.data
FirefoxCookieEventData.expiration_time
FirefoxCookieEventData.httponly
FirefoxCookieEventData.host
FirefoxCookieEventData.offset
FirefoxCookieEventData.path
FirefoxCookieEventData.query
FirefoxCookieEventData.secure
FirefoxCookieEventData.DATA_TYPE
FirefoxCookieEventData.__init__()
- plaso.parsers.sqlite_plugins.firefox_downloads module
Firefox118DownloadEventData
Firefox118DownloadEventData.deleted
Firefox118DownloadEventData.download_state
Firefox118DownloadEventData.end_time
Firefox118DownloadEventData.expiration
Firefox118DownloadEventData.flags
Firefox118DownloadEventData.full_path
Firefox118DownloadEventData.mime_type
Firefox118DownloadEventData.name
Firefox118DownloadEventData.offset
Firefox118DownloadEventData.query
Firefox118DownloadEventData.received_bytes
Firefox118DownloadEventData.referrer
Firefox118DownloadEventData.start_time
Firefox118DownloadEventData.temporary_location
Firefox118DownloadEventData.total_bytes
Firefox118DownloadEventData.type
Firefox118DownloadEventData.url
Firefox118DownloadEventData.DATA_TYPE
Firefox118DownloadEventData.__init__()
Firefox118DownloadsPlugin
FirefoxDownloadEventData
FirefoxDownloadEventData.end_time
FirefoxDownloadEventData.full_path
FirefoxDownloadEventData.mime_type
FirefoxDownloadEventData.name
FirefoxDownloadEventData.offset
FirefoxDownloadEventData.query
FirefoxDownloadEventData.received_bytes
FirefoxDownloadEventData.referrer
FirefoxDownloadEventData.start_time
FirefoxDownloadEventData.temporary_location
FirefoxDownloadEventData.total_bytes
FirefoxDownloadEventData.url
FirefoxDownloadEventData.DATA_TYPE
FirefoxDownloadEventData.__init__()
FirefoxDownloadsPlugin
- plaso.parsers.sqlite_plugins.firefox_history module
FirefoxHistoryPlugin
FirefoxHistoryPlugin.DATA_FORMAT
FirefoxHistoryPlugin.NAME
FirefoxHistoryPlugin.ParseBookmarkAnnotationRow()
FirefoxHistoryPlugin.ParseBookmarkFolderRow()
FirefoxHistoryPlugin.ParseBookmarkRow()
FirefoxHistoryPlugin.ParsePageVisitedRow()
FirefoxHistoryPlugin.QUERIES
FirefoxHistoryPlugin.REQUIRED_STRUCTURE
FirefoxHistoryPlugin.SCHEMAS
FirefoxHistoryPlugin.URL_CACHE_QUERY
FirefoxPlacesBookmarkAnnotationEventData
FirefoxPlacesBookmarkAnnotationEventData.added_time
FirefoxPlacesBookmarkAnnotationEventData.content
FirefoxPlacesBookmarkAnnotationEventData.modification_time
FirefoxPlacesBookmarkAnnotationEventData.offset
FirefoxPlacesBookmarkAnnotationEventData.query
FirefoxPlacesBookmarkAnnotationEventData.title
FirefoxPlacesBookmarkAnnotationEventData.url
FirefoxPlacesBookmarkAnnotationEventData.DATA_TYPE
FirefoxPlacesBookmarkAnnotationEventData.__init__()
FirefoxPlacesBookmarkEventData
FirefoxPlacesBookmarkEventData.added_time
FirefoxPlacesBookmarkEventData.host
FirefoxPlacesBookmarkEventData.modification_time
FirefoxPlacesBookmarkEventData.offset
FirefoxPlacesBookmarkEventData.places_title
FirefoxPlacesBookmarkEventData.query
FirefoxPlacesBookmarkEventData.title
FirefoxPlacesBookmarkEventData.type
FirefoxPlacesBookmarkEventData.url
FirefoxPlacesBookmarkEventData.visit_count
FirefoxPlacesBookmarkEventData.DATA_TYPE
FirefoxPlacesBookmarkEventData.__init__()
FirefoxPlacesBookmarkFolderEventData
FirefoxPlacesBookmarkFolderEventData.added_time
FirefoxPlacesBookmarkFolderEventData.modification_time
FirefoxPlacesBookmarkFolderEventData.offset
FirefoxPlacesBookmarkFolderEventData.query
FirefoxPlacesBookmarkFolderEventData.title
FirefoxPlacesBookmarkFolderEventData.DATA_TYPE
FirefoxPlacesBookmarkFolderEventData.__init__()
FirefoxPlacesPageVisitedEventData
FirefoxPlacesPageVisitedEventData.from_visit
FirefoxPlacesPageVisitedEventData.hidden
FirefoxPlacesPageVisitedEventData.host
FirefoxPlacesPageVisitedEventData.last_visited_time
FirefoxPlacesPageVisitedEventData.offset
FirefoxPlacesPageVisitedEventData.query
FirefoxPlacesPageVisitedEventData.title
FirefoxPlacesPageVisitedEventData.typed
FirefoxPlacesPageVisitedEventData.url
FirefoxPlacesPageVisitedEventData.visit_count
FirefoxPlacesPageVisitedEventData.visit_type
FirefoxPlacesPageVisitedEventData.DATA_TYPE
FirefoxPlacesPageVisitedEventData.__init__()
- plaso.parsers.sqlite_plugins.gdrive module
GoogleDrivePlugin
GoogleDrivePlugin.CLOUD_PATH_CACHE_QUERY
GoogleDrivePlugin.DATA_FORMAT
GoogleDrivePlugin.GetCloudPath()
GoogleDrivePlugin.GetLocalPath()
GoogleDrivePlugin.LOCAL_PATH_CACHE_QUERY
GoogleDrivePlugin.NAME
GoogleDrivePlugin.ParseCloudEntryRow()
GoogleDrivePlugin.ParseLocalEntryRow()
GoogleDrivePlugin.QUERIES
GoogleDrivePlugin.REQUIRED_STRUCTURE
GoogleDrivePlugin.SCHEMAS
GoogleDriveSnapshotCloudEntryEventData
GoogleDriveSnapshotCloudEntryEventData.creation_time
GoogleDriveSnapshotCloudEntryEventData.doc_type
GoogleDriveSnapshotCloudEntryEventData.modification_time
GoogleDriveSnapshotCloudEntryEventData.path
GoogleDriveSnapshotCloudEntryEventData.query
GoogleDriveSnapshotCloudEntryEventData.shared
GoogleDriveSnapshotCloudEntryEventData.size
GoogleDriveSnapshotCloudEntryEventData.url
GoogleDriveSnapshotCloudEntryEventData.DATA_TYPE
GoogleDriveSnapshotCloudEntryEventData.__init__()
GoogleDriveSnapshotLocalEntryEventData
- plaso.parsers.sqlite_plugins.imessage module
IMessageEventData
IMessageEventData.attachment_location
IMessageEventData.client_version
IMessageEventData.creation_time
IMessageEventData.imessage_id
IMessageEventData.message_type
IMessageEventData.offset
IMessageEventData.query
IMessageEventData.read_receipt
IMessageEventData.service
IMessageEventData.text
IMessageEventData.DATA_TYPE
IMessageEventData.__init__()
IMessagePlugin
- plaso.parsers.sqlite_plugins.interface module
- plaso.parsers.sqlite_plugins.ios_datausage module
IOSDatausageEventData
IOSDatausageEventData.bundle_identifier
IOSDatausageEventData.process_name
IOSDatausageEventData.start_time
IOSDatausageEventData.wifi_in
IOSDatausageEventData.wifi_out
IOSDatausageEventData.wireless_wan_in
IOSDatausageEventData.wireless_wan_out
IOSDatausageEventData.DATA_TYPE
IOSDatausageEventData.__init__()
IOSDatausagePlugin
- plaso.parsers.sqlite_plugins.ios_kik module
- plaso.parsers.sqlite_plugins.ios_netusage module
IOSNetusagePlugin
IOSNetusageProcessEventData
IOSNetusageProcessEventData.process_name
IOSNetusageProcessEventData.start_time
IOSNetusageProcessEventData.wifi_in
IOSNetusageProcessEventData.wifi_out
IOSNetusageProcessEventData.wired_in
IOSNetusageProcessEventData.wired_out
IOSNetusageProcessEventData.wireless_wan_in
IOSNetusageProcessEventData.wireless_wan_out
IOSNetusageProcessEventData.DATA_TYPE
IOSNetusageProcessEventData.__init__()
IOSNetusageRouteEventData
IOSNetusageRouteEventData.bytes_in
IOSNetusageRouteEventData.bytes_out
IOSNetusageRouteEventData.network_identifier
IOSNetusageRouteEventData.network_signature
IOSNetusageRouteEventData.network_type
IOSNetusageRouteEventData.start_time
IOSNetusageRouteEventData.DATA_TYPE
IOSNetusageRouteEventData.__init__()
- plaso.parsers.sqlite_plugins.ios_powerlog module
IOSPowerlogApplicationUsageEventData
IOSPowerlogApplicationUsageEventData.background_time
IOSPowerlogApplicationUsageEventData.bundle_identifier
IOSPowerlogApplicationUsageEventData.screen_on_time
IOSPowerlogApplicationUsageEventData.start_time
IOSPowerlogApplicationUsageEventData.DATA_TYPE
IOSPowerlogApplicationUsageEventData.__init__()
IOSPowerlogApplicationUsagePlugin
IOSPowerlogApplicationUsagePlugin.DATA_FORMAT
IOSPowerlogApplicationUsagePlugin.NAME
IOSPowerlogApplicationUsagePlugin.ParseApplicationRunTime()
IOSPowerlogApplicationUsagePlugin.QUERIES
IOSPowerlogApplicationUsagePlugin.REQUIRED_STRUCTURE
IOSPowerlogApplicationUsagePlugin.REQUIRES_SCHEMA_MATCH
IOSPowerlogApplicationUsagePlugin.SCHEMAS
- plaso.parsers.sqlite_plugins.ios_screentime module
IOSScreenTimeEventData
IOSScreenTimeEventData.bundle_identifier
IOSScreenTimeEventData.device_identifier
IOSScreenTimeEventData.device_name
IOSScreenTimeEventData.domain
IOSScreenTimeEventData.start_time
IOSScreenTimeEventData.total_time
IOSScreenTimeEventData.user_family_name
IOSScreenTimeEventData.user_given_name
IOSScreenTimeEventData.DATA_TYPE
IOSScreenTimeEventData.__init__()
IOSScreenTimePlugin
- plaso.parsers.sqlite_plugins.ios_twitter module
IOSTwitterContactEventData
IOSTwitterContactEventData.creation_time
IOSTwitterContactEventData.description
IOSTwitterContactEventData.followers_count
IOSTwitterContactEventData.following_count
IOSTwitterContactEventData.following
IOSTwitterContactEventData.location
IOSTwitterContactEventData.modification_time
IOSTwitterContactEventData.name
IOSTwitterContactEventData.profile_url
IOSTwitterContactEventData.query
IOSTwitterContactEventData.screen_name
IOSTwitterContactEventData.url
IOSTwitterContactEventData.DATA_TYPE
IOSTwitterContactEventData.__init__()
IOSTwitterPlugin
IOSTwitterStatusEventData
IOSTwitterStatusEventData.creation_time
IOSTwitterStatusEventData.favorite_count
IOSTwitterStatusEventData.favorited
IOSTwitterStatusEventData.modification_time
IOSTwitterStatusEventData.name
IOSTwitterStatusEventData.query
IOSTwitterStatusEventData.retweet_count
IOSTwitterStatusEventData.text
IOSTwitterStatusEventData.user_identifier
IOSTwitterStatusEventData.DATA_TYPE
IOSTwitterStatusEventData.__init__()
- plaso.parsers.sqlite_plugins.kodi module
- plaso.parsers.sqlite_plugins.ls_quarantine module
- plaso.parsers.sqlite_plugins.mackeeper_cache module
MacKeeperCacheEventData
MacKeeperCacheEventData.added_time
MacKeeperCacheEventData.description
MacKeeperCacheEventData.event_type
MacKeeperCacheEventData.offset
MacKeeperCacheEventData.query
MacKeeperCacheEventData.record_id
MacKeeperCacheEventData.room
MacKeeperCacheEventData.text
MacKeeperCacheEventData.url
MacKeeperCacheEventData.user_name
MacKeeperCacheEventData.user_sid
MacKeeperCacheEventData.DATA_TYPE
MacKeeperCacheEventData.__init__()
MacKeeperCachePlugin
- plaso.parsers.sqlite_plugins.macos_appusage module
MacOSApplicationUsageEventData
MacOSApplicationUsageEventData.application
MacOSApplicationUsageEventData.application_version
MacOSApplicationUsageEventData.bundle_identifier
MacOSApplicationUsageEventData.count
MacOSApplicationUsageEventData.event
MacOSApplicationUsageEventData.last_used_time
MacOSApplicationUsageEventData.query
MacOSApplicationUsageEventData.DATA_TYPE
MacOSApplicationUsageEventData.__init__()
MacOSApplicationUsagePlugin
- plaso.parsers.sqlite_plugins.macos_document_versions module
MacOSDocumentVersionsEventData
MacOSDocumentVersionsEventData.creation_time
MacOSDocumentVersionsEventData.last_seen_time
MacOSDocumentVersionsEventData.name
MacOSDocumentVersionsEventData.path
MacOSDocumentVersionsEventData.query
MacOSDocumentVersionsEventData.user_sid
MacOSDocumentVersionsEventData.version_path
MacOSDocumentVersionsEventData.DATA_TYPE
MacOSDocumentVersionsEventData.__init__()
MacOSDocumentVersionsPlugin
- plaso.parsers.sqlite_plugins.macos_knowledgec module
MacOSKnowledgeCApplicationEventData
MacOSKnowledgeCApplicationEventData.bundle_identifier
MacOSKnowledgeCApplicationEventData.creation_time
MacOSKnowledgeCApplicationEventData.duration
MacOSKnowledgeCApplicationEventData.end_time
MacOSKnowledgeCApplicationEventData.start_time
MacOSKnowledgeCApplicationEventData.DATA_TYPE
MacOSKnowledgeCApplicationEventData.__init__()
MacOSKnowledgeCPlugin
MacOSKnowledgeCSafariEventData
MacOSKnowledgeCSafariEventData.bundle_identifier
MacOSKnowledgeCSafariEventData.creation_time
MacOSKnowledgeCSafariEventData.duration
MacOSKnowledgeCSafariEventData.end_time
MacOSKnowledgeCSafariEventData.start_time
MacOSKnowledgeCSafariEventData.title
MacOSKnowledgeCSafariEventData.url
MacOSKnowledgeCSafariEventData.DATA_TYPE
MacOSKnowledgeCSafariEventData.__init__()
- plaso.parsers.sqlite_plugins.macos_notes module
- plaso.parsers.sqlite_plugins.macos_notification_center module
MacOSNotificationCenterEventData
MacOSNotificationCenterEventData.body
MacOSNotificationCenterEventData.bundle_name
MacOSNotificationCenterEventData.creation_time
MacOSNotificationCenterEventData.presented
MacOSNotificationCenterEventData.subtitle
MacOSNotificationCenterEventData.title
MacOSNotificationCenterEventData.DATA_TYPE
MacOSNotificationCenterEventData.__init__()
MacOSNotificationCenterPlugin
- plaso.parsers.sqlite_plugins.macos_tcc module
- plaso.parsers.sqlite_plugins.safari module
SafariHistoryPageVisitedEventData
SafariHistoryPageVisitedEventData.host
SafariHistoryPageVisitedEventData.last_visited_time
SafariHistoryPageVisitedEventData.offset
SafariHistoryPageVisitedEventData.query
SafariHistoryPageVisitedEventData.title
SafariHistoryPageVisitedEventData.url
SafariHistoryPageVisitedEventData.visit_count
SafariHistoryPageVisitedEventData.was_http_non_get
SafariHistoryPageVisitedEventData.DATA_TYPE
SafariHistoryPageVisitedEventData.__init__()
SafariHistoryPluginSqlite
- plaso.parsers.sqlite_plugins.skype module
SkypeAccountEventData
SkypeAccountEventData.authentication_request_time
SkypeAccountEventData.authentication_request_sent_time
SkypeAccountEventData.country
SkypeAccountEventData.display_name
SkypeAccountEventData.email
SkypeAccountEventData.last_online_time
SkypeAccountEventData.last_used_time
SkypeAccountEventData.mood_change_time
SkypeAccountEventData.offset
SkypeAccountEventData.profile_change_time
SkypeAccountEventData.query
SkypeAccountEventData.username
SkypeAccountEventData.DATA_TYPE
SkypeAccountEventData.__init__()
SkypeCallEventData
SkypeCallEventData.attempt_time
SkypeCallEventData.call_type
SkypeCallEventData.dst_call
SkypeCallEventData.duration
SkypeCallEventData.end_time
SkypeCallEventData.offset
SkypeCallEventData.query
SkypeCallEventData.src_call
SkypeCallEventData.start_time
SkypeCallEventData.user_start_call
SkypeCallEventData.video_conference
SkypeCallEventData.DATA_TYPE
SkypeCallEventData.__init__()
SkypeChatEventData
SkypePlugin
SkypePlugin.DATA_FORMAT
SkypePlugin.NAME
SkypePlugin.ParseAccountInformation()
SkypePlugin.ParseCall()
SkypePlugin.ParseChat()
SkypePlugin.ParseFileTransfer()
SkypePlugin.ParseSMS()
SkypePlugin.QUERIES
SkypePlugin.QUERY_DEST_FROM_TRANSFER
SkypePlugin.QUERY_SOURCE_FROM_TRANSFER
SkypePlugin.REQUIRED_STRUCTURE
SkypePlugin.SCHEMAS
SkypeSMSEventData
SkypeTransferFileEventData
SkypeTransferFileEventData.accept_time
SkypeTransferFileEventData.destination
SkypeTransferFileEventData.end_time
SkypeTransferFileEventData.offset
SkypeTransferFileEventData.query
SkypeTransferFileEventData.source
SkypeTransferFileEventData.start_time
SkypeTransferFileEventData.transfer_status
SkypeTransferFileEventData.transferred_filename
SkypeTransferFileEventData.transferred_filepath
SkypeTransferFileEventData.transferred_filesize
SkypeTransferFileEventData.DATA_TYPE
SkypeTransferFileEventData.__init__()
- plaso.parsers.sqlite_plugins.windows_eventtranscript module
EventTranscriptPlugin
WindowsEventTranscriptEventData
WindowsEventTranscriptEventData.application_name
WindowsEventTranscriptEventData.application_root_directory
WindowsEventTranscriptEventData.application_version
WindowsEventTranscriptEventData.compressed_payload_size
WindowsEventTranscriptEventData.event_keywords
WindowsEventTranscriptEventData.event_name_hash
WindowsEventTranscriptEventData.event_name
WindowsEventTranscriptEventData.friendly_logging_binary_name
WindowsEventTranscriptEventData.ikey
WindowsEventTranscriptEventData.is_core
WindowsEventTranscriptEventData.logging_binary_name
WindowsEventTranscriptEventData.name
WindowsEventTranscriptEventData.producer_identifier
WindowsEventTranscriptEventData.provider_group_identifier
WindowsEventTranscriptEventData.recorded_time
WindowsEventTranscriptEventData.user_identifier
WindowsEventTranscriptEventData.version
WindowsEventTranscriptEventData.DATA_TYPE
WindowsEventTranscriptEventData.__init__()
- plaso.parsers.sqlite_plugins.windows_push_notification module
WindowsPushNotificationEventData
WindowsPushNotificationEventData.arrival_time
WindowsPushNotificationEventData.boot_time
WindowsPushNotificationEventData.expiration_time
WindowsPushNotificationEventData.handler_identifier
WindowsPushNotificationEventData.notification_type
WindowsPushNotificationEventData.payload
WindowsPushNotificationEventData.DATA_TYPE
WindowsPushNotificationEventData.__init__()
WindowsPushNotificationHandlerEventData
WindowsPushNotificationHandlerEventData.creation_time
WindowsPushNotificationHandlerEventData.handler_type
WindowsPushNotificationHandlerEventData.identifier
WindowsPushNotificationHandlerEventData.modification_time
WindowsPushNotificationHandlerEventData.service_identifier
WindowsPushNotificationHandlerEventData.DATA_TYPE
WindowsPushNotificationHandlerEventData.__init__()
WindowsPushNotificationPlugin
WindowsPushNotificationPlugin.DATA_FORMAT
WindowsPushNotificationPlugin.NAME
WindowsPushNotificationPlugin.ParseNotificationHandlerRow()
WindowsPushNotificationPlugin.ParseNotificationRow()
WindowsPushNotificationPlugin.QUERIES
WindowsPushNotificationPlugin.REQUIRED_STRUCTURE
WindowsPushNotificationPlugin.SCHEMAS
- plaso.parsers.sqlite_plugins.windows_timeline module
WindowsTimelineGenericEventData
WindowsTimelinePlugin
WindowsTimelineUserEngagedEventData
WindowsTimelineUserEngagedEventData.active_duration_seconds
WindowsTimelineUserEngagedEventData.package_identifier
WindowsTimelineUserEngagedEventData.reporting_app
WindowsTimelineUserEngagedEventData.start_time
WindowsTimelineUserEngagedEventData.DATA_TYPE
WindowsTimelineUserEngagedEventData.__init__()
- plaso.parsers.sqlite_plugins.zeitgeist module
- Module contents
- plaso.parsers.text_plugins package
- Submodules
- plaso.parsers.text_plugins.android_logcat module
AndroidLogcatEventData
AndroidLogcatEventData.component_tag
AndroidLogcatEventData.file_offset
AndroidLogcatEventData.message
AndroidLogcatEventData.pid
AndroidLogcatEventData.priority
AndroidLogcatEventData.recorded_time
AndroidLogcatEventData.thread_identifier
AndroidLogcatEventData.user_identifier
AndroidLogcatEventData.DATA_TYPE
AndroidLogcatEventData.__init__()
AndroidLogcatTextPlugin
- plaso.parsers.text_plugins.apache_access module
ApacheAccessLogEventData
ApacheAccessLogEventData.http_request_referer
ApacheAccessLogEventData.http_request
ApacheAccessLogEventData.http_request_user_agent
ApacheAccessLogEventData.http_response_bytes
ApacheAccessLogEventData.http_response_code
ApacheAccessLogEventData.ip_address
ApacheAccessLogEventData.port_number
ApacheAccessLogEventData.recorded_time
ApacheAccessLogEventData.remote_name
ApacheAccessLogEventData.server_name
ApacheAccessLogEventData.user_name
ApacheAccessLogEventData.DATA_TYPE
ApacheAccessLogEventData.__init__()
ApacheAccessLogTextPlugin
- plaso.parsers.text_plugins.apt_history module
- plaso.parsers.text_plugins.aws_elb_access module
AWSELBEventData
AWSELBEventData.actions_executed
AWSELBEventData.alpn_back_end_protocol
AWSELBEventData.alpn_client_preference_list
AWSELBEventData.alpn_front_end_protocol
AWSELBEventData.chosen_cert_arn
AWSELBEventData.chosen_cert_serial
AWSELBEventData.classification
AWSELBEventData.classification_reason
AWSELBEventData.connection_duration
AWSELBEventData.destination_group_arn
AWSELBEventData.destination_ip_address
AWSELBEventData.destination_list
AWSELBEventData.destination_port
AWSELBEventData.destination_processing_duration
AWSELBEventData.destination_status_code
AWSELBEventData.destination_status_code_list
AWSELBEventData.domain_name
AWSELBEventData.error_reason
AWSELBEventData.handshake_duration
AWSELBEventData.incoming_tls_alert
AWSELBEventData.listener
AWSELBEventData.matched_rule_priority
AWSELBEventData.received_bytes
AWSELBEventData.redirect_url
AWSELBEventData.request_processing_duration
AWSELBEventData.request_time
AWSELBEventData.request_type
AWSELBEventData.resource_identifier
AWSELBEventData.response_processing_duration
AWSELBEventData.response_time
AWSELBEventData.sent_bytes
AWSELBEventData.ssl_cipher
AWSELBEventData.ssl_protocol
AWSELBEventData.source_ip_address
AWSELBEventData.source_port
AWSELBEventData.tls_cipher
AWSELBEventData.tls_named_group
AWSELBEventData.tls_protocol_version
AWSELBEventData.trace_identifier
AWSELBEventData.user_agent
AWSELBEventData.version
AWSELBEventData.DATA_TYPE
AWSELBEventData.__init__()
AWSELBTextPlugin
- plaso.parsers.text_plugins.bash_history module
- plaso.parsers.text_plugins.confluence_access module
ConfluenceAccessEventData
ConfluenceAccessEventData.forwarded_for
ConfluenceAccessEventData.http_request_method
ConfluenceAccessEventData.http_request_referer
ConfluenceAccessEventData.http_request_uri
ConfluenceAccessEventData.http_request_user_agent
ConfluenceAccessEventData.http_response_bytes
ConfluenceAccessEventData.http_response_code
ConfluenceAccessEventData.http_version
ConfluenceAccessEventData.process_duration
ConfluenceAccessEventData.recorded_time
ConfluenceAccessEventData.remote_name
ConfluenceAccessEventData.thread_name
ConfluenceAccessEventData.user_name
ConfluenceAccessEventData.DATA_TYPE
ConfluenceAccessEventData.__init__()
ConfluenceAccessTextPlugin
- plaso.parsers.text_plugins.cri module
- plaso.parsers.text_plugins.dpkg module
- plaso.parsers.text_plugins.gdrive_synclog module
GoogleDriveSyncLogEventData
GoogleDriveSyncLogEventData.added_time
GoogleDriveSyncLogEventData.level
GoogleDriveSyncLogEventData.message
GoogleDriveSyncLogEventData.process_identifier
GoogleDriveSyncLogEventData.source_code
GoogleDriveSyncLogEventData.thread
GoogleDriveSyncLogEventData.DATA_TYPE
GoogleDriveSyncLogEventData.__init__()
GoogleDriveSyncLogTextPlugin
GoogleDriveSyncLogTextPlugin.CheckRequiredFormat()
GoogleDriveSyncLogTextPlugin.DATA_FORMAT
GoogleDriveSyncLogTextPlugin.ENCODING
GoogleDriveSyncLogTextPlugin.NAME
GoogleDriveSyncLogTextPlugin.VERIFICATION_GRAMMAR
GoogleDriveSyncLogTextPlugin.VERIFICATION_LITERALS
GoogleDriveSyncLogTextPlugin.__init__()
- plaso.parsers.text_plugins.google_logging module
- plaso.parsers.text_plugins.iis module
IISEventData
IISEventData.cs_cookie
IISEventData.cs_host
IISEventData.cs_referrer
IISEventData.cs_uri_query
IISEventData.cs_username
IISEventData.dest_ip
IISEventData.dest_port
IISEventData.http_method
IISEventData.http_status
IISEventData.last_written_time
IISEventData.protocol_version
IISEventData.received_bytes
IISEventData.requested_uri_stem
IISEventData.s_computername
IISEventData.sc_substatus
IISEventData.sc_win32_status
IISEventData.sent_bytes
IISEventData.source_ip
IISEventData.s_sitename
IISEventData.time_taken
IISEventData.user_agent
IISEventData.DATA_TYPE
IISEventData.__init__()
WinIISTextPlugin
- plaso.parsers.text_plugins.interface module
- plaso.parsers.text_plugins.ios_lockdownd module
- plaso.parsers.text_plugins.ios_logd module
- plaso.parsers.text_plugins.ios_sysdiag_log module
- plaso.parsers.text_plugins.macos_appfirewall module
MacOSAppFirewallLogEventData
MacOSAppFirewallLogEventData.action
MacOSAppFirewallLogEventData.added_time
MacOSAppFirewallLogEventData.agent
MacOSAppFirewallLogEventData.computer_name
MacOSAppFirewallLogEventData.process_name
MacOSAppFirewallLogEventData.status
MacOSAppFirewallLogEventData.DATA_TYPE
MacOSAppFirewallLogEventData.__init__()
MacOSAppFirewallTextPlugin
- plaso.parsers.text_plugins.macos_launchd module
- plaso.parsers.text_plugins.macos_securityd module
MacOSSecuritydLogEventData
MacOSSecuritydLogEventData.added_time
MacOSSecuritydLogEventData.caller
MacOSSecuritydLogEventData.facility
MacOSSecuritydLogEventData.level
MacOSSecuritydLogEventData.message
MacOSSecuritydLogEventData.security_api
MacOSSecuritydLogEventData.sender
MacOSSecuritydLogEventData.sender_pid
MacOSSecuritydLogEventData.DATA_TYPE
MacOSSecuritydLogEventData.__init__()
MacOSSecuritydLogTextPlugin
- plaso.parsers.text_plugins.macos_wifi module
- plaso.parsers.text_plugins.popcontest module
PopularityContestEventData
PopularityContestSessionEventData
PopularityContestSessionEventData.details
PopularityContestSessionEventData.end_time
PopularityContestSessionEventData.host_identifier
PopularityContestSessionEventData.session
PopularityContestSessionEventData.start_time
PopularityContestSessionEventData.DATA_TYPE
PopularityContestSessionEventData.__init__()
PopularityContestTextPlugin
- plaso.parsers.text_plugins.postgresql module
- plaso.parsers.text_plugins.powershell_transcript module
PowerShellTranscriptLogEventData
PowerShellTranscriptLogEventData.build_version
PowerShellTranscriptLogEventData.clr_version
PowerShellTranscriptLogEventData.commands
PowerShellTranscriptLogEventData.compatible_versions
PowerShellTranscriptLogEventData.configuration_name
PowerShellTranscriptLogEventData.edition
PowerShellTranscriptLogEventData.host_application
PowerShellTranscriptLogEventData.machine
PowerShellTranscriptLogEventData.process_identifier
PowerShellTranscriptLogEventData.remoting_protocol_version
PowerShellTranscriptLogEventData.runas_user
PowerShellTranscriptLogEventData.serialization_version
PowerShellTranscriptLogEventData.start_time
PowerShellTranscriptLogEventData.username
PowerShellTranscriptLogEventData.version
PowerShellTranscriptLogEventData.ws_man_stack_version
PowerShellTranscriptLogEventData.DATA_TYPE
PowerShellTranscriptLogEventData.__init__()
PowerShellTranscriptLogTextPlugin
PowerShellTranscriptLogTextPlugin.CheckRequiredFormat()
PowerShellTranscriptLogTextPlugin.DATA_FORMAT
PowerShellTranscriptLogTextPlugin.ENCODING
PowerShellTranscriptLogTextPlugin.NAME
PowerShellTranscriptLogTextPlugin.VERIFICATION_GRAMMAR
PowerShellTranscriptLogTextPlugin.VERIFICATION_LITERALS
PowerShellTranscriptLogTextPlugin.__init__()
- plaso.parsers.text_plugins.santa module
SantaExecutionEventData
SantaExecutionEventData.action
SantaExecutionEventData.certificate_common_name
SantaExecutionEventData.certificate_hash
SantaExecutionEventData.decision
SantaExecutionEventData.gid
SantaExecutionEventData.group
SantaExecutionEventData.last_run_time
SantaExecutionEventData.long_reason
SantaExecutionEventData.mode
SantaExecutionEventData.pid
SantaExecutionEventData.pid_version
SantaExecutionEventData.ppid
SantaExecutionEventData.process_arguments
SantaExecutionEventData.process_hash
SantaExecutionEventData.process_path
SantaExecutionEventData.reason
SantaExecutionEventData.uid
SantaExecutionEventData.user
SantaExecutionEventData.DATA_TYPE
SantaExecutionEventData.__init__()
SantaFileSystemEventData
SantaFileSystemEventData.action
SantaFileSystemEventData.file_new_path
SantaFileSystemEventData.file_path
SantaFileSystemEventData.gid
SantaFileSystemEventData.group
SantaFileSystemEventData.last_written_time
SantaFileSystemEventData.pid
SantaFileSystemEventData.pid_version
SantaFileSystemEventData.ppid
SantaFileSystemEventData.process_path
SantaFileSystemEventData.process
SantaFileSystemEventData.uid
SantaFileSystemEventData.user
SantaFileSystemEventData.DATA_TYPE
SantaFileSystemEventData.__init__()
SantaMountEventData
SantaMountEventData.action
SantaMountEventData.appearance_time
SantaMountEventData.bsd_name
SantaMountEventData.bus
SantaMountEventData.dmg_path
SantaMountEventData.fs
SantaMountEventData.last_written_time
SantaMountEventData.model
SantaMountEventData.mount
SantaMountEventData.serial
SantaMountEventData.volume
SantaMountEventData.DATA_TYPE
SantaMountEventData.__init__()
SantaProcessExitEventData
SantaProcessExitEventData.action
SantaProcessExitEventData.exit_time
SantaProcessExitEventData.gid
SantaProcessExitEventData.pid
SantaProcessExitEventData.pid_version
SantaProcessExitEventData.ppid
SantaProcessExitEventData.uid
SantaProcessExitEventData.DATA_TYPE
SantaProcessExitEventData.__init__()
SantaTextPlugin
- plaso.parsers.text_plugins.sccm module
- plaso.parsers.text_plugins.selinux module
- plaso.parsers.text_plugins.setupapi module
- plaso.parsers.text_plugins.skydrivelog module
- plaso.parsers.text_plugins.snort_fastlog module
SnortFastAlertEventData
SnortFastAlertEventData.classification
SnortFastAlertEventData.destination_ip
SnortFastAlertEventData.destination_port
SnortFastAlertEventData.last_written_time
SnortFastAlertEventData.message
SnortFastAlertEventData.priority
SnortFastAlertEventData.rule_identifier
SnortFastAlertEventData.source_ip
SnortFastAlertEventData.source_port
SnortFastAlertEventData.DATA_TYPE
SnortFastAlertEventData.__init__()
SnortFastLogTextPlugin
- plaso.parsers.text_plugins.sophos_av module
- plaso.parsers.text_plugins.syslog module
- plaso.parsers.text_plugins.teamviewer module
TeamViewerApplicationEventData
TeamViewerApplicationLogTextPlugin
TeamViewerConnectionsIncomingEventData
TeamViewerConnectionsIncomingEventData.activity_type
TeamViewerConnectionsIncomingEventData.connection_identifier
TeamViewerConnectionsIncomingEventData.display_name
TeamViewerConnectionsIncomingEventData.end_time
TeamViewerConnectionsIncomingEventData.local_account
TeamViewerConnectionsIncomingEventData.source_identifier
TeamViewerConnectionsIncomingEventData.start_time
TeamViewerConnectionsIncomingEventData.DATA_TYPE
TeamViewerConnectionsIncomingEventData.__init__()
TeamViewerConnectionsIncomingLogTextPlugin
TeamViewerConnectionsOutgoingEventData
TeamViewerConnectionsOutgoingEventData.activity_type
TeamViewerConnectionsOutgoingEventData.connection_identifier
TeamViewerConnectionsOutgoingEventData.destination_identifier
TeamViewerConnectionsOutgoingEventData.end_time
TeamViewerConnectionsOutgoingEventData.local_account
TeamViewerConnectionsOutgoingEventData.start_time
TeamViewerConnectionsOutgoingEventData.DATA_TYPE
TeamViewerConnectionsOutgoingEventData.__init__()
TeamViewerConnectionsOutgoingLogTextPlugin
- plaso.parsers.text_plugins.viminfo module
- plaso.parsers.text_plugins.vsftpd module
- plaso.parsers.text_plugins.winfirewall module
WinFirewallEventData
WinFirewallEventData.action
WinFirewallEventData.destination_ip
WinFirewallEventData.destination_port
WinFirewallEventData.icmp_code
WinFirewallEventData.icmp_type
WinFirewallEventData.information
WinFirewallEventData.last_written_time
WinFirewallEventData.packet_size
WinFirewallEventData.path
WinFirewallEventData.protocol
WinFirewallEventData.source_ip
WinFirewallEventData.source_port
WinFirewallEventData.tcp_ack
WinFirewallEventData.tcp_flags
WinFirewallEventData.tcp_sequence_number
WinFirewallEventData.tcp_window_size
WinFirewallEventData.DATA_TYPE
WinFirewallEventData.__init__()
WinFirewallLogTextPlugin
- plaso.parsers.text_plugins.xchatlog module
- plaso.parsers.text_plugins.xchatscrollback module
- plaso.parsers.text_plugins.zsh_extended_history module
- Module contents
- plaso.parsers.winreg_plugins package
- Submodules
- plaso.parsers.winreg_plugins.amcache module
AMCacheFileEventData
AMCacheFileEventData.company_name
AMCacheFileEventData.file_creation_time
AMCacheFileEventData.file_description
AMCacheFileEventData.file_modification_time
AMCacheFileEventData.file_reference
AMCacheFileEventData.file_size
AMCacheFileEventData.file_version
AMCacheFileEventData.full_path
AMCacheFileEventData.installation_time
AMCacheFileEventData.language_code
AMCacheFileEventData.last_written_time
AMCacheFileEventData.link_time
AMCacheFileEventData.msi_installation_time
AMCacheFileEventData.product_name
AMCacheFileEventData.program_identifier
AMCacheFileEventData.sha1
AMCacheFileEventData.DATA_TYPE
AMCacheFileEventData.__init__()
AMCachePlugin
AMCacheProgramEventData
AMCacheProgramEventData.entry_type
AMCacheProgramEventData.file_paths
AMCacheProgramEventData.files
AMCacheProgramEventData.installation_time
AMCacheProgramEventData.language_code
AMCacheProgramEventData.msi_package_code
AMCacheProgramEventData.msi_product_code
AMCacheProgramEventData.name
AMCacheProgramEventData.package_code
AMCacheProgramEventData.product_code
AMCacheProgramEventData.publisher
AMCacheProgramEventData.uninstall_key
AMCacheProgramEventData.version
AMCacheProgramEventData.DATA_TYPE
AMCacheProgramEventData.__init__()
- plaso.parsers.winreg_plugins.appcompatcache module
- plaso.parsers.winreg_plugins.bagmru module
- plaso.parsers.winreg_plugins.bam module
- plaso.parsers.winreg_plugins.ccleaner module
- plaso.parsers.winreg_plugins.default module
- plaso.parsers.winreg_plugins.interface module
- plaso.parsers.winreg_plugins.lfu module
- plaso.parsers.winreg_plugins.mountpoints module
- plaso.parsers.winreg_plugins.mrulist module
- plaso.parsers.winreg_plugins.mrulistex module
- plaso.parsers.winreg_plugins.msie_zones module
- plaso.parsers.winreg_plugins.network_drives module
- plaso.parsers.winreg_plugins.networks module
NetworksWindowsRegistryPlugin
WindowsRegistryNetworkListEventData
WindowsRegistryNetworkListEventData.connection_type
WindowsRegistryNetworkListEventData.creation_time
WindowsRegistryNetworkListEventData.default_gateway_mac
WindowsRegistryNetworkListEventData.description
WindowsRegistryNetworkListEventData.dns_suffix
WindowsRegistryNetworkListEventData.key_path
WindowsRegistryNetworkListEventData.last_connected_time
WindowsRegistryNetworkListEventData.ssid
WindowsRegistryNetworkListEventData.DATA_TYPE
WindowsRegistryNetworkListEventData.__init__()
- plaso.parsers.winreg_plugins.officemru module
- plaso.parsers.winreg_plugins.outlook module
- plaso.parsers.winreg_plugins.programscache module
ExplorerProgramsCacheEventData
ExplorerProgramsCacheEventData.entries
ExplorerProgramsCacheEventData.key_path
ExplorerProgramsCacheEventData.known_folder_identifier
ExplorerProgramsCacheEventData.last_written_time
ExplorerProgramsCacheEventData.value_name
ExplorerProgramsCacheEventData.DATA_TYPE
ExplorerProgramsCacheEventData.__init__()
ExplorerProgramsCacheWindowsRegistryPlugin
- plaso.parsers.winreg_plugins.run module
- plaso.parsers.winreg_plugins.sam_users module
SAMUsersWindowsRegistryEventData
SAMUsersWindowsRegistryEventData.account_rid
SAMUsersWindowsRegistryEventData.comments
SAMUsersWindowsRegistryEventData.fullname
SAMUsersWindowsRegistryEventData.key_path
SAMUsersWindowsRegistryEventData.last_login_time
SAMUsersWindowsRegistryEventData.last_password_set_time
SAMUsersWindowsRegistryEventData.last_written_time
SAMUsersWindowsRegistryEventData.login_count
SAMUsersWindowsRegistryEventData.username
SAMUsersWindowsRegistryEventData.DATA_TYPE
SAMUsersWindowsRegistryEventData.__init__()
SAMUsersWindowsRegistryPlugin
- plaso.parsers.winreg_plugins.services module
ServicesPlugin
WindowsRegistryServiceEventData
WindowsRegistryServiceEventData.error_control
WindowsRegistryServiceEventData.image_path
WindowsRegistryServiceEventData.key_path
WindowsRegistryServiceEventData.last_written_time
WindowsRegistryServiceEventData.name
WindowsRegistryServiceEventData.object_name
WindowsRegistryServiceEventData.service_dll
WindowsRegistryServiceEventData.service_type
WindowsRegistryServiceEventData.start_type
WindowsRegistryServiceEventData.values
WindowsRegistryServiceEventData.values
WindowsRegistryServiceEventData.DATA_TYPE
WindowsRegistryServiceEventData.__init__()
- plaso.parsers.winreg_plugins.shutdown module
- plaso.parsers.winreg_plugins.task_scheduler module
- plaso.parsers.winreg_plugins.terminal_server module
TerminalServerClientConnectionEventData
TerminalServerClientConnectionEventData.entries
TerminalServerClientConnectionEventData.key_path
TerminalServerClientConnectionEventData.last_written_time
TerminalServerClientConnectionEventData.username
TerminalServerClientConnectionEventData.DATA_TYPE
TerminalServerClientConnectionEventData.__init__()
TerminalServerClientMRUEventData
TerminalServerClientMRUPlugin
TerminalServerClientPlugin
- plaso.parsers.winreg_plugins.timezone module
- plaso.parsers.winreg_plugins.typedurls module
- plaso.parsers.winreg_plugins.usb module
- plaso.parsers.winreg_plugins.usbstor module
USBStorDeviceInstanceEventData
USBStorDeviceInstanceEventData.device_last_arrival_time
USBStorDeviceInstanceEventData.device_last_removal_time
USBStorDeviceInstanceEventData.device_type
USBStorDeviceInstanceEventData.display_name
USBStorDeviceInstanceEventData.key_path
USBStorDeviceInstanceEventData.driver_first_installation_time
USBStorDeviceInstanceEventData.driver_last_installation_time
USBStorDeviceInstanceEventData.firmware_time
USBStorDeviceInstanceEventData.product
USBStorDeviceInstanceEventData.revision
USBStorDeviceInstanceEventData.vendor
USBStorDeviceInstanceEventData.DATA_TYPE
USBStorDeviceInstanceEventData.__init__()
USBStorPlugin
- plaso.parsers.winreg_plugins.userassist module
UserAssistPlugin
UserAssistWindowsRegistryEventData
UserAssistWindowsRegistryEventData.application_focus_count
UserAssistWindowsRegistryEventData.application_focus_duration
UserAssistWindowsRegistryEventData.entry_index
UserAssistWindowsRegistryEventData.key_path
UserAssistWindowsRegistryEventData.last_execution_time
UserAssistWindowsRegistryEventData.number_of_executions
UserAssistWindowsRegistryEventData.value_name
UserAssistWindowsRegistryEventData.DATA_TYPE
UserAssistWindowsRegistryEventData.__init__()
UserAssistWindowsRegistryKeyPathFilter
- plaso.parsers.winreg_plugins.windows_version module
WindowsRegistryInstallationEventData
WindowsRegistryInstallationEventData.build_number
WindowsRegistryInstallationEventData.installation_time
WindowsRegistryInstallationEventData.key_path
WindowsRegistryInstallationEventData.owner
WindowsRegistryInstallationEventData.product_name
WindowsRegistryInstallationEventData.service_pack
WindowsRegistryInstallationEventData.version
WindowsRegistryInstallationEventData.DATA_TYPE
WindowsRegistryInstallationEventData.__init__()
WindowsVersionPlugin
- plaso.parsers.winreg_plugins.winlogon module
- plaso.parsers.winreg_plugins.winrar module
- Module contents
Submodules
plaso.parsers.android_app_usage module
Parser for the Android usage history (usage-history.xml) files.
- class plaso.parsers.android_app_usage.AndroidAppUsageEventData(*args: Any, **kwargs: Any)[source]
Bases:
EventData
Android application usage event data.
- component
name of the individual component of the application.
- Type:
str
- last_resume_time
date and time the application was last resumed.
- Type:
dfdatetime.DateTimeValues
- package
name of the Android application.
- Type:
str
- DATA_TYPE = 'android:app_usage'
- class plaso.parsers.android_app_usage.AndroidAppUsageParser[source]
Bases:
FileObjectParser
Parses the Android usage history (usage-history.xml) file.
- DATA_FORMAT = 'Android usage history (usage-history.xml) file'
- NAME = 'android_app_usage'
- ParseFileObject(parser_mediator, file_object)[source]
Parses an Android usage-history file-like object.
- Parameters:
parser_mediator (ParserMediator) – mediates interactions between parsers and other components, such as storage and dfvfs.
file_object (dfvfs.FileIO) – file-like object.
- Raises:
WrongParser – when the file cannot be parsed.
plaso.parsers.asl module
The Apple System Log (ASL) file parser.
- class plaso.parsers.asl.ASLEventData(*args: Any, **kwargs: Any)[source]
Bases:
EventData
Apple System Log (ASL) event data.
- computer_name
name of the host.
- Type:
str
- extra_information
extra fields associated to the event.
- Type:
str
- facility
facility.
- Type:
str
- group_identifier
group identifier (GID).
- Type:
int
- level
level of criticality of the event.
- Type:
str
- message
message of the event.
- Type:
str
- message_identifier
message identifier.
- Type:
int
- process_identifier
process identifier (PID).
- Type:
int
- read_group_identifier
the group identifier that can read this file, where -1 represents all.
- Type:
int
- read_user_identifier
user identifier that can read this file, where -1 represents all.
- Type:
int
- record_position
position of the event record.
- Type:
int
- sender
sender or process that created the event.
- Type:
str
- user_identifier
user identifier (UID).
- Type:
int
- written_time
entry written date and time.
- Type:
dfdatetime.DateTimeValues
- DATA_TYPE = 'macos:asl:entry'
- class plaso.parsers.asl.ASLFileEventData(*args: Any, **kwargs: Any)[source]
Bases:
EventData
Apple System Log (ASL) file event data.
- creation_time
creation date and time.
- Type:
dfdatetime.DateTimeValues
- format_version
ASL file format version.
- Type:
int
- is_dirty
True if the last log entry offset does not match value in file header and the file is considered dirty.
- Type:
bool
- DATA_TYPE = 'macos:asl:file'
- class plaso.parsers.asl.ASLParser[source]
Bases:
FileObjectParser
,DtFabricHelper
Parser for Apple System Log (ASL) files.
- DATA_FORMAT = 'Apple System Log (ASL) file'
- classmethod GetFormatSpecification()[source]
Retrieves the format specification.
- Returns:
format specification.
- Return type:
- NAME = 'asl_log'
- ParseFileObject(parser_mediator, file_object)[source]
Parses an ASL file-like object.
- Parameters:
parser_mediator (ParserMediator) – mediates interactions between parsers and other components, such as storage and dfVFS.
file_object (dfvfs.FileIO) – file-like object.
- Raises:
WrongParser – when the file cannot be parsed.
plaso.parsers.bencode_parser module
Parser for bencoded files.
- class plaso.parsers.bencode_parser.BencodeFile[source]
Bases:
object
Bencode file.
- GetValues()[source]
Retrieves the values in the root of the bencode file.
- Returns:
values.
- Return type:
- IsEmpty()[source]
Determines if the bencode file has no values (is empty).
- Returns:
True if the bencode file is empty, False otherwise.
- Return type:
bool
- Open(file_object)[source]
Opens a bencode file.
- Parameters:
file_object (dfvfs.FileIO) – file-like object.
- Raises:
IOError – if the file-like object cannot be read.
OSError – if the file-like object cannot be read.
ValueError – if the file-like object is missing.
- property keys
names of all the keys.
- Type:
Set[str]
- class plaso.parsers.bencode_parser.BencodeParser[source]
Bases:
FileObjectParser
Parser for bencoded files.
- DATA_FORMAT = 'Bencoded file'
- NAME = 'bencode'
- ParseFileObject(parser_mediator, file_object)[source]
Parses a bencoded file-like object.
- Parameters:
parser_mediator (ParserMediator) – mediates interactions between parsers and other components, such as storage and dfvfs.
file_object (dfvfs.FileIO) – a file-like object.
- Raises:
WrongParser – when the file cannot be parsed.
- class plaso.parsers.bencode_parser.BencodeValues(decoded_values)[source]
Bases:
object
Bencode values.
- GetDateTimeValue(name)[source]
Retrieves a date and time value.
- Parameters:
name (str) – name of the value.
- Returns:
date and time or None if not available.
- Return type:
dfdatetime.PosixTime
plaso.parsers.bodyfile module
Parser for the Sleuthkit (TSK) bodyfile format.
Sleuthkit version 3 format: MD5|name|inode|mode_as_string|UID|GID|size|atime|mtime|ctime|crtime 0|/lost+found|11|d/drwx——|0|0|12288|1337961350|1337961350|1337961350|0
- More information about the format specifications can be read here:
- class plaso.parsers.bodyfile.BodyfileEventData(*args: Any, **kwargs: Any)[source]
Bases:
EventData
Bodyfile event data.
- access_time
file entry last access date and time.
- Type:
dfdatetime.DateTimeValues
- change_time
file entry inode change (or metadata last modification) date and time.
- Type:
dfdatetime.DateTimeValues
- creation_time
file entry creation date and time.
- Type:
dfdatetime.DateTimeValues
- filename
name of the file.
- Type:
str
- group_identifier
group identifier (GID), equivalent to st_gid.
- Type:
int
- inode
“inode” of the file. Note that inode is an overloaded term in the context of a bodyfile and used for MFT entry index values as well.
- Type:
int
- md5
MD5 hash of the file content, formatted as a hexadecimal string.
- Type:
str
- mode_as_string
protection mode.
- Type:
str
- modification_time
file entry last modification date and time.
- Type:
dfdatetime.DateTimeValues
- offset
number of the corresponding line, from which the event data was extracted.
- Type:
int
- owner_identifier
user identifier (UID or SID) of the owner.
- Type:
str
- size
size of the file content.
- Type:
int
- symbolic_link_target
path of the symbolic link target.
- Type:
str
- DATA_TYPE = 'fs:bodyfile:entry'
- class plaso.parsers.bodyfile.BodyfileParser[source]
Bases:
FileObjectParser
SleuthKit bodyfile parser.
- DATA_FORMAT = 'SleuthKit version 3 bodyfile'
- NAME = 'bodyfile'
- ParseFileObject(parser_mediator, file_object)[source]
Parses a bodyfile file-like object.
- Parameters:
parser_mediator (ParserMediator) – mediates interactions between parsers and other components, such as storage and dfVFS.
file_object (dfvfs.FileIO) – file-like object.
- Raises:
WrongParser – when the file cannot be parsed.
plaso.parsers.bsm module
Basic Security Module (BSM) event auditing file parser.
- class plaso.parsers.bsm.BSMEventData(*args: Any, **kwargs: Any)[source]
Bases:
EventData
Basic Security Module (BSM) audit event data.
- event_type
identifier that represents the type of the event.
- Type:
int
- extra_tokens
event extra tokens, which is a list of dictionaries that contain: {token type: {token values}}
- Type:
list[dict[str, dict[str, str]]]
- offset
offset of the BSM record relative to the start of the file, from which the event data was extracted.
- Type:
int
- record_length
record length in bytes (trailer number).
- Type:
int
- return_value
processed return value and exit status.
- Type:
str
- written_time
entry written date and time.
- Type:
dfdatetime.DateTimeValues
- DATA_TYPE = 'bsm:entry'
- class plaso.parsers.bsm.BSMParser[source]
Bases:
FileObjectParser
,DtFabricHelper
Parser for Basic Security Module (BSM) event auditing files.
- DATA_FORMAT = 'Basic Security Module (BSM) event auditing file'
- NAME = 'bsm_log'
- ParseFileObject(parser_mediator, file_object)[source]
Parses a BSM file-like object.
- Parameters:
parser_mediator (ParserMediator) – mediates interactions between parsers and other components, such as storage and dfvfs.
file_object (dfvfs.FileIO) – a file-like object.
- Raises:
WrongParser – when the file cannot be parsed.
plaso.parsers.chrome_cache module
Parser for Google Chrome and Chromium Cache files.
- class plaso.parsers.chrome_cache.CacheAddress(cache_address)[source]
Bases:
object
Chrome cache address.
- block_number
block data file number.
- Type:
int
- block_offset
offset within the block data file.
- Type:
int
- block_size
block size.
- Type:
int
- filename
name of the block data file.
- Type:
str
- value
cache address.
- Type:
int
- FILE_TYPE_BLOCK_1024 = 3
- FILE_TYPE_BLOCK_256 = 2
- FILE_TYPE_BLOCK_4096 = 4
- FILE_TYPE_BLOCK_RANKINGS = 1
- FILE_TYPE_SEPARATE = 0
- class plaso.parsers.chrome_cache.CacheEntry[source]
Bases:
object
Chrome cache entry.
- creation_time
creation time, in number of microseconds since January 1, 1601, 00:00:00 UTC.
- Type:
int
- hash
super fast hash of the key.
- Type:
int
- key
key.
- Type:
bytes
- next
cache address of the next cache entry.
- Type:
int
- original_url
original URL derived from the key.
- Type:
str
- rankings_node
cache address of the rankings node.
- Type:
int
- class plaso.parsers.chrome_cache.ChromeCacheDataBlockFileParser[source]
Bases:
FileObjectParser
,DtFabricHelper
Chrome cache data block file parser.
- ParseCacheEntry(file_object, block_offset)[source]
Parses a cache entry.
- Parameters:
file_object (dfvfs.FileIO) – a file-like object to read from.
block_offset (int) – block offset of the cache entry.
- Returns:
cache entry.
- Return type:
- Raises:
ParseError – if the cache entry cannot be read.