diff --git a/README.md b/README.md index d278100..b80259d 100644 --- a/README.md +++ b/README.md @@ -1097,6 +1097,10 @@ _return-to-libc techniques_ williballenthin/EVTXtract EVTXtract recovers and reconstructs fragments of EVTX log files from raw binary data, including unallocated space and memory images. + + williballenthin/process-forest + process-forest is a tool that processes Microsoft Windows EVTX event logs that contain process accounting events and reconstructs the historical process heirarchies. + ### Exploits