Windows event logs in EVTX format are a key source of telemetry for incident response. They provide evidence of attacker activity on a host and are often the only remaining record of what happened during account compromise, lateral movement, or persistence attempts.
Attackers often try to destroy these logs by clearing them with wevtutil cl, encrypting them, or wiping disks. Ransomware operators increasingly target entire virtual machine disk images, including VDI, VMDK, and VHDX files. The file system of the affected volume may become inaccessible or too badly damaged for standard tools to mount: for example, if the master file table (MFT) has been destroyed or the partition table is missing.
One option is to reconstruct the file system manually by locating lost partitions and recovering deleted files. However, this takes time and may still leave gaps in the event history or severely corrupted EVTX files. This is where carving comes in — a byte-level search for EVTX signatures in raw data from a disk or volume image, a memory dump, a pagefile, or a VSS snapshot. It can recover surviving event data without relying on the file system.
At the Positive Technologies Expert Security Center, our Incident Response team (PT ESC IR) prioritizes automated artifact parsing to detect malicious activity and reconstruct incidents faster. Our processing pipeline is written primarily in Go. We could not find a suitable open-source library that combined EVTX parsing and carving. Existing parsers either crash regularly or consume too much memory, which hinders automation. We developed our own library that parses intact EVTX files, recovers data even when checksums do not match or files are corrupted, and performs event carving from bit-for-bit copies, memory dumps, and virtual disk images.