log2timeline / plaso

Super timeline all the things

Home Page:https://plaso.readthedocs.io

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Add TeamViewer log parser

hur opened this issue · comments

Add a parser for logs created by TeamViewer, a RMM tool that is sometimes used by Threat Actors for lateral movement / C2.

In particular, the it would be good to support the following log files of interest:

  • Connections_incoming.txt - logs incoming TeamViewer connections
  • Connections.txt - logs outgoing TeamViewer connections
  • TeamViewerXX_Logfile.log - General log file containing many types of forensically interesting log entries

Please assign to me.

@hur thanks for taking this on

  • let us know if you need assistance getting started
  • please add test data that can be shared under the license of this project (please not other people's copyrighted material)