[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fxlyV-eTMzGWojkLTr5YLv5asHeLlVH1RS1hJTBVOaOc":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},732,"What key steps are involved in recalculating the CRC checksum after deleting a log entry from an EVTX file?","After deletion, the CRC32 checksum must be recalculated for both the file header (first 120 bytes) and the event records within ElfChunk (from offset 512 to `FreeSpaceOffset`). Additionally, the ElfChunk header checksum is recomputed using a 504-byte buffer that skips the event records data area. The article provides C code for CRC32 calculation and specifies the exact byte ranges needed for each checksum update.","\u003Cp>After deletion, the CRC32 checksum must be recalculated for both the file header (first 120 bytes) and the event records within ElfChunk (from offset 512 to `FreeSpaceOffset`). Additionally, the ElfChunk header checksum is recomputed using a 504-byte buffer that skips the event records data area. The article provides C code for CRC32 calculation and specifies the exact byte ranges needed for each checksum update.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fwindows-xml-event-log-evtx-single-log-deletion-part-2-program-implementation-for-deleting-single-log-records-in-evtx-files\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-key-steps-are-involved-in-recalculating-the-crc-checksum-after-deleting-a-l-1777482041499","CRC32 checksum, file header checksum, ElfChunk checksum, FreeSpaceOffset, event records checksum",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},180,"Windows XML Event Log (EVTX) Single Log Deletion (Part 2) – Program Implementation for Deleting Single Log Records in EVTX Files","windows-xml-event-log-evtx-single-log-deletion-part-2-program-implementation-for-deleting-single-log-records-in-evtx-files","Learn how to delete single log entries from EVTX files with detailed programming steps, including handling intermediate, first, and last log deletions.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The second article in the Windows XML Event Log (EVTX) single log deletion series introduces methods for deleting single log entries from specified EVTX files, addresses multiple design considerations in programming, and provides open-source implementation code.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Approach for deleting single log entries from specified EVTX files\u003C\u002Fli>\u003Cli>Program implementation details\u003C\u002Fli>\u003Cli>Open-source code\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Approach for Deleting Single Log Entries from Specified EVTX Files\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The previous article, 'Windows XML Event Log (EVTX) Single Log Deletion (Part 1) – Deletion Approach and Examples', explained the principles and an example of deleting single log entries from EVTX files by modifying log lengths.\u003C\u002Fp>\u003Cp>The implementation approach is illustrated below:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017237258_0_fa343de00d.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Image from https:\u002F\u002Fblog.fox-it.com\u002F2017\u002F12\u002F08\u002Fdetection-and-recovery-of-nsas-covered-up-tracks\u002F\u003C\u002Fp>\u003Cp>This method is relatively simple to implement, but multiple different scenarios need to be considered:\u003C\u002Fp>\u003Col>\u003Cli>Delete intermediate log\u003C\u002Fli>\u003Cli>Delete the last log\u003C\u002Fli>\u003Cli>Delete the first log\u003C\u002Fli>\u003C\u002Fol>\u003Ch2>0x03 Delete intermediate log\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Method as follows:\u003C\u002Fp>\u003Col>\u003Cli>Decrease the Next record identifier value in the File header by 1\u003C\u002Fli>\u003Cli>Recalculate the Checksum in the File header\u003C\u002Fli>\u003Cli>Recalculate the previous log length, involving 2 positions (offset 4 and the last 4 bytes of the current log)\u003C\u002Fli>\u003Cli>Decrease the Event record identifier of subsequent logs by 1 sequentially\u003C\u002Fli>\u003Cli>Decrease the Last event record number in ElfChuk by 1\u003C\u002Fli>\u003Cli>Decrease the Last event record identifier in ElfChuk by 1\u003C\u002Fli>\u003Cli>Recalculate checksum of Event records in ElfChuk\u003C\u002Fli>\u003Cli>Recalculate checksum in ElfChuk\u003C\u002Fli>\u003C\u002Fol>\u003Cp>In program implementation, the specific details are as follows:\u003C\u002Fp>\u003Ch3>1. Decrement the Next record identifier value in File header by 1\u003C\u002Fh3>\u003Cp>Read log file content\u003C\u002Fp>\u003Cp>Define log file format structure and parse the log file format\u003C\u002Fp>\u003Cp>Decrement Next record identifier value by 1:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>FileHeader-&gt;NextRecordIdentifier = FileHeader-&gt;NextRecordIdentifier-1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Recalculate the Checksum in File header\u003C\u002Fh3>\u003Cp>C code for calculating CRC checksum:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>unsigned int CRC32[256];\u003Cbr>static void init_table()\u003Cbr>{\u003Cbr>\tint i, j;\u003Cbr>\tunsigned int crc;\u003Cbr>\tfor (i = 0; i &lt; 256; i++)\u003Cbr>\t{\u003Cbr>\t\tcrc = i;\u003Cbr>\t\tfor (j = 0; j &lt; 8; j++)\u003Cbr>\t\t{\u003Cbr>\t\t\tif (crc &amp; 1)\u003Cbr>\t\t\t\tcrc = (crc &gt;&gt; 1) ^ 0xEDB88320;\u003Cbr>\t\t\telse\u003Cbr>\t\t\t\tcrc = crc &gt;&gt; 1;\u003Cbr>\t\t}\u003Cbr>\t\tCRC32[i] = crc;\u003Cbr>\t}\u003Cbr>}\u003Cbr>\u003Cbr>unsigned int GetCRC32(unsigned char *buf, int len)\u003Cbr>{\u003Cbr>\tunsigned int ret = 0xFFFFFFFF;\u003Cbr>\tint i;\u003Cbr>\tstatic char init = 0;\u003Cbr>\tif (!init)\u003Cbr>\t{\u003Cbr>\t\tinit_table();\u003Cbr>\t\tinit = 1;\u003Cbr>\t}\u003Cbr>\tfor (i = 0; i &lt; len; i++)\u003Cbr>\t{\u003Cbr>\t\tret = CRC32[((ret &amp; 0xFF) ^ buf[i])] ^ (ret &gt;&gt; 8);\u003Cbr>\t}\u003Cbr>\tret = ~ret;\u003Cbr>\treturn ret;\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Calculate the checksum of the first 120 bytes of the File header\u003C\u002Fp>\u003Cp>Code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>unsigned char *ChecksumBuf = new unsigned char[120];\u003Cbr>memcpy(ChecksumBuf, (PBYTE)elfFilePtr, 120);\u003Cbr>crc32 = GetCRC32(ChecksumBuf, 120);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Recalculate the length of the previous log, involving 2 positions (offset 4 and the last 4 bytes of the current log)\u003C\u002Fh3>\u003Cp>Locate Event Records one by one by searching for the magic string 0x2A 0x2A 0x00 0x00\u003C\u002Fp>\u003Cp>(1) Locate the log to be deleted: CurrentRecord\u003C\u002Fp>\u003Cp>Read the length, i.e., CurrentRecord-&gt;Size\u003C\u002Fp>\u003Cp>(2) Locate the previous log: PrevRecord\u003C\u002Fp>\u003Cp>Read the length, i.e., PrevRecord-&gt;Size\u003C\u002Fp>\u003Cp>Calculate the merged length:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>NewSize = CurrentRecord-&gt;Size + PrevRecord-&gt;Size\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Update the length:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>PrevRecord-&gt;Size = NewSize\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(3) Locate the next log record NextRecord\u003C\u002Fp>\u003Cp>Replace the 4 bytes before the starting point of NextRecord with NewSize:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>*(PULONG)((PBYTE)NextRecord-4) = NewSize\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Decrement the Event record identifier of subsequent logs by 1 sequentially\u003C\u002Fh3>\u003Cp>Traverse subsequent logs, decrementing the Event record identifier by 1 sequentially\u003C\u002Fp>\u003Cp>Two locations need to be modified:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>CurrentRecord-&gt;EventRecordIdentifier = CurrentRecord-&gt;EventRecordIdentifier-1\u003Cbr>CurrentRecord-&gt;Template-&gt;EventRecordIdentifier = CurrentRecord-&gt;Template-&gt;EventRecordIdentifier-1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>5. Decrement the Last event record number in ElfChuk by 1\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ElfChuk-&gt;LastEventRecordNumber = ElfChuk-&gt;LastEventRecordNumber-1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>6. Decrement the Last event record identifier in ElfChuk by 1\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ElfChuk-&gt;LastEventRecordIdentifier = ElfChuk-&gt;LastEventRecordIdentifier-1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>7. Recalculate the Event records checksum in ElfChuk\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>unsigned char *ChecksumBuf = new unsigned char[currentChunk-&gt;FreeSpaceOffset - 512];\u003Cbr>memcpy(ChecksumBuf, (PBYTE)currentChunk+512, currentChunk-&gt;FreeSpaceOffset - 512);\u003Cbr>crc32 = GetCRC32(ChecksumBuf, currentChunk-&gt;FreeSpaceOffset - 512);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>8. Recalculate the Checksum in ElfChuk\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>unsigned char *ChecksumBuf = new unsigned char[504];\u003Cbr>memcpy(ChecksumBuf, (PBYTE)currentChunk, 120);\u003Cbr>memcpy(ChecksumBuf+120, (PBYTE)currentChunk+128, 384);\u003Cbr>crc32 = GetCRC32(ChecksumBuf, 504);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Delete the last log entry\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Deleting the last log entry was demonstrated in the previous article 'Windows XML Event Log (EVTX) Single Log Entry Deletion (Part 1) – Deletion Approach and Example'. The method is essentially the same as deleting a middle log entry.\u003C\u002Fp>\u003Cp>The differences are as follows:\u003C\u002Fp>\u003Col>\u003Cli>The Event record identifier of subsequent logs does not need to be decremented by 1, as there are no subsequent logs.\u003C\u002Fli>\u003Cli>The Last event record data offset in ElfChuk needs to be recalculated.\u003C\u002Fli>\u003C\u002Fol>\u003Cp>The program details are as follows:\u003C\u002Fp>\u003Cp>1. Recalculate the Last event record data offset in ElfChuk\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ElfChuk-&gt;LastEventRecordDataOffset = ElfChuk-&gt;LastEventRecordDataOffset - LastRecord-&gt;Size\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x05 Delete the first log\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The method of modifying log length is not applicable for deleting the first log, because there is no previous log to overwrite the current one\u003C\u002Fp>\u003Cp>If you still want to achieve this using the overwrite length method, further analysis of the log file format is required\u003C\u002Fp>\u003Cp>We know that the content of Event Records is stored in Binary XML format\u003C\u002Fp>\u003Cp>For reference on Binary XML format:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Flibyal\u002Flibevtx\u002Fblob\u002Fmaster\u002Fdocumentation\u002FWindows%20XML%20Event%20Log%20(EVTX).asciidoc#4-binary-xml\u003C\u002Fp>\u003Cp>To merge logs by modifying the Binary XML format content, the following items need to be modified:\u003C\u002Fp>\u003Cul>\u003Cli>Written date and time\u003C\u002Fli>\u003Cli>Template definition Data size\u003C\u002Fli>\u003Cli>Next template definition offset\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This method is also applicable for modifying middle logs and the last log, so understanding the log format means deletion methods are not unique\u003C\u002Fp>\u003Cp>For other implementation details, refer to the open-source code at the following address:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Cp>The code implements reading the specified log file c:\\\\test\\\\Setup.evtx, deleting a single log entry (EventRecordID=14), and saving it as a new log file c:\\\\test\\\\SetupNew.evtx\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>In the implementation details of the code, I referred to the demo code on KanXue, with the address as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fbbs.pediy.com\u002Fthread-219313.htm\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the approach and program implementation details for deleting a single log entry from an evtx file, with open-source code. The method for deleting a single log entry is not unique. Next, multiple methods for deleting a single log entry from the current system will be introduced.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The second article in the Windows XML Event Log (EVTX) single log deletion series introduces methods for deleting single log entries from specified EVTX files, addresses multiple design considerations in programming, and provides open-source implementation code.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Approach for deleting single log entries from specified EVTX files\u003C\u002Fli>\u003Cli>Program implementation details\u003C\u002Fli>\u003Cli>Open-source code\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Approach for Deleting Single Log Entries from Specified EVTX Files\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The previous article, 'Windows XML Event Log (EVTX) Single Log Deletion (Part 1) – Deletion Approach and Examples', explained the principles and an example of deleting single log entries from EVTX files by modifying log lengths.\u003C\u002Fp>\u003Cp>The implementation approach is illustrated below:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017237258_0_fa343de00d-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Image from https:\u002F\u002Fblog.fox-it.com\u002F2017\u002F12\u002F08\u002Fdetection-and-recovery-of-nsas-covered-up-tracks\u002F\u003C\u002Fp>\u003Cp>This method is relatively simple to implement, but multiple different scenarios need to be considered:\u003C\u002Fp>\u003Col>\u003Cli>Delete intermediate log\u003C\u002Fli>\u003Cli>Delete the last log\u003C\u002Fli>\u003Cli>Delete the first log\u003C\u002Fli>\u003C\u002Fol>\u003Ch2>0x03 Delete intermediate log\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Method as follows:\u003C\u002Fp>\u003Col>\u003Cli>Decrease the Next record identifier value in the File header by 1\u003C\u002Fli>\u003Cli>Recalculate the Checksum in the File header\u003C\u002Fli>\u003Cli>Recalculate the previous log length, involving 2 positions (offset 4 and the last 4 bytes of the current log)\u003C\u002Fli>\u003Cli>Decrease the Event record identifier of subsequent logs by 1 sequentially\u003C\u002Fli>\u003Cli>Decrease the Last event record number in ElfChuk by 1\u003C\u002Fli>\u003Cli>Decrease the Last event record identifier in ElfChuk by 1\u003C\u002Fli>\u003Cli>Recalculate checksum of Event records in ElfChuk\u003C\u002Fli>\u003Cli>Recalculate checksum in ElfChuk\u003C\u002Fli>\u003C\u002Fol>\u003Cp>In program implementation, the specific details are as follows:\u003C\u002Fp>\u003Ch3>1. Decrement the Next record identifier value in File header by 1\u003C\u002Fh3>\u003Cp>Read log file content\u003C\u002Fp>\u003Cp>Define log file format structure and parse the log file format\u003C\u002Fp>\u003Cp>Decrement Next record identifier value by 1:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>FileHeader-&gt;NextRecordIdentifier = FileHeader-&gt;NextRecordIdentifier-1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Recalculate the Checksum in File header\u003C\u002Fh3>\u003Cp>C code for calculating CRC checksum:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>unsigned int CRC32[256];\u003Cbr>static void init_table()\u003Cbr>{\u003Cbr>\tint i, j;\u003Cbr>\tunsigned int crc;\u003Cbr>\tfor (i = 0; i &lt; 256; i++)\u003Cbr>\t{\u003Cbr>\t\tcrc = i;\u003Cbr>\t\tfor (j = 0; j &lt; 8; j++)\u003Cbr>\t\t{\u003Cbr>\t\t\tif (crc &amp; 1)\u003Cbr>\t\t\t\tcrc = (crc &gt;&gt; 1) ^ 0xEDB88320;\u003Cbr>\t\t\telse\u003Cbr>\t\t\t\tcrc = crc &gt;&gt; 1;\u003Cbr>\t\t}\u003Cbr>\t\tCRC32[i] = crc;\u003Cbr>\t}\u003Cbr>}\u003Cbr>\u003Cbr>unsigned int GetCRC32(unsigned char *buf, int len)\u003Cbr>{\u003Cbr>\tunsigned int ret = 0xFFFFFFFF;\u003Cbr>\tint i;\u003Cbr>\tstatic char init = 0;\u003Cbr>\tif (!init)\u003Cbr>\t{\u003Cbr>\t\tinit_table();\u003Cbr>\t\tinit = 1;\u003Cbr>\t}\u003Cbr>\tfor (i = 0; i &lt; len; i++)\u003Cbr>\t{\u003Cbr>\t\tret = CRC32[((ret &amp; 0xFF) ^ buf[i])] ^ (ret &gt;&gt; 8);\u003Cbr>\t}\u003Cbr>\tret = ~ret;\u003Cbr>\treturn ret;\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Calculate the checksum of the first 120 bytes of the File header\u003C\u002Fp>\u003Cp>Code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>unsigned char *ChecksumBuf = new unsigned char[120];\u003Cbr>memcpy(ChecksumBuf, (PBYTE)elfFilePtr, 120);\u003Cbr>crc32 = GetCRC32(ChecksumBuf, 120);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Recalculate the length of the previous log, involving 2 positions (offset 4 and the last 4 bytes of the current log)\u003C\u002Fh3>\u003Cp>Locate Event Records one by one by searching for the magic string 0x2A 0x2A 0x00 0x00\u003C\u002Fp>\u003Cp>(1) Locate the log to be deleted: CurrentRecord\u003C\u002Fp>\u003Cp>Read the length, i.e., CurrentRecord-&gt;Size\u003C\u002Fp>\u003Cp>(2) Locate the previous log: PrevRecord\u003C\u002Fp>\u003Cp>Read the length, i.e., PrevRecord-&gt;Size\u003C\u002Fp>\u003Cp>Calculate the merged length:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>NewSize = CurrentRecord-&gt;Size + PrevRecord-&gt;Size\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Update the length:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>PrevRecord-&gt;Size = NewSize\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(3) Locate the next log record NextRecord\u003C\u002Fp>\u003Cp>Replace the 4 bytes before the starting point of NextRecord with NewSize:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>*(PULONG)((PBYTE)NextRecord-4) = NewSize\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Decrement the Event record identifier of subsequent logs by 1 sequentially\u003C\u002Fh3>\u003Cp>Traverse subsequent logs, decrementing the Event record identifier by 1 sequentially\u003C\u002Fp>\u003Cp>Two locations need to be modified:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>CurrentRecord-&gt;EventRecordIdentifier = CurrentRecord-&gt;EventRecordIdentifier-1\u003Cbr>CurrentRecord-&gt;Template-&gt;EventRecordIdentifier = CurrentRecord-&gt;Template-&gt;EventRecordIdentifier-1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>5. Decrement the Last event record number in ElfChuk by 1\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ElfChuk-&gt;LastEventRecordNumber = ElfChuk-&gt;LastEventRecordNumber-1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>6. Decrement the Last event record identifier in ElfChuk by 1\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ElfChuk-&gt;LastEventRecordIdentifier = ElfChuk-&gt;LastEventRecordIdentifier-1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>7. Recalculate the Event records checksum in ElfChuk\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>unsigned char *ChecksumBuf = new unsigned char[currentChunk-&gt;FreeSpaceOffset - 512];\u003Cbr>memcpy(ChecksumBuf, (PBYTE)currentChunk+512, currentChunk-&gt;FreeSpaceOffset - 512);\u003Cbr>crc32 = GetCRC32(ChecksumBuf, currentChunk-&gt;FreeSpaceOffset - 512);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>8. Recalculate the Checksum in ElfChuk\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>unsigned char *ChecksumBuf = new unsigned char[504];\u003Cbr>memcpy(ChecksumBuf, (PBYTE)currentChunk, 120);\u003Cbr>memcpy(ChecksumBuf+120, (PBYTE)currentChunk+128, 384);\u003Cbr>crc32 = GetCRC32(ChecksumBuf, 504);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Delete the last log entry\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Deleting the last log entry was demonstrated in the previous article 'Windows XML Event Log (EVTX) Single Log Entry Deletion (Part 1) – Deletion Approach and Example'. The method is essentially the same as deleting a middle log entry.\u003C\u002Fp>\u003Cp>The differences are as follows:\u003C\u002Fp>\u003Col>\u003Cli>The Event record identifier of subsequent logs does not need to be decremented by 1, as there are no subsequent logs.\u003C\u002Fli>\u003Cli>The Last event record data offset in ElfChuk needs to be recalculated.\u003C\u002Fli>\u003C\u002Fol>\u003Cp>The program details are as follows:\u003C\u002Fp>\u003Cp>1. Recalculate the Last event record data offset in ElfChuk\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ElfChuk-&gt;LastEventRecordDataOffset = ElfChuk-&gt;LastEventRecordDataOffset - LastRecord-&gt;Size\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x05 Delete the first log\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The method of modifying log length is not applicable for deleting the first log, because there is no previous log to overwrite the current one\u003C\u002Fp>\u003Cp>If you still want to achieve this using the overwrite length method, further analysis of the log file format is required\u003C\u002Fp>\u003Cp>We know that the content of Event Records is stored in Binary XML format\u003C\u002Fp>\u003Cp>For reference on Binary XML format:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Flibyal\u002Flibevtx\u002Fblob\u002Fmaster\u002Fdocumentation\u002FWindows%20XML%20Event%20Log%20(EVTX).asciidoc#4-binary-xml\u003C\u002Fp>\u003Cp>To merge logs by modifying the Binary XML format content, the following items need to be modified:\u003C\u002Fp>\u003Cul>\u003Cli>Written date and time\u003C\u002Fli>\u003Cli>Template definition Data size\u003C\u002Fli>\u003Cli>Next template definition offset\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This method is also applicable for modifying middle logs and the last log, so understanding the log format means deletion methods are not unique\u003C\u002Fp>\u003Cp>For other implementation details, refer to the open-source code at the following address:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Cp>The code implements reading the specified log file c:\\\\test\\\\Setup.evtx, deleting a single log entry (EventRecordID=14), and saving it as a new log file c:\\\\test\\\\SetupNew.evtx\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>In the implementation details of the code, I referred to the demo code on KanXue, with the address as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fbbs.pediy.com\u002Fthread-219313.htm\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the approach and program implementation details for deleting a single log entry from an evtx file, with open-source code. The method for deleting a single log entry is not unique. Next, multiple methods for deleting a single log entry from the current system will be introduced.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",769,"Onedaysec",5,"published","2026-02-02T07:38:21.201Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"EVTX Single Log Deletion: Program Implementation Guide","EVTX log deletion, Windows event log, log record removal, EVTX file editing, program implementation",null,false,[],{"docs":43,"hasNextPage":40},[4,44,45,46],731,730,729,{"title":39,"description":39,"image":39},"2026-07-24T15:37:11.728Z","2026-07-23T16:02:01.005Z","draft","2026-07-23T16:14:26.521Z"]