Repository navigation

#

evtx

Set of Mindmaps providing a detailed overview of the different #Microsoft auditing capacities for Windows, Exchange, Azure,...

1082
1 年前

Pure Python parser for Windows Event Log files (.evtx)

Python
752
2 个月前

A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs

Python
738
4 个月前

Set of EVTX samples (>270) mapped to MITRE ATT&CK tactic and techniques to measure your SIEM coverage or developed new use cases.

588
7 个月前

C# based evtx parser with lots of extras

C#
318
2 个月前
Python
240
7 个月前

evtx-hunter helps to quickly spot interesting security-related activity in Windows Event Viewer (EVTX) files.

Python
155
4 年前

Parse evtx files and detect use of the DanderSpritz eventlogedit module

Python
148
8 年前

ThreatSeeker: Threat Hunting via Windows Event Logs

Python
123
2 年前

A library for fast parse & import of Windows Eventlogs into Elasticsearch.

Python
85
2 个月前

Evtx Log (xml) Browser

PowerShell
56
2 年前

Triaging Windows event logs based on SANS Poster

PowerShell
39
3 年前

Simple Windows Event Log Forwarder (SWELF). Its easy to use/simply works Log Forwarder and EVTX Parser. Almost in full release here at https://github.com/ceramicskate0/SWELF/releases/latest.

C#
24
2 年前

Logpresso Mini and community contents for incident response

18
4 年前

EvtXHunt is an Autopsy plugin that is able to analyze Windows EVTX logs against a library of SIGMA rules.

Python
16
4 年前

Is a portable forensic tool for analyzing Windows logs, pre-organized according to the methodology outlined in this job: https://cybersecuritynews.com/windows-event-log-analysis/, to quickly highlight key forensic artifacts.

C#
11
1 个月前

A simple System monitor(Sysmon) EVTX inspector; search, visualize, and track Sysmon events

Go
7
1 年前

This is a PySimpleGUI-based Python software tool for processing and visualising selected Windows Event Security.evtx log files that meet a condition in Event ID 4688.

Python
6
1 年前