Repository navigation

#

evtx

Set of Mindmaps providing a detailed overview of the different #Microsoft auditing capacities for Windows, Exchange, Azure,...

1068
8 个月前

Pure Python parser for Windows Event Log files (.evtx)

Python
738
9 个月前

A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs

Python
708
14 天前

Set of EVTX samples (>270) mapped to MITRE ATT&CK tactic and techniques to measure your SIEM coverage or developed new use cases.

563
3 个月前

C# based evtx parser with lots of extras

C#
299
20 天前
Python
236
3 个月前

evtx-hunter helps to quickly spot interesting security-related activity in Windows Event Viewer (EVTX) files.

Python
151
3 年前

Parse evtx files and detect use of the DanderSpritz eventlogedit module

Python
148
7 年前

ThreatSeeker: Threat Hunting via Windows Event Logs

Python
120
2 年前

A library for fast parse & import of Windows Eventlogs into Elasticsearch.

Python
85
10 个月前

Evtx Log (xml) Browser

PowerShell
56
2 年前

Triaging Windows event logs based on SANS Poster

PowerShell
39
2 年前

Simple Windows Event Log Forwarder (SWELF). Its easy to use/simply works Log Forwarder and EVTX Parser. Almost in full release here at https://github.com/ceramicskate0/SWELF/releases/latest.

C#
24
2 年前

Logpresso Mini and community contents for incident response

17
3 年前

EvtXHunt is an Autopsy plugin that is able to analyze Windows EVTX logs against a library of SIGMA rules.

Python
16
3 年前

This is a PySimpleGUI-based Python software tool for processing and visualising selected Windows Event Security.evtx log files that meet a condition in Event ID 4688.

Python
6
10 个月前

Glossy Event Log Forensics

JavaScript
5
1 年前

A simple System monitor(Sysmon) EVTX inspector; search, visualize, and track Sysmon events

Go
4
10 个月前