Repository navigation

#

windows-event-logs

APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of windows event logs to decrease the time to uncover suspicious activity

Python
1366
9 个月前

Automation scripts to deploy Windows Event Forwarding, Sysmon, and custom audit policies in an Active Directory environment.

PowerShell
485
9 个月前

A PS forensics tool for Scraping, Filtering and Exporting Windows Event Logs

PowerShell
16
6 年前

Search Windows event log and output results to a text file

C#
4
2 年前

A Python script that parses CPER-formatted raw data contained in error event log provided by WHEA-Logger

Python
4
2 年前

Convert Windows Event Log .evtx files to other formats.

Python
4
6 年前

Purpose: analyze Windows Security Logs using Splunk to develop a behavioral baseline and investigate host activity patterns.

Jupyter Notebook
0
2 个月前

*This simulation captures core, widely observed attacker behaviors aligned with common enterprise intrusion patterns. From brute-force access to obfuscated execution, persistence, recon, and privilege assessment, each step reflects actions that threat actors commonly execute after compromising a host.

Jupyter Notebook
0
1 个月前

This case study captures a classic example of attacker persistence using a built-in operating system feature: the Windows service framework. Through the lens of Event ID 7045, the attacker installed a background service named WinUpdateHelper, masked to resemble a legitimate update utility.

Jupyter Notebook
0
3 个月前

Detection engineering lab using Splunk, Sigma, and Windows logs — mapped to MITRE ATT&CK

0
4 个月前

Parses and imports a Windows Log File (CSV) into a Microsoft SQL Server Database.

C#
0
7 个月前

Parses and Analyse Authentication on Windows Event Log

PowerShell
0
2 年前

Shows how to write entries to Windows Event Log

C#
0
2 年前
C#
0
8 个月前