Repositories tagged with "evtx"
EVTX-ATTACK-SAMPLES
sbousseaden
โWindows Events Attack Samplesโ
Microsoft-eventlog-mindmap
mdecrevoisier
โSet of Mindmaps providing a detailed overview of the different #Microsoft auditing capacities for Windows, Exchange, Azure,...โ
Zircolite
wagga40
โA standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logsโ
python-evtx
williballenthin
โPure Python parser for Windows Event Log files (.evtx)โ
EVTX-to-MITRE-Attack
โSet of EVTX samples (>270) mapped to MITRE ATT&CK tactic and techniques to measure your SIEM coverage or developed new use cases.โ
evtx
EricZimmerman
โC# based evtx parser with lots of extrasโ
epagneul
jurelou
โGraph Visualization for windows event logsโ
evtx-hunter
NVISOsecurity
โevtx-hunter helps to quickly spot interesting security-related activity in Windows Event Viewer (EVTX) files.โ
danderspritz-evtx
fox-it
โParse evtx files and detect use of the DanderSpritz eventlogedit moduleโ
ThreatSeeker
ine-labs
โThreatSeeker: Threat Hunting via Windows Event Logsโ
evtx2es
sumeshi
โA command-line tool and Python library for parsing Windows Event Logs and importing the results into Elasticsearch.โ
Evtx_Log_Browser
kacos2000
โEvtx Log (xml) Browserโ
ADFT
Kjean13
โActive Directory Forensic Toolkit : Detect & reconstruct AD attacks from Windows event logs (EVTX) โ