Set of Mindmaps providing a detailed overview of the different #Microsoft auditing capacities for Windows, Exchange, Azure,...
-
Updated
May 23, 2024
Set of Mindmaps providing a detailed overview of the different #Microsoft auditing capacities for Windows, Exchange, Azure,...
This is a PySimpleGUI-based Python software tool for processing and visualising selected Windows Event Security.evtx log files that meet a condition in Event ID 4688.
An Autopsy data source ingest module for detection of IOCs in EVTX for Windows and Auditd for Linux based on SIGMA Rules.
Set of EVTX samples (>270) mapped to MITRE ATT&CK tactic and techniques to measure your SIEM coverage or developed new use cases.
A simplified EVTX file parser wrapping 0xrawsec's golang-evtx module
A simple System monitor(Sysmon) EVTX inspector; search, visualize, and track Sysmon events
Simple Windows Event Log Forwarder (SWELF). Its easy to use/simply works Log Forwarder and EVTX Parser. Almost in full release here at https://github.com/ceramicskate0/SWELF/releases/latest.
ThreatSeeker: Threat Hunting via Windows Event Logs
Windows Log to Logstash ingesting service
Windows Events Attack Samples
Add a description, image, and links to the evtx topic page so that developers can more easily learn about it.
To associate your repository with the evtx topic, visit your repo's landing page and select "manage topics."