#

evtx

https://static.github-zh.com/github_avatars/sbousseaden?size=40
HTML 2.34 k
2 年前
https://static.github-zh.com/github_avatars/mdecrevoisier?size=40

Set of Mindmaps providing a detailed overview of the different #Microsoft auditing capacities for Windows, Exchange, Azure,...

翻译一组思维导图提供了不同 #Windows 审计能力和事件日志文件的详细概述。

1.07 k
7 个月前
https://static.github-zh.com/github_avatars/williballenthin?size=40

Pure Python parser for Windows Event Log files (.evtx)

Python 738
9 个月前
https://static.github-zh.com/github_avatars/wagga40?size=40

A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs

翻译用于EVTX的基于SIGMA的独立检测工具。

Python 707
11 天前
https://static.github-zh.com/github_avatars/mdecrevoisier?size=40

Set of EVTX samples (>270) mapped to MITRE ATT&CK tactic and techniques to measure your SIEM coverage or developed new use cases.

563
3 个月前
https://static.github-zh.com/github_avatars/EricZimmerman?size=40

C# based evtx parser with lots of extras

C# 298
16 天前
https://static.github-zh.com/github_avatars/jurelou?size=40
Python 235
3 个月前
https://static.github-zh.com/github_avatars/NVISOsecurity?size=40

evtx-hunter helps to quickly spot interesting security-related activity in Windows Event Viewer (EVTX) files.

Python 151
3 年前
https://static.github-zh.com/github_avatars/fox-it?size=40

Parse evtx files and detect use of the DanderSpritz eventlogedit module

Python 148
7 年前
https://static.github-zh.com/github_avatars/ine-labs?size=40
Python 121
2 年前
https://static.github-zh.com/github_avatars/sumeshi?size=40

A library for fast parse & import of Windows Eventlogs into Elasticsearch.

Python 85
10 个月前
https://static.github-zh.com/github_avatars/kacos2000?size=40
PowerShell 56
2 年前
https://static.github-zh.com/github_avatars/AhmedKamal1432?size=40

Triaging Windows event logs based on SANS Poster

PowerShell 39
2 年前
https://static.github-zh.com/github_avatars/ceramicskate0?size=40

Simple Windows Event Log Forwarder (SWELF). Its easy to use/simply works Log Forwarder and EVTX Parser. Almost in full release here at https://github.com/ceramicskate0/SWELF/releases/latest.

C# 24
2 年前
https://static.github-zh.com/github_avatars/logpresso?size=40

Logpresso Mini and community contents for incident response

17
3 年前
https://static.github-zh.com/github_avatars/Lyc4on?size=40

EvtXHunt is an Autopsy plugin that is able to analyze Windows EVTX logs against a library of SIGMA rules.

Python 16
3 年前
https://static.github-zh.com/github_avatars/martinmathurine?size=40

This is a PySimpleGUI-based Python software tool for processing and visualising selected Windows Event Security.evtx log files that meet a condition in Event ID 4688.

Python 5
10 个月前
https://static.github-zh.com/github_avatars/whatabeautifulmemory?size=40
JavaScript 5
1 年前
https://static.github-zh.com/github_avatars/KnightChaser?size=40

A simple System monitor(Sysmon) EVTX inspector; search, visualize, and track Sysmon events

Go 4
10 个月前
loading...
Website
Wikipedia