94 skills found · Page 1 of 4
sbousseaden / EVTX ATTACK SAMPLESWindows Events Attack Samples
mdecrevoisier / Microsoft Eventlog MindmapSet of Mindmaps providing a detailed overview of the different #Microsoft auditing capacities for Windows, Exchange, Azure,...
omerbenamram / EvtxA Fast (and safe) parser for the Windows XML Event Log (EVTX) format
wagga40 / ZircoliteA standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs
williballenthin / Python EvtxPure Python parser for Windows Event Log files (.evtx)
mdecrevoisier / EVTX To MITRE AttackSet of EVTX samples (>270) mapped to MITRE ATT&CK tactic and techniques to measure your SIEM coverage or developed new use cases.
nasbench / EVTX ETW ResourcesEvent Tracing For Windows (ETW) Resources
EricZimmerman / EvtxC# based evtx parser with lots of extras
3gstudent / Eventlogedit Evtx EvolutionRemove individual lines from Windows XML Event Log (EVTX) files
jurelou / EpagneulGraph Visualization for windows event logs
libyal / LibevtxLibrary and tools to access the Windows XML Event Log (EVTX) format
r3nzsec / Irflow TimelineDFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with built-in process inspection, lateral movement tracking, persistence detection, and VirusTotal enrichment.
williballenthin / EVTXtractEVTXtract recovers and reconstructs fragments of EVTX log files from raw binary data, including unallocated space and memory images.
0xrawsec / Golang EvtxNo description available
NVISOsecurity / Evtx Hunterevtx-hunter helps to quickly spot interesting security-related activity in Windows Event Viewer (EVTX) files.
fox-it / Danderspritz EvtxParse evtx files and detect use of the DanderSpritz eventlogedit module
ine-labs / ThreatSeekerThreatSeeker: Threat Hunting via Windows Event Logs
dgunter / EvtxtoelkA lightweight tool to load Windows Event Log evtx files into Elasticsearch.
Koifman / LUMENYour Browser-based EVTX Companion
Velocidex / EvtxGolang Parser for Microsoft Event Logs