Awesome Cybersecurity Blue Team
Section: Incident Response tools · Investigate malicious Windows logon by visualizing and analyzing Windows event log.
Entry
Appears in 5 awesome lists
Tool to investigate malicious Windows logon by visualizing and analyzing Windows event log.
Section: Incident Response tools · Investigate malicious Windows logon by visualizing and analyzing Windows event log.
Section: 事件响应工具 · 可用于可视化分析Windows事件日志来调查恶意的Windows登录
Section: Log Analysis Tools · Tool to investigate malicious Windows logon by visualizing and analyzing Windows event log.
Section: Windows Artifacts · Investigate malicious Windows logon by visualizing and analyzing Windows event log
Section: General
Sigma's repository of turnkey detection content. Content can be converted for use with most SIEMs.
CLI utility and Python API for analyzing log files and other data. (MIT)
Hayabusa is a Windows event log fast forensics timeline generator and threat hunting tool created by the Yamato Security group in Japan.
Windows Event Log Analyzer aims to be the Swiss Army knife for Windows event logs.
A standalone and fast SIGMA-based detection tool for EVTX or JSON.
APT-Hunter is Threat Hunting tool for windows event logs.
A serverless, realtime data analysis framework which empowers you to ingest, analyze, and alert on data from any environment, using datasources and alerting logic you define
Threat intelligence fusion and analysis tool that integrates threat data feeds with SIEM solutions. Users can immediately leverage threat intelligence for security monitoring and incident report (IR) activities in the workflow of their existing security operations.