Skip to content

Entry

LogonTracer

Appears in 5 awesome lists

Tool to investigate malicious Windows logon by visualizing and analyzing Windows event log.

Open github.comjpcertcc/logontracer

Found in these lists

Awesome Cybersecurity Blue Team

Section: Incident Response tools · Investigate malicious Windows logon by visualizing and analyzing Windows event log.

StaleScore 53

Awesome Cybersecurity Blue Team - CN

Section: 事件响应工具 · 可用于可视化分析Windows事件日志来调查恶意的Windows登录

StaleScore 47

Awesome Incident Response

Section: Log Analysis Tools · Tool to investigate malicious Windows logon by visualizing and analyzing Windows event log.

ActiveScore 82

Forensics Tools

Section: Windows Artifacts · Investigate malicious Windows logon by visualizing and analyzing Windows event log

ActiveScore 77

Security lists for SOC/DFIR detections

Section: General

FreshScore 84

Sigma

Sigma's repository of turnkey detection content. Content can be converted for use with most SIEMs.

In 5 listsDetails

Logdissect

CLI utility and Python API for analyzing log files and other data. (MIT)

In 4 lists

Hayabusa

Hayabusa is a Windows event log fast forensics timeline generator and threat hunting tool created by the Yamato Security group in Japan.

In 3 lists

WELA

Windows Event Log Analyzer aims to be the Swiss Army knife for Windows event logs.

In 2 lists

Zircolite

A standalone and fast SIGMA-based detection tool for EVTX or JSON.

In 2 lists

APT Hunter

APT-Hunter is Threat Hunting tool for windows event logs.

In 2 lists

StreamAlert

A serverless, realtime data analysis framework which empowers you to ingest, analyze, and alert on data from any environment, using datasources and alerting logic you define

In 2 lists

Kaspersky CyberTrace

Threat intelligence fusion and analysis tool that integrates threat data feeds with SIEM solutions. Users can immediately leverage threat intelligence for security monitoring and incident report (IR) activities in the workflow of their existing security operations.