This pack is targeted for collections of Window events in the Classic or newer XML format. For events in the Classic format, sometimes the Message field contains XML.
-
Updated
Jan 30, 2023
This pack is targeted for collections of Window events in the Classic or newer XML format. For events in the Classic format, sometimes the Message field contains XML.
A Python tool that parses EVTX files and converts them into JSON formatted logs mimicking Wazuh agent behavior in version 4.x. wazuhevtx is designed as a helper for wazuh-logtest tool.
Blocks failed RDP login IPs using the routing table instead of Windows Firewall. Ideal for systems with firewall disabled for performance reasons.
Windows Event Threat Navigator: Quick reference linking Windows/Sysmon events to MITRE ATT&CK®
HF Server Events is a Powershell script that creates and configures the: SQL Server Database, Forwarder Subscriptions, Schedulated Tasks and the Domain Controllers to centralize and store the events recommended by Microsoft.
Production-grade Windows telemetry agent that dynamically intercepts critical system events, auto-diagnoses hardware/software faults, and generates structured data for Machine Learning predictive maintenance pipelines.
Powershell script switch proxy on event 8001 by Journal Microsoft-Windows-Wan-AutoConfig/Operationnal, Source : Wan-AutoConfig Windows
Small convince tool to lookup windows ids and return triggers them.
Security monitoring dashboard for detecting brute-force attacks through Windows Event ID 4625 monitoring. Features real-time visualizations, alerting, and filtering capabilities.
A log analysis and threat detection platform for web server logs and Windows event logs — with rule-based detection, behavioral analytics, and an analyst dashboard.
Production-grade Windows telemetry agent that dynamically intercepts critical system events, auto-diagnoses hardware/software faults, and generates structured data for Machine Learning predictive maintenance pipelines.
Forward Windows Events to syslog server
SOC dashboard for detecting early ransomware behaviour using endpoint events, risk scoring and MITRE ATT&CK mapping.
Local-first Windows diagnostics for freezes, throttling, disk, GPU, and system events.
To associate your repository with the windows-events topic, visit your repo's landing page and select "manage topics."