This tool parses Windows EVTX logs to extract login and logout sessions from a security.evtx file. It uses a Tkinter GUI to let you select the EVTX file and specify a time for correlating login and logout events.
☆32Feb 22, 2025Updated last year
Alternatives and similar repositories for LogonSessionAuditor
Users that are interested in LogonSessionAuditor are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A series of python scripts to extract information from Dark Web Applications☆14Mar 26, 2025Updated last year
- A tool for fetching DFIR and other GitHub tools.☆29Aug 2, 2025Updated 11 months ago
- macOS Artifacts☆33Mar 2, 2025Updated last year
- A comprehensive PowerShell toolkit for RDP forensics analysis, tracking connection attempts, authentication, sessions, and logoffs across…☆18May 27, 2026Updated last month
- Parses USB connection artifacts from offline Registry hives☆109Feb 8, 2026Updated 5 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Triage automation tool☆22Updated this week
- Forensic cheatsheets for use with cheat☆15Dec 2, 2021Updated 4 years ago
- Just Another broken Registry Parser (JARP)☆16May 23, 2024Updated 2 years ago
- Tools for Incident Response and Malware Analysis☆11Feb 9, 2025Updated last year
- ☆26Feb 18, 2025Updated last year
- Browse Windows Prefetch versions: 17,23,26,30v1/2,31 & some of SuperFetch .7db/.db's☆65Dec 18, 2024Updated last year
- Menu for Thor scanner lite☆20Oct 24, 2025Updated 8 months ago
- Scanner for certain IoCs☆11Jan 29, 2025Updated last year
- CLI tools for forensic investigation of Windows artifacts☆355Jul 21, 2025Updated last year
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- FJTA (Forensic Journal Timeline Analyzer) is a tool that analyzes Linux filesystem (ext4, XFS) journals (not systemd-journald logs), gene…☆112Apr 8, 2026Updated 3 months ago
- Browse Windows Recycle Bin from E01 forensic images with Explorer-style interface. Parse $I/$R artifacts, view deleted files in original …☆18Dec 16, 2025Updated 7 months ago
- Quick ESXi Log Parser☆33Oct 20, 2025Updated 9 months ago
- A collection of content for blue team professionals, designed to support both reactive and proactive cybersecurity measures of every aspe…☆35Apr 2, 2026Updated 3 months ago
- A Model Context Protocol (MCP) server that integrates Volatility 3 memory forensics framework with Claude☆39Jul 7, 2025Updated last year
- Comprehensive adversary emulation tool for security testing on Google Cloud Platform (GCP) environments.☆14Jun 14, 2024Updated 2 years ago
- PowerShell-based Automation of Defender for Endpoint☆196Jul 3, 2025Updated last year
- Scripts to for ready-to-use Velociraptor instance deployment in Azure☆14Jun 27, 2023Updated 3 years ago
- Tools and scripts to deploy and manage OpenRelik instances☆17Mar 23, 2026Updated 3 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A powerful macOS triage collection tool designed for forensic analysis. It gathers critical system artifacts such as FSEvents, Spotlight,…☆45Oct 24, 2025Updated 8 months ago
- Google Filestream Forensic Tool☆22Mar 10, 2022Updated 4 years ago
- A simple python script to generate nested folders based on user input. The script will also name and place a template report document and…☆12May 6, 2026Updated 2 months ago
- PowerShell tools to help defenders hunt smarter, hunt harder.☆489Oct 29, 2025Updated 8 months ago
- MAES: M365 Analyzer & Extractor Suite Po☆37May 4, 2026Updated 2 months ago
- ADXFlowmaster helps SecOps teams Threat Hunt suspicious network traffic inside & outside of Azure.☆39Oct 30, 2024Updated last year
- Portable Windows forensic tool for reviewing Firefox-like and Chromium-based browser artifacts, with labeling, search, CLI processing, an…☆58May 10, 2026Updated 2 months ago
- FileSigExtractor is a python based tool which extracts the file signatures of all files within a directory and writes the output to a CSV…☆10Jul 15, 2023Updated 3 years ago
- A pentesting tool for enumeration/download/graphical analysis of OCI content. Includes an OpenGraph generator for Bloodhound-style analys…☆20Updated this week
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- Automatic, fast parsing of browser artifacts☆17Jan 4, 2025Updated last year
- A Windows Event Log MCP☆49Aug 25, 2025Updated 10 months ago
- Find open storage buckets and accessible files across Amazon Web Services, Google Cloud, Microsoft Azure, and Digital Ocean simultaneousl…☆20Jan 15, 2025Updated last year
- ☆23Mar 12, 2025Updated last year
- Automate forensic traige package collection and evidence parsing with KAPE and Crowdstrike☆15Mar 5, 2022Updated 4 years ago
- A series of functions to parse Teamviewer logs to answer specific questions☆10Jul 17, 2022Updated 4 years ago
- Incident response teams usually working on the offline data, collecting the evidence, then analyze the data☆48Jan 2, 2022Updated 4 years ago