Velocidex / evtx
Golang Parser for Microsoft Event Logs
☆98Updated 3 months ago
Related projects ⓘ
Alternatives and complementary repositories for evtx
- Signature engine for all your logs☆161Updated last year
- YARA rule metadata specification and validation utility / Spécification et validation pour les règles YARA☆98Updated 2 months ago
- YARA rule analyzer to improve rule quality and performance☆93Updated 11 months ago
- Automatically create YARA rules from malicious documents.☆208Updated 2 years ago
- enpoint detection / live analysis & sandbox host / signatures quality test☆42Updated 3 years ago
- ☆158Updated 2 years ago
- HXTool is an extended user interface for the FireEye HX Endpoint product. HXTool can be installed on a dedicated server or on your physic…☆79Updated 4 months ago
- A guide on how to write fast and memory friendly YARA rules☆126Updated last year
- A VBA parser and emulation engine to analyze malicious macros.☆92Updated 2 weeks ago
- simple YARA-based IOC scanner☆164Updated this week
- Import specific data sources into the Sigma generic and open signature format.☆77Updated 2 years ago
- A repo to document API functions mapped to security events across diverse platforms☆74Updated 5 years ago
- attack2jira automates the process of standing up a Jira environment that can be used to track and measure ATT&CK coverage☆111Updated last year
- A Cobalt Strike Scanner that retrieves detected Team Server beacons into a JSON object☆164Updated 2 years ago
- Set of Yara rules for finding files using magics headers☆135Updated 4 years ago
- Publicly shareable windows event log message data☆27Updated 4 years ago
- Random hunting ordiented yara rules☆95Updated last year
- ☆53Updated 5 years ago
- Digital Forensics Artifacts Knowledge Base☆75Updated 6 months ago
- Blueteam operational triage registry hunting/forensic tool.☆142Updated last year
- Factual-rules-generator is an open source project which aims to generate YARA rules about installed software from a machine.☆76Updated 2 years ago
- Go library for ETW (Event Tracing for Windows) events processing☆60Updated 2 years ago
- JPCERT/CC public YARA rules repository☆103Updated 5 months ago
- A CALDERA plugin☆72Updated 3 weeks ago
- PowerGRR is an API client library in PowerShell working on Windows, Linux and macOS for GRR automation and scripting.☆56Updated 2 years ago
- Malware similarity platform with modularity in mind.☆76Updated 3 years ago
- Initial triage of Windows Event logs☆89Updated 5 months ago
- A community event for security researchers to share their favorite notebooks☆106Updated 9 months ago