bannsec / winevt
Windows Event Interactions in Python
☆67Updated 3 months ago
Alternatives and similar repositories for winevt:
Users that are interested in winevt are comparing it to the libraries listed below
- Minimal, consistent Python API for building integrations with malware sandboxes.☆138Updated last year
- A lightweight tool to load Windows Event Log evtx files into Elasticsearch.☆115Updated 4 years ago
- Analysis Correlation Engine☆26Updated 5 years ago
- Event Log Analysis Tools☆29Updated 8 years ago
- Community modules for FAME☆65Updated 2 weeks ago
- Static analysis tools for Microsoft Office Open XML files and documents☆68Updated 7 years ago
- Repository with selected IOCs and YARA rules for threat hunting.☆35Updated last month
- ☆17Updated 7 years ago
- A tool to convert Windows evtx files (Windows Event Log Files) into JSON format and log to Splunk (optional) using HTTP Event Collector.☆54Updated 2 years ago
- ☆12Updated 3 years ago
- A HIDS (host-based intrusion detection system) for verifying the integrity of a system.☆59Updated this week
- Breaking the security of Microsoft's RMS☆53Updated 5 years ago
- Validates yara rules and tries to repair the broken ones.☆39Updated 4 years ago
- ☆38Updated 5 years ago
- Open source Python library for NTFS analysis☆80Updated 7 years ago
- Actionable analytics designed to combat threats based on MITRE's ATT&CK.☆22Updated 5 years ago
- Python library for parsing AccessData AD1 images☆30Updated last year
- The Alternative Fileless File System☆55Updated 5 years ago
- pollen - A command-line tool for interacting with TheHive☆35Updated 5 years ago
- Theat hunting notes in flat file format and mapped to MITRE's ATT&CK IDs☆42Updated 6 years ago
- Bro IDS + ELK Stack to detect and block data exfiltration☆46Updated 6 years ago
- A DFVFS Backed Forensic Viewer☆40Updated 4 years ago
- ☆33Updated 4 years ago
- ☆15Updated 6 years ago
- Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.☆46Updated 5 years ago
- Pure Python parser for classic Windows Event Log files (.evt)☆47Updated last year
- Python bindings for https://github.com/omerbenamram/evtx/☆50Updated 2 months ago
- An Inofficial Sysmon Version History (Change Log)☆32Updated 4 years ago
- Extract common Windows artifacts from source images and VSCs☆65Updated 3 years ago
- Tools to assist in forensicating docker☆81Updated last week