jonny-jhnson / EventSightLinks
AI-powered Windows Event Log analyzer that learns from your feedback. Uses Claude AI with RAG to detect suspicious activity, improve accuracy over time, and share learnings across your team. CLI and MCP server interfaces.
☆31Updated last month
Alternatives and similar repositories for EventSight
Users that are interested in EventSight are comparing it to the libraries listed below
Sorting:
- Baseline a Windows System against LOLBAS☆70Updated last year
- A simple tool designed to create Atomic Red Team tests with ease.☆49Updated 10 months ago
- SQL, IIS, Oh My...☆18Updated 11 months ago
- VTC - Velociraptor Timeline Creator☆19Updated last year
- Living off the False Positive!☆41Updated last year
- urlyzer is a URL parsing analysis tool.☆24Updated last year
- Slides of my public talks☆56Updated 2 years ago
- A little tool to filter the stranger strings from a binary so you can analyze the good ones☆52Updated 4 months ago
- orc2timeline extracts and analyzes artifacts contained in archives generated with DFIR-ORC.exe to create a timeline from them☆34Updated 7 months ago
- Ludus range for the Constructing Defense Lab☆72Updated 2 months ago
- TTPMapper is an AI-driven threat intelligence parser that converts unstructured reports whether from web URLs or PDF files into structure…☆49Updated 7 months ago
- Detonate malware on VMs and get logs & detection status☆76Updated last week
- Framework for Monitoring File Ingestion Source for Yara Matches☆50Updated 10 months ago
- Purple-team telemetry & simulation toolkit.☆107Updated last month
- Placeholder for my detection repo and misc detection engineering content☆42Updated 2 years ago
- JamfHound is a python3 project designed to collect and identify attack paths in Jamf Pro tenants based on existing object permissions by …☆113Updated 4 months ago
- Assortment of scripts and tools for our Blackhat EU 2024 talk☆104Updated 11 months ago
- MS Graph Commands and Tools for Blue Teamers☆52Updated 2 years ago
- Invoke-AtomicAssessment is a powerful tool designed to facilitate adversary emulation by leveraging Atomic Red Team.☆44Updated last year
- A public repository of MITRE ATT&ACK TTP mappings by BushidoUK for OSINT reports that lack a section breaking down the TTPs.☆27Updated 10 months ago
- ☆33Updated last year
- This repository is meant to catalog network and host artifacts associated with various EDR products "shell" and response functionalities.☆92Updated last year
- A home for detection content developed by the delivr.to team☆73Updated 5 months ago
- MSIX Building Made Easy for Defenders☆59Updated 5 months ago
- ☆58Updated last month
- Listener that spawns a new tmux window for each incoming reverse shell + Supports listening on many ports☆59Updated 6 months ago
- A zero dependency and customizable Python library for scanning Windows and Linux process memory.☆66Updated 2 years ago
- Providing Azure pipelines to create an infrastructure and run Atomic tests.☆53Updated 2 years ago
- ☆52Updated 3 weeks ago
- SubCrawl is a modular framework for discovering open directories, identifying unique content through signatures and organizing the data w…☆54Updated last year