jonny-jhnson / EventSightLinks
AI-powered Windows Event Log analyzer that learns from your feedback. Uses Claude AI with RAG to detect suspicious activity, improve accuracy over time, and share learnings across your team. CLI and MCP server interfaces.
☆29Updated 3 weeks ago
Alternatives and similar repositories for EventSight
Users that are interested in EventSight are comparing it to the libraries listed below
Sorting:
- VTC - Velociraptor Timeline Creator☆19Updated last year
- Baseline a Windows System against LOLBAS☆69Updated last year
- A simple tool designed to create Atomic Red Team tests with ease.☆49Updated 10 months ago
- Living off the False Positive!☆41Updated 11 months ago
- A little tool to filter the stranger strings from a binary so you can analyze the good ones☆52Updated 4 months ago
- HoneyZure is a honeypot tool specifically designed for Azure environments, fully provisioned through Terraform. It leverages a Log Analyt…☆16Updated last year
- Slides of my public talks☆56Updated 2 years ago
- Interactive PowerShell framework for testing WMI, COM, LOLBAS, and persistence techniques☆54Updated 2 weeks ago
- Purple-team telemetry & simulation toolkit.☆100Updated 3 weeks ago
- TTPMapper is an AI-driven threat intelligence parser that converts unstructured reports whether from web URLs or PDF files into structure…☆48Updated 6 months ago
- ☆33Updated last year
- A zero dependency and customizable Python library for scanning Windows and Linux process memory.☆66Updated last year
- ☆59Updated last month
- urlyzer is a URL parsing analysis tool.☆24Updated last year
- Framework for Monitoring File Ingestion Source for Yara Matches☆50Updated 10 months ago
- Detonate malware on VMs and get logs & detection status☆74Updated last week
- Ludus range for the Constructing Defense Lab☆70Updated 2 months ago
- AI-Powered, Local Pythonic Coding Agent 🐞💻☆24Updated 10 months ago
- create a "simulated internet" cyber range environment☆19Updated 7 months ago
- MSIX Building Made Easy for Defenders☆60Updated 4 months ago
- Listener that spawns a new tmux window for each incoming reverse shell + Supports listening on many ports☆59Updated 5 months ago
- ☆10Updated last year
- A not-curated list of cloud hacking labs☆26Updated last year
- ☆18Updated this week
- Invoke-AtomicAssessment is a powerful tool designed to facilitate adversary emulation by leveraging Atomic Red Team.☆43Updated 11 months ago
- A public repository of MITRE ATT&ACK TTP mappings by BushidoUK for OSINT reports that lack a section breaking down the TTPs.☆28Updated 9 months ago
- ☆25Updated 3 years ago
- MS Graph Commands and Tools for Blue Teamers☆52Updated 2 years ago
- Silver SAML forgery tool☆56Updated last year
- Repo containing various intel-based resources such as threat research, adversary emulation/simulation plan and so on☆84Updated last year