You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of windows event logs to decrease the time to uncover suspicious activity
A Python tool that parses EVTX files and converts them into JSON formatted logs mimicking Wazuh agent behavior in version 4.x. wazuhevtx is designed as a helper for wazuh-logtest tool.
LogLens is a universal log explorer that runs entirely in your browser. Drop any log file in, query it with KQL, visualize it on a timeline, and analyze it with a local AI - all without a single byte of your data touching the internet.
SOC Authentication Monitoring Dashboard using Splunk Enterprise with Brute Force Detection, Windows Security Event Monitoring, Alerting, and Interactive Dashboard.
Implement the Yamato Security Windows event logging baselines with native PowerShell: tiered enable, read-only verification, rollback, and WELA-based independent checking. No agents, no modules.
Hands-on enterprise SIEM lab built with Splunk Enterprise, Windows Server AD, and VirtualBox. Covers log ingestion, Windows Event ID analysis, SPL queries, and security dashboarding.
Справочник событий Windows/Linux для SOC-аналитиков, threat hunters и IR-инженеров. 144 Event ID, Sysmon, Linux, MITRE ATT&CK, storylines, инструменты — на русском, с интерактивным поиском.
Hands-on practice in monitoring activity on workstations, as that’s where adversaries spend the most time trying to achieve their objectives. Practice done in the simulated challenge/room environment inside a Virtual Machine (VM) provided by TryHackMe.