Open source Windows Event Collector
-
Updated
Jun 15, 2024 - Python
Open source Windows Event Collector
Qt based application to decode windows log files(.etl and .evtx) to txt files
AI destekli çoklu platform log analiz ve güvenlik aracı - Windows, Linux, macOS için otomatik log toplama ve güvenlik analizi
The Granted Access Converter is a utility designed to help users understand and interpret the GrantedAccess values found in Sysmon Event ID 10 logs.
Hands-on detection engineering portfolio focused on behavior-based threat detection, EQL, and real-world attack analysis
Windows disk cleanup PowerShell script.
PowerShell script to efficiently search and analyze Windows Event Logs.
Local Validation Toolkit is a Python-based toolkit for Windows log processing and local LLM analysis. It enables AI-assisted workflows using a local model (via LM Studio), including log sanitization for privacy, structured prompt design, and system log analysis with guardrails for adversarial and out-of-scope user inputs.
SOC-level Windows Security Log Analysis using ELK Stack (Filebeat, Elasticsearch, Kibana) and Python on LANL dataset. Includes log ingestion, chunk processing, forensic analysis, and threat detection.
AI-powered Windows log analyzer and network threat detection system using hybrid Machine Learning.
A CLI program that fetches logs from Windows Event Viewer. Summarizes them via OpenAI GPT and exports in various file types
Windows Security Monitoring Dashboard in Splunk – detect failed logons, track account lockouts, and visualize authentication trends.
Custom CrowdSec parser test to detect Windows brute-force login attempts (Issue #1235)
A practical cybersecurity project focused on building and configuring a SIEM environment using Splunk/ELK Stack to collect, monitor, and analyze Windows event and Sysmon logs. Includes real-world attack simulations, threat detection dashboards, and an incident response report.
SOC project simulating and investigating brute force login attacks using Splunk and Windows authentication logs.
A practical SOC training lab using OPNsense, Wazuh SIEM . Suricata IDS . Wireshark . and Windows/Linux telemetry.
Learn Windows Event Viewer, analyze Windows Security logs, and investigate authentication events using Event IDs 4624, 4625, and 4634.
A lightweight Mini-SIEM and Centralized Log Management system for Windows. Features remote Agent collection, Sysmon integration, and a Rules Engine for threat detection. Built with JavaFX & Javalin.
No more manually clearing Windows logs — just run and go
To associate your repository with the windows-logs topic, visit your repo's landing page and select "manage topics."