logging-essentials

Event logging guide

Provides guidance on configuring and collecting Windows event logs to enhance forensic analysis and incident response capabilities.

A Windows event logging and collection baseline focused on finding balance between forensic value and optimising retention.

GitHub

276 stars
20 watching
27 forks
last commit: about 5 years ago
Linked from 1 awesome list


Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
jdu2600/windows10etweventsCollects and analyzes Windows 10 event tracing data from various providers across different versions.275
nshalabi/sysmontoolsUtilities for analyzing and visualizing Windows event logs from Sysmon, helping users track and monitor system activity.1,492
thiber-org/userlineAutomates analysis of Windows Security Events to identify user logon relations241
sans-blue-team/deepbluecliA PowerShell module for analyzing Windows event logs to detect and respond to potential security threats.2,203
damienbod/aspnetcorenlogAn ASP.NET Core application demonstrating configuration and usage of NLog with various logging targets including MS SQL Server, PostgreSQL, MySQL, and Elasticsearch.60
retracedhq/retracedProvides a searchable, exportable record of read/write events365
reed1713/elatA toolset for analyzing Windows event logs to detect and analyze malware29
jpcertcc/sysmonsearchAnalyzes Sysmon event logs to detect suspicious activity and visualize process and network correlations.419
jvandevelde/dnxcore-logging-logstashAn extension that provides logging capabilities to .NET Core applications using UDP and Redis transports.8
certsocietegenerale/irmOperational guidelines and best practices for handling various types of security incidents982
collective/collective.fingerpointingTracks and logs events in an audit log to maintain record of user activity and content lifecycle.5
yamato-security/welaAnalyzes Windows Event Logs to identify security-related events and provides forensic tools for incident response.769
airbus-cert/timelinerA tool for filtering and analyzing Windows event logs based on complex time-based conditions37
threathunters-io/laurelConverts Linux audit logs into standardized JSON format for enhanced security monitoring722
mdecrevoisier/splunk-input-windows-baselineProvides an advanced Splunk configuration for collecting Windows log data relevant to threat detection, incident response, and forensic analysis.85