logging-essentials
Event logging guide
Provides guidance on configuring and collecting Windows event logs to enhance forensic analysis and incident response capabilities.
A Windows event logging and collection baseline focused on finding balance between forensic value and optimising retention.
276 stars
20 watching
27 forks
last commit: about 5 years agoLinked from 1 awesome list
Related projects:
| Repository | Description | Stars |
|---|---|---|
| Collects and analyzes Windows 10 event tracing data from various providers across different versions. | 275 | |
| Utilities for analyzing and visualizing Windows event logs from Sysmon, helping users track and monitor system activity. | 1,492 | |
| Automates analysis of Windows Security Events to identify user logon relations | 241 | |
| A PowerShell module for analyzing Windows event logs to detect and respond to potential security threats. | 2,203 | |
| An ASP.NET Core application demonstrating configuration and usage of NLog with various logging targets including MS SQL Server, PostgreSQL, MySQL, and Elasticsearch. | 60 | |
| Provides a searchable, exportable record of read/write events | 365 | |
| A toolset for analyzing Windows event logs to detect and analyze malware | 29 | |
| Analyzes Sysmon event logs to detect suspicious activity and visualize process and network correlations. | 419 | |
| An extension that provides logging capabilities to .NET Core applications using UDP and Redis transports. | 8 | |
| Operational guidelines and best practices for handling various types of security incidents | 982 | |
| Tracks and logs events in an audit log to maintain record of user activity and content lifecycle. | 5 | |
| Analyzes Windows Event Logs to identify security-related events and provides forensic tools for incident response. | 769 | |
| A tool for filtering and analyzing Windows event logs based on complex time-based conditions | 37 | |
| Converts Linux audit logs into standardized JSON format for enhanced security monitoring | 722 | |
| Provides an advanced Splunk configuration for collecting Windows log data relevant to threat detection, incident response, and forensic analysis. | 85 |