APT-Hunter

Event log analyzer

A tool to analyze Windows event logs for signs of APT attacks and malware activity.

APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of windows event logs to decrease the time to uncover suspicious activity

GitHub

1k stars
47 watching
238 forks
Language: Python
last commit: almost 2 years ago
Linked from 1 awesome list

apt-attacksforensic-analysisincident-responsepurpleteampython3threat-huntingwindows-event-logswindows-eventlog

Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
reed1713/elatA toolset for analyzing Windows event logs to detect and analyze malware29
sans-blue-team/deepbluecliA PowerShell module for analyzing Windows event logs to detect and respond to potential security threats.2,203
yamato-security/welaAnalyzes Windows Event Logs to identify security-related events and provides forensic tools for incident response.769
airbus-cert/timelinerA tool for filtering and analyzing Windows event logs based on complex time-based conditions37
antagon/tchunt-ngA tool that uses various tests to identify and analyze encrypted files on a filesystem.52
fox-it/dissect.etlA parser for Event Trace Log files used by the Windows operating system to log kernel events.2
hasherezade/hollows_hunterAnalyzes running processes to detect and dump malicious code2,047
mvelazc0/orianaA tool for analyzing Windows event logs to identify potential security threats and suspicious behavior in corporate environments.177
thiber-org/userlineAutomates analysis of Windows Security Events to identify user logon relations241
williballenthin/python-evtxA Python module for parsing Windows Event Log files (.evtx) into structured data732
erickramirezds/cass_log_toolsA collection of scripts for analyzing and summarizing Apache Cassandra logs.9
ydkhatri/mac_aptA digital forensics tool for analyzing macOS and iOS systems790
fox-it/dissect.eventlogProvides parsers for parsing Windows log file formats6
miriamxyra/eventlistAn automation tool that integrates Microsoft Security Baselines and MITRE ATT&CK to generate hunting queries for security operation centers.370
jpcertcc/sysmonsearchAnalyzes Sysmon event logs to detect suspicious activity and visualize process and network correlations.419