EVTX-to-MITRE-Attack

Log indicators

Provides Windows log event indicators mapped to MITRE ATT&CK tactic and techniques

Set of EVTX samples (>270) mapped to MITRE ATT&CK tactic and techniques to measure your SIEM coverage or developed new use cases.

GitHub

532 stars
26 watching
89 forks
last commit: about 2 years ago
Linked from 1 awesome list

evtxmitre-attackredteamsiemthreat-hunting

Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
mitre/advmlthreatmatrixA framework to help security analysts understand and prepare for adversarial machine learning attacks on AI systems1,056
mitre/ctiA repository providing threat intelligence data in STIX format for security analysis and automation1,765
sbousseaden/evtx-attack-samplesA repository of Windows Event log samples associated with various attack and post-exploitation techniques.2,265
mdecrevoisier/splunk-input-windows-baselineProvides an advanced Splunk configuration for collecting Windows log data relevant to threat detection, incident response, and forensic analysis.85
mdecrevoisier/microsoft-eventlog-mindmapProvides detailed mindmaps on Microsoft auditing capacities and event logs for security and monitoring1,048
mtnmunuklu/alterixConverts detection rules and IOCs to be usable with a proprietary SIEM product15
yarox24/evtkitTool to repair Windows Event Log files (.evt) acquired during forensic investigations18
misp/misp-maltegoAn integration tool for Maltego to leverage MISP threat intelligence and the MITRE ATT&CK dataset171
nshalabi/attack-toolsUtilities for simulating adversary behavior in the context of threat intelligence and security analysis1,011
vernamlab/medusaAutomated attack synthesis tool for discovering vulnerabilities in CPU architecture and cryptographic protocols18
ericzimmerman/evtxTool to parse Event Viewer logs and extract useful information283
mitre/brawl-public-game-001Automates testing of cybersecurity detection and response capabilities in a controlled network environment202
cybersecurityup/mitre-attack-matrixA comprehensive resource for understanding and visualizing the relationships between different types of cyber attacks and their tactics, techniques, and procedures.18
yamato-security/hayabusa-sample-evtxA collection of sample event log files used for testing and development of threat detection rules45
redcanaryco/atomic-red-teamA portable set of tests mapped to the MITRE ATT&CK framework for evaluating security environments.9,951