Splunk-input-windows-baseline

Windows log collector

Provides an advanced Splunk configuration for collecting Windows log data relevant to threat detection, incident response, and forensic analysis.

Provides an advanced input.conf file for Windows and 3rd party related software with more than 70 different event log mapped to the MITRE Att&CK

GitHub

85 stars
5 watching
10 forks
last commit: almost 2 years ago
Linked from 1 awesome list


Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
mdecrevoisier/evtx-to-mitre-attackProvides Windows log event indicators mapped to MITRE ATT&CK tactic and techniques532
anssi-fr/dfir-o365rcA PowerShell module for collecting and analyzing logs from Microsoft 365 and Azure systems252
mdecrevoisier/microsoft-eventlog-mindmapProvides detailed mindmaps on Microsoft auditing capacities and event logs for security and monitoring1,048
west-wind/threat-hunting-with-splunkProvides Splunk queries to detect vulnerability exploitation attempts and subsequent compromise, including threat hunting for MITRE ATT&CK TTPs58
inodee/threathunting-splProvides Splunk code and prototypes for building rules and queries to detect malicious activity268
spujadas/elk-dockerA pre-configured Docker image for Elasticsearch, Logstash, and Kibana to facilitate log management and analysis.2,160
securityjoes/forensicminerAutomates evidence collection and analysis from Windows machines using PowerShell.149
nshalabi/sysmontoolsUtilities for analyzing and visualizing Windows event logs from Sysmon, helping users track and monitor system activity.1,492
splunk/botsv2A comprehensive security dataset and CTF platform for analysis and training of information security professionals.358
danielmartensson/opensourceloggerSoftware for collecting and analyzing measurement data from industrial equipment.18
thiber-org/userlineAutomates analysis of Windows Security Events to identify user logon relations241
mlsecproject/combineTool to gather Threat Intelligence indicators from publicly available sources657
jscu-nl/logging-essentialsProvides guidance on configuring and collecting Windows event logs to enhance forensic analysis and incident response capabilities.276
yamato-security/welaAnalyzes Windows Event Logs to identify security-related events and provides forensic tools for incident response.769
improsec/sharpeventpersistTools to write and read shellcode from Event Log using C# and Windows persistence mechanisms367