Awesome Lists

awesome-event-ids

by stuhli

awesome listpushed over 2 years ago

Collection of Event ID ressources useful for Digital Forensics and Incident Response

AI summary

Event IDs

A collection of Event ID resources useful for Digital Forensics and Incident Response

stars
593
forks
85
watching
24
awesome list
1
entries
61
View on GitHub

Embed the badge

Show how many awesome lists link to your project. The count updates automatically.

Awesome Lists badge
Markdown
[![Awesome Lists Badge](https://awesome.facts.dev/shield/stuhli/awesome-event-ids/links.svg)](https://awesome.facts.dev/awesome/stuhli/awesome-event-ids)
HTML
<a href="https://awesome.facts.dev/awesome/stuhli/awesome-event-ids"><img src="https://awesome.facts.dev/shield/stuhli/awesome-event-ids/links.svg" alt="Awesome Lists Badge" /></a>
Image URL
https://awesome.facts.dev/shield/stuhli/awesome-event-ids/links.svg

What's in the list

61 links in 19 sections, with live GitHub stats.activeno commit in 2y

Resources / Event ID databases

Resources / Event ID documentation

Resources / Event ID configuration and monitoring suggestions / General

Resources / Event ID configuration and monitoring suggestions / PowerShell

Resources / Event ID configuration and monitoring suggestions / Security Auditing

Resources / Event ID configuration and monitoring suggestions / Security Auditing / US NSA Spotting the Adversary with Windows Event Log Monitoring

Resources / Event ID configuration and monitoring suggestions / Security Auditing

Resources / Event ID configuration and monitoring suggestions / Sysmon

Resources / Event ID configuration and monitoring suggestions / Sysmon / Configuration by SwiftOnSecurity

Resources / Event ID configuration and monitoring suggestions / Sysmon

Resources / Event ID analysis / General

  • EVTX Attack Samples

    EVTX samples recorded during attack simulations by sbousseaden

  • EVTX-to-MITRE-Attack

    More than 170 EVTX samples matched to MITRE TTPs provided by

  • Tool Analysis Result Sheet

    Logs analyzed after tool execution by JPCERT

  • EvtxECmd Map Repository

    Maps used by Eric Zimmerman's EvtxECmd which provide examples of Event IDs with documentation, lookup tables, and important values within each respective event ID which are parsed by EvtxECmd using the associated Map

  • Event Log Observer

    View, analyze and monitor events recorded in Microsoft Windows event logs

  • Splunk advanced input configuration for Windows

    Provides an advanced input.conf file for Windows and 3rd party related software with more than 70 different event log mapped to the MITRE Att&CK

  • Windows Security Event ID Helper

    [ ] Will allow you to filter on each GPO setting and display all Event IDs produced by it

Resources / Event ID analysis / Antivirus

Resources / Event ID analysis / PowerShell

Resources / Event ID analysis / RDP

Resources / Event ID analysis / SMB

Resources / Event ID analysis / Task Scheduler

Resources / Event ID analysis / Windows Remote Command Execution

Resources / Event ID analysis / Windows Specific Event IDs

Contributing

More related projects

Add a GitHub project

Missing a project or an awesome list? Paste its GitHub URL and we fetch it right away.