awesome-event-ids
by stuhli
Collection of Event ID ressources useful for Digital Forensics and Incident Response
AI summary
Event IDs
A collection of Event ID resources useful for Digital Forensics and Incident Response
- stars
- 593
- forks
- 85
- watching
- 24
- awesome list
- 1
- entries
- 61
What's in the list
61 links in 19 sections, with live GitHub stats.activeno commit in 2y
Resources / Event ID databases
- EventTracker Knowledgebase
Database
- MyEventlog.com
Database
Resources / Event ID documentation
- Kaspersky Security for Microsoft Exchange
Official resource
- Microsoft Defender Antivirus
Official resource
- Microsoft Windows Security Auditing
Official resource
- Microsoft Windows Security Auditing by Randy Franklin Smith
Better known as
Notable Event IDs
Collection of common event IDs with descriptions
- Sysmon
Official resource
- Symantec Endpoint Protection 14.0.X
Official resource
- Symantec Endpoint Protection Manager
Official resource
- Events and Errors - Windows Server 2008
Collection of event IDs from different windows event source. Applies to Windows Server 2008 and similar. (Official resource)
- Finding Forensic Goodness In Obscure Windows Event Logs
List of lesser-known Event IDs
Resources / Event ID configuration and monitoring suggestions / General
- Audit Policy Recommendations
Audit Policy Recommendations by Microsoft
SIEM Tactics, Techniques, and Procedures
Comprehensive SIEM resources be TonyPhipps
Windows Auditing Mindmap
Set of Mindmaps providing a detailed overview of the different Windows auditing capacities and event log files
Resources / Event ID configuration and monitoring suggestions / PowerShell
- Script Block Logging
Enable 4104
Resources / Event ID configuration and monitoring suggestions / Security Auditing
- Command line Process Auditing
Enable 4688 featuring command line
- Critical Windows Event ID's to Monitor
Monitoring suggestions
- Events to Monitor
Official resource
Monitoring Guidance
Event monitoring guidance from JSCU (Joint SIGINT Cyber Unit) from Netherlands. With volume estimates, and WEC/WEF configurations
- Malware Archeology Splunk Logging Cheat Sheet
about specific exclusions to avoid getting noise from the Splunk Universal Forwarder agent
- US NSA Spotting the Adversary with Windows Event Log Monitoring
Covers quite a lot of ground
Resources / Event ID configuration and monitoring suggestions / Security Auditing / US NSA Spotting the Adversary with Windows Event Log Monitoring
US NSA Event Forwarding Guidance
Companion repository with WEF configurations, scripts to configure WEF, and WEB subscriptions in XML format
Resources / Event ID configuration and monitoring suggestions / Security Auditing
- Windows Security Monitoring - Policy & Event IDs
Spreadsheet with recommendations sorted by system functions
- EventID Policy Map
Spreadsheet with policy map as well as reference collection
- Windows security event log library
Small database with explanations and monitoring suggestions
Resources / Event ID configuration and monitoring suggestions / Sysmon
Configuration by SwiftOnSecurity
Configuration file template with default high-quality event tracing
Resources / Event ID configuration and monitoring suggestions / Sysmon / Configuration by SwiftOnSecurity
Fork of SwiftOnSecurity by Neo23x0 Florian ROTH
Same as above, with all PR
Resources / Event ID configuration and monitoring suggestions / Sysmon
Configuration by olafhartong
A repository of Sysmon configuration modules
Resources / Event ID analysis / General
EVTX Attack Samples
EVTX samples recorded during attack simulations by sbousseaden
EVTX-to-MITRE-Attack
More than 170 EVTX samples matched to MITRE TTPs provided by
- Tool Analysis Result Sheet
Logs analyzed after tool execution by JPCERT
EvtxECmd Map Repository
Maps used by Eric Zimmerman's EvtxECmd which provide examples of Event IDs with documentation, lookup tables, and important values within each respective event ID which are parsed by EvtxECmd using the associated Map
- Event Log Observer
View, analyze and monitor events recorded in Microsoft Windows event logs
Splunk advanced input configuration for Windows
Provides an advanced input.conf file for Windows and 3rd party related software with more than 70 different event log mapped to the MITRE Att&CK
Windows Security Event ID Helper
[ ] Will allow you to filter on each GPO setting and display all Event IDs produced by it
Resources / Event ID analysis / Antivirus
- Antivirus Event Analysis Cheat Sheet
Antivirus Event Analysis Cheat Sheet
Resources / Event ID analysis / PowerShell
- Attack and Defense Around PowerShell Event Logging
PowerShell logging deep dive from different perspectives by Mina Hao
Resources / Event ID analysis / RDP
- RDP Logon / Logoff events 1
RDP event chain by Jonathon Poling
- RDP Logon / Logoff events 2
RDP deep dive on 1149 by Mike Cary
Resources / Event ID analysis / SMB
Resources / Event ID analysis / Task Scheduler
- Task Scheduler Event IDs
List of the most common Event IDs for Windows Scheduled Tasks by mnaoumov
Resources / Event ID analysis / Windows Remote Command Execution
- Traces of Windows remote command execution
Blogpost focused on remote command execution techniques used by attackers and read teamers and detailed logging recommendations
Resources / Event ID analysis / Windows Specific Event IDs
- Windows Event ID 4776 [SOLVED]
Blogpost explaining the meaning of 4776 by Diego Asturias
Contributing
Nothing in this list matches your filter.
Featured in 1 awesome list
Each link jumps to the spot where the list mentions awesome-event-ids.
More related projects
yamato-security/hayabusa2.4K
clong/detectionlab4.7K
mhaggis/sysmon-dfir901
yamato-security/wela769
geeksniper/active-directory-pentest156
withsecurelabs/chainsaw2.9K
swiftonsecurity/orgkit597
withsecurelabs/leonidas535
karneades/malware-persistence165
redcanaryco/atomic-red-team10K
palantir/alerting-detection-strategy-framework703
drewnoakes/metadata-extractor-dotnet953
drewnoakes/metadata-extractor2.6K