process-forest

Process analyzer

Tools for reconstructing historical process hierarchies from Windows event logs.

Reconstruct process trees from event logs

GitHub

146 stars
16 watching
29 forks
Language: Python
last commit: about 6 years ago

Related projects:

RepositoryDescriptionStars
williballenthin/lfleRecover event log entries from an image by identifying record structures.27
illusivenetworks-labs/historicprocesstreeAnalyzes Windows event log data to visualize historic process execution evidence in a tree view.59
williballenthin/python-evtA Python module for parsing classic Windows Event Log files (.evt)49
williballenthin/python-evtxA Python module for parsing Windows Event Log files (.evtx) into structured data732
williballenthin/evtxtractReconstructs fragments of event log data from raw binary files, including unallocated space and memory images.191
williballenthin/shellbagsThis tool helps reconstruct user activities by parsing Windows Registry data.151
williballenthin/python-ntfsA Python library for analyzing and working with NTFS file systems.81
logzio/sawmillEnables JSON document transformation and enrichment with configurable pipelines and patterns116
andrew-plowright/foresttoolsA collection of R functions for analyzing and processing remote sensing forest data to detect and segment individual trees.68
monaxgt/parsefieldsTool for analyzing and structuring log data from JSON-like sources7
thiber-org/userlineAutomates analysis of Windows Security Events to identify user logon relations241
ahmedkhlief/apt-hunterA tool to analyze Windows event logs for signs of APT attacks and malware activity.1,265
yarox24/evtkitTool to repair Windows Event Log files (.evt) acquired during forensic investigations18
h0mbre/busychildA utility that analyzes and displays detailed information about processes and their relationships with other processes.24
glouppe/phd-thesisAn in-depth analysis of random forests, focusing on their learning capabilities and interpretability.525