WELA (Windows Event Log Analyzer) Logo

WELA (Windows Event Log Analyzer)

0
Free
Visit Website

WELA (Windows Event Log Analyzer) aims to be the Swiss Army knife for Windows event logs. Currently, WELA's greatest functionality is creating an easy-to-analyze logon timeline in order to aid in fast forensics and incident response. WELA's logon timeline generator will consolidate only the useful information in multiple logon log entries (4624, 4634, 4647, 4672, 4776) into single events, perform data reduction by ignoring around 90% of the noise, and will convert any hard to read data (such as hex status codes) into human-readable format. Tested on Windows PowerShell 5.1 but may work with previous versions. It will unfortunately NOT work with PowerShell Core as there is no built-in functionality to read Windows event logs. Features: - The last SIGMA rule compliance in WELA is July 2021. If you want to use the latest SIGMA rules for evtx detection, please use Hayabusa. - Written in PowerShell so is easy to read and customize. - Fast Forensics Logon Timeline Generator. - Detect lateral movement, system usage, suspicious logons, vulnerable protocol usage, etc... - 90%+ noise reduction for logon events. - Calculate Logon Elapsed Time.

FEATURES

ALTERNATIVES

GrokEVT is a tool for reading Windows event log files and converting them to a human-readable format.

Free

ELAT (Event Log Analysis Tool) is a tool that helps in analyzing Windows event logs for malware detection.

Free

Serverless, real-time data analysis framework for incident detection and response.

Free

Browse a library of EQL analytics now natively integrated in Elasticsearch.

Free

An Event Hub to gather, process, and monitor system events and link them to an inventory.

Free

A log management solution that optimizes SIEM performance, provides rapid search and troubleshooting, and meets compliance requirements.

Commercial

A tool that collects and displays user activity and system events on a Windows system.

Free

A pure Python parser for Windows Event Log files with access to File and Chunk headers, record templates, and event entries.

Free

PINNED