WELA (Windows Event Log Analyzer) aims to be the Swiss Army knife for Windows event logs. Currently, WELA's greatest functionality is creating an easy-to-analyze logon timeline in order to aid in fast forensics and incident response. WELA's logon timeline generator will consolidate only the useful information in multiple logon log entries (4624, 4634, 4647, 4672, 4776) into single events, perform data reduction by ignoring around 90% of the noise, and will convert any hard to read data (such as hex status codes) into human-readable format. Tested on Windows PowerShell 5.1 but may work with previous versions. It will unfortunately NOT work with PowerShell Core as there is no built-in functionality to read Windows event logs. Features: - The last SIGMA rule compliance in WELA is July 2021. If you want to use the latest SIGMA rules for evtx detection, please use Hayabusa. - Written in PowerShell so is easy to read and customize. - Fast Forensics Logon Timeline Generator. - Detect lateral movement, system usage, suspicious logons, vulnerable protocol usage, etc... - 90%+ noise reduction for logon events. - Calculate Logon Elapsed Time.
Common questions about WELA (Windows Event Log Analyzer) including features, pricing, alternatives, and user reviews.
WELA (Windows Event Log Analyzer) is Windows Event Log Analyzer with logon timeline generator and noise reduction for fast forensics. It is a Security Operations solution designed to help security teams with Windows.
WELA (Windows Event Log Analyzer) is a free Security Operations tool. This makes it accessible for organizations of all sizes, from startups to enterprises. Visit https://github.com/Yamato-Security/WELA/ for download and installation instructions.
Popular alternatives to WELA (Windows Event Log Analyzer) include:
Compare all WELA (Windows Event Log Analyzer) alternatives at https://cybersectools.com/alternatives/wela-windows-event-log-analyzer
WELA (Windows Event Log Analyzer) is for security teams and organizations that need Windows. It's particularly suitable for small to medium-sized teams looking for cost-effective solutions. Other Security Operations tools can be found at https://cybersectools.com/categories/security-operations
Head-to-head feature, pricing, and rating breakdowns.
A utility package that monitors hard drive health through SMART technology to detect and prevent disk failures before data loss occurs.
A library to access the Windows New Technology File System (NTFS) format with read-only support for NTFS versions 3.0 and 3.1.
A library for working with Windows NT data types, providing access and manipulation functions.
A collection of PowerShell modules for artifact gathering and reconnaissance of Windows-based endpoints.
A suite of console tools for working with timestamps in Windows with 100-nanosecond precision.