WELA (Windows Event Log Analyzer) Logo

WELA (Windows Event Log Analyzer)

Windows Event Log Analyzer with logon timeline generator and noise reduction for fast forensics.

92
Visit website
Compare
Compare
0
MCPThe entire cybersecurity market, one prompt awayTry MCP Access

WELA (Windows Event Log Analyzer) Description

WELA (Windows Event Log Analyzer) aims to be the Swiss Army knife for Windows event logs. Currently, WELA's greatest functionality is creating an easy-to-analyze logon timeline in order to aid in fast forensics and incident response. WELA's logon timeline generator will consolidate only the useful information in multiple logon log entries (4624, 4634, 4647, 4672, 4776) into single events, perform data reduction by ignoring around 90% of the noise, and will convert any hard to read data (such as hex status codes) into human-readable format. Tested on Windows PowerShell 5.1 but may work with previous versions. It will unfortunately NOT work with PowerShell Core as there is no built-in functionality to read Windows event logs. Features: - The last SIGMA rule compliance in WELA is July 2021. If you want to use the latest SIGMA rules for evtx detection, please use Hayabusa. - Written in PowerShell so is easy to read and customize. - Fast Forensics Logon Timeline Generator. - Detect lateral movement, system usage, suspicious logons, vulnerable protocol usage, etc... - 90%+ noise reduction for logon events. - Calculate Logon Elapsed Time.

WELA (Windows Event Log Analyzer) FAQ

Common questions about WELA (Windows Event Log Analyzer) including features, pricing, alternatives, and user reviews.

WELA (Windows Event Log Analyzer) is Windows Event Log Analyzer with logon timeline generator and noise reduction for fast forensics.. It is a Security Operations solution designed to help security teams with Windows.

Have more questions? Browse our categories or search for specific tools.

ALTERNATIVES

Axence ConnectPro Logo

Remote access and IT support tool for workstation management and diagnostics

0
ElcomSoft Advanced PDF Password Recovery Logo

Recovers/removes passwords and restrictions from encrypted PDF files.

0
ElcomSoft Advanced Office Password Recovery Logo

Password recovery tool for MS Office, WordPerfect, Lotus & other office docs.

0
ElcomSoft Advanced EFS Data Recovery Logo

Decrypts EFS-protected files on NTFS volumes across Windows versions.

0
ElcomSoft Adv. Archive Password Recovery Logo

Password recovery tool for encrypted ZIP, 7Zip, and RAR archives.

0

Stay Updated with Mandos Brief

Get strategic cybersecurity insights in your inbox