Windows EVTX Samples [200 EVTX examples] Logo

Windows EVTX Samples [200 EVTX examples]

0
Free
Visit Website

This container provides 200 Windows events samples related to specific attack and post-exploitation techniques, useful for testing detection scripts, training on DFIR and threat hunting, and designing detection use cases using Windows and Sysmon event logs. It includes a PowerShell script for parsing and replaying EVTX files with Winlogbeat.

FEATURES

ALTERNATIVES

A Splunk app mapped to MITRE ATT&CK to guide threat hunts.

DNSDumpster is a domain research tool for discovering and analyzing DNS records to map an organization's attack surface.

A system for collecting, managing, and distributing security information on a large scale, developed by CERT Polska.

Machinae is a tool for collecting intelligence from public sites/feeds about various security-related pieces of data.

C# wrapper around Yara pattern matching library with Loki and Yara signature support.

A comprehensive Threat Intelligence Program Management Solution for managing the entire CTI lifecycle.

A nonprofit security organization that collects and shares threat data to make the Internet more secure.

A PowerShell script to interact with the MITRE ATT&CK Framework via its own API using the deprecated MediaWiki API.

CyberSecTools logoCyberSecTools

Explore the largest curated directory of cybersecurity tools and resources to enhance your security practices. Find the right solution for your domain.

Copyright © 2024 - All rights reserved