Windows EVTX Samples [200 EVTX examples] Logo

Windows EVTX Samples [200 EVTX examples]

0
Free
Updated 11 March 2025
Visit Website

This container provides 200 Windows events samples related to specific attack and post-exploitation techniques, useful for testing detection scripts, training on DFIR and threat hunting, and designing detection use cases using Windows and Sysmon event logs. It includes a PowerShell script for parsing and replaying EVTX files with Winlogbeat.

FEATURES

SIMILAR TOOLS

Maltego transform pack for analyzing and graphing Honeypots using MySQL data.

A tool for tracking, scanning, and filtering yara files with distributed scanning capabilities.

RedEye is a visual analytic tool for enhancing Red and Blue Team operations.

Provides indicators of compromise (IOCs) to combat malware with Yara and Snort rules.

The Cybersecurity and Infrastructure Security Agency (CISA) is a government agency that provides alerts, advisories, and resources to help protect the United States' critical infrastructure from cyber threats.

Python APIs for serializing and de-serializing STIX2 JSON content with higher-level APIs for common tasks.

Unified repository for Microsoft Sentinel and Microsoft 365 Defender containing security content, detections, queries, playbooks, and resources to secure environments and hunt for threats.

An all-in-one email outreach platform for finding and connecting with professionals, with features for lead discovery, email verification, and cold email campaigns.

Silent Push Platform provides preemptive cyber defense by identifying malicious infrastructure before attacks are launched using Indicators of Future Attack (IOFA)™ technology.

CyberSecTools logoCyberSecTools

Explore the largest curated directory of cybersecurity tools and resources to enhance your security practices. Find the right solution for your domain.

Operated by:

Mandos Cyber • KVK: 97994448

Netherlands • contact@mandos.io

Copyright © 2025 - All rights reserved