Windows EVTX Samples [200 EVTX examples] Logo

Windows EVTX Samples [200 EVTX examples]

0
Free
Visit Website

This container provides 200 Windows events samples related to specific attack and post-exploitation techniques, useful for testing detection scripts, training on DFIR and threat hunting, and designing detection use cases using Windows and Sysmon event logs. It includes a PowerShell script for parsing and replaying EVTX files with Winlogbeat.

FEATURES

ALTERNATIVES

A Splunk app mapped to MITRE ATT&CK to guide threat hunts.

Freely available network IOCs for monitoring and incident response

Amazon GuardDuty is a threat detection service for AWS accounts.

Parse IOCs from text

A free software that calculates the security ranking of Internet Service Providers to detect malicious activities.

Platform for the latest threat intelligence information

A cybersecurity concept categorizing indicators of compromise based on their level of difficulty for threat actors to change.

Maldatabase is a threat intelligence platform providing malware datasets and threat intelligence feeds for malware data science and threat intelligence.

PINNED