WELA
PoShLog
WELA | PoShLog | |
---|---|---|
3 | 2 | |
678 | 177 | |
4.0% | 0.0% | |
0.0 | 0.0 | |
about 1 year ago | over 1 year ago | |
PowerShell | PowerShell | |
GNU General Public License v3.0 only | MIT License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
WELA
PoShLog
What are some alternatives?
hayabusa - Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.
CXXLog - HeaderOnly Logging Utilities
teler - Real-time HTTP Intrusion Detection
SKYAPI - PowerShell module for the Blackbaud SKY API
WindowsDFIR - Repository for different Windows DFIR related CMDs, PowerShell CMDlets, etc, plus workshops that I did for different conferences or events.
Gollum - An n:m message multiplexer written in Go
timesketch - Collaborative forensic timeline analysis
PSEventViewer - PSEventViewer (Get-Events) is really useful PowerShell wrapper around Get-WinEvent. One of the features you may be interested in is a simple way of getting “hidden” events data
chainsaw - Rapidly Search and Hunt through Windows Forensic Artefacts
livelog - Python logger and live reader
SIEM - SIEM Tactics, Techiques, and Procedures
WinLoginAudit - Send realtime Windows Login Audit trail to Telegram messenger