python-evtx
Zircolite
Our great sponsors
python-evtx | Zircolite | |
---|---|---|
2 | 4 | |
670 | 596 | |
- | - | |
1.6 | 7.5 | |
about 1 year ago | 23 days ago | |
Python | Python | |
Apache License 2.0 | - |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
python-evtx
-
analyzing Windows Event Logs on Linux
python-evtx should do the trick for you: https://github.com/williballenthin/python-evtx
-
Searching Windows Event logs for fun!
To be able to read the logs, we converted them to XML using python-evtx:
Zircolite
-
Chainsaw for Linux
You can compare with Zircolite which uses Sigma on Auditd, Sysmon For Linux or any JSON formatted logs. It works also on EVTX but that's not the subject.
- Zircolite: A standalone SIGMA-based detection tool for EVTX
- Zircolite - A standalone SIGMA-based detection tool for EVTX
- Battle-tested, standalone and fast SIGMA-based detection tool for EVTX or JSON
What are some alternatives?
mimikatz - A little tool to play with Windows security
sigma-essentials - Everything you need for the #grindset
evtx-hunter - evtx-hunter helps to quickly spot interesting security-related activity in Windows Event Viewer (EVTX) files.
Automata - Automatic detection engineering technical state compliance
prowler - Prowler is an Open Source Security tool for AWS, Azure, GCP and Kubernetes to do security assessments, audits, incident response, compliance, continuous monitoring, hardening and forensics readiness. Includes CIS, NIST 800, NIST CSF, CISA, FedRAMP, PCI-DSS, GDPR, HIPAA, FFIEC, SOC2, GXP, Well-Architected Security, ENS and more
rich - Rich is a Python library for rich text and beautiful formatting in the terminal.
mvt - MVT (Mobile Verification Toolkit) helps with conducting forensics of mobile devices in order to find signs of a potential compromise.
celery - Distributed Task Queue (development branch)
evtx2es - A library for fast parse & import of Windows Eventlogs into Elasticsearch.
automathon - A Python library for simulating and visualizing finite automata
WatchAD - AD Security Intrusion Detection System
labelImg - LabelImg is now part of the Label Studio community. The popular image annotation tool created by Tzutalin is no longer actively being developed, but you can check out Label Studio, the open source data labeling tool for images, text, hypertext, audio, video and time-series data.