-
InfluxDB
Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.
Can also pull Windows Event logs, chuck it through a tool like EvtxECmd and then open the output file in TimelineExplorer and go digging for events occuring plus minus a few minutes from that alert. Also can look at anomalous RDP connections or use of explicit creds but it seems like you might have done this already.
NOTE:
The number of mentions on this list indicates mentions on common posts plus user suggested alternatives.
Hence, a higher number means a more popular project.
Related posts
-
Fast import of Windows EventLogs(.evtx) into Elasticsearch.
-
Hayabusa: Sigma-based forensics timeline generator for Windows event logs
-
Release v2.5.0 🦅 of Hayabusa - Hayabusa is a Windows event log fast forensics timeline generator and threat hunting tool
-
Is it possible to analyze old Windows Event Logs to find IOAs or IOCs with Wazuh?
-
Analysing Hayabusa Results with jq