Suspicious batch file

This page summarizes the projects mentioned and recommended in the original post on /r/cybersecurity

InfluxDB - Power Real-Time Data Analytics at Scale
Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.
www.influxdata.com
featured
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com
featured
  • evtx

    C# based evtx parser with lots of extras (by EricZimmerman)

  • Can also pull Windows Event logs, chuck it through a tool like EvtxECmd and then open the output file in TimelineExplorer and go digging for events occuring plus minus a few minutes from that alert. Also can look at anomalous RDP connections or use of explicit creds but it seems like you might have done this already.

  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

    InfluxDB logo
NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts

  • Fast import of Windows EventLogs(.evtx) into Elasticsearch.

    1 project | /r/blueteamsec | 11 Jul 2021
  • Hayabusa: Sigma-based forensics timeline generator for Windows event logs

    1 project | news.ycombinator.com | 24 Apr 2024
  • Release v2.5.0 🦅 of Hayabusa - Hayabusa is a Windows event log fast forensics timeline generator and threat hunting tool

    1 project | /r/blueteamsec | 7 May 2023
  • Is it possible to analyze old Windows Event Logs to find IOAs or IOCs with Wazuh?

    5 projects | /r/Wazuh | 8 Feb 2023
  • Analysing Hayabusa Results with jq

    1 project | /r/blueteamsec | 16 Jan 2023