Skip to content
View mthcht's full-sized avatar
🏠
Working from home
🏠
Working from home

Sponsors

@kick707

Highlights

  • Pro

Organizations

@lolc2

Block or report mthcht

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Stars

logs

43 repositories

Transform Linux Audit logs for SIEM usage

Rust 1 Updated Aug 3, 2023

Explore Kernel Objects on Windows

C++ 1 Updated Jun 19, 2023

A Fast (and safe) parser for the Windows XML Event Log (EVTX) format

Rust 1 Updated Apr 13, 2023

Snoopy Command Logger is a small library that logs all program executions on your Linux/BSD system.

C 1 Updated Sep 13, 2023

Combining Sealighter with unpatched exploits to run the Threat-Intelligence ETW Provider

C 1 Updated Dec 6, 2022

A log pattern analyzer CLI

Python 1 Updated Jan 6, 2022

Expose a lot of MDE telemetry that is not easily accessible in any searchable form

Go 103 6 Updated Dec 12, 2024

Event Tracing For Windows (ETW) Resources

1 Updated Apr 17, 2023

SSH Session Monitoring Daemon

C 488 24 Updated May 12, 2023

Set of Mindmaps providing a detailed overview of the different #Microsoft auditing capacities for Windows, Exchange, Azure,...

1,059 182 Updated Sep 4, 2024

Handbook of windows forensic artifacts across multiple Windows version with interpretation tips and some examples. Work in progress!

308 34 Updated Aug 13, 2024

A Splunk Technology Add-on to forward filtered ETW events.

C# 30 3 Updated Oct 14, 2020

A Fast (and safe) parser for the Windows XML Event Log (EVTX) format

Rust 714 66 Updated Nov 3, 2024

Evtx to Splunk ingestor

Python 15 8 Updated Mar 18, 2022

Sysmon for Linux

C 1,801 191 Updated Jan 29, 2025

This project aims to compare and evaluate the telemetry of various EDR products.

Python 2 Updated Nov 22, 2024
C++ 201 29 Updated Jan 28, 2025

A repository of curated datasets from various attacks

Python 614 97 Updated Jan 29, 2025

Generate datasets of cloud audit logs for common attacks

Go 195 16 Updated Aug 9, 2024

Set of EVTX samples (>270) mapped to MITRE ATT&CK tactic and techniques to measure your SIEM coverage or developed new use cases.

543 90 Updated Jan 15, 2025

Documentation and scripts to properly enable Windows event logs.

Batchfile 583 53 Updated Sep 20, 2023

Re-play Security Events

PowerShell 1,620 238 Updated Mar 20, 2024

Windows Events Attack Samples

HTML 2,292 406 Updated Jan 24, 2023

A tool that allows you to create vulnerable instrumented local or cloud environments to simulate attacks against and collect the data into Splunk

Jinja 2,213 367 Updated Jan 30, 2025

Deep Linux runtime visibility meets Wireshark

C 257 11 Updated Jan 16, 2025

Linux Runtime Security and Forensics using eBPF

Go 3,736 431 Updated Jan 30, 2025