{"id":13599256,"url":"https://github.com/miriamxyra/EventList","last_synced_at":"2025-04-10T12:32:01.139Z","repository":{"id":53607205,"uuid":"190014268","full_name":"miriamxyra/EventList","owner":"miriamxyra","description":"EventList","archived":false,"fork":false,"pushed_at":"2021-03-21T14:43:11.000Z","size":345,"stargazers_count":375,"open_issues_count":10,"forks_count":40,"subscribers_count":33,"default_branch":"development","last_synced_at":"2025-04-02T05:44:11.765Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":"PowerShell","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/miriamxyra.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2019-06-03T13:47:53.000Z","updated_at":"2025-04-01T17:34:33.000Z","dependencies_parsed_at":"2022-08-26T08:10:21.067Z","dependency_job_id":null,"html_url":"https://github.com/miriamxyra/EventList","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/miriamxyra%2FEventList","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/miriamxyra%2FEventList/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/miriamxyra%2FEventList/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/miriamxyra%2FEventList/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/miriamxyra","download_url":"https://codeload.github.com/miriamxyra/EventList/tar.gz/refs/heads/development","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":248217131,"owners_count":21066633,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-01T17:01:01.397Z","updated_at":"2025-04-10T12:31:59.744Z","avatar_url":"https://github.com/miriamxyra.png","language":"PowerShell","funding_links":[],"categories":["PowerShell"],"sub_categories":[],"readme":"# EventList\n\n![alt text](https://miriamxyra.files.wordpress.com/2019/05/eventlist.png?w=300 \"EventList Logo\")\n\nEventList is a tool to help improving your Audit capabilities and to help to build your Security Operation Center.\n\nIt helps you combining Microsoft Security Baselines with MITRE ATT\u0026CK and generating hunting queries for your SIEM system - regardless of the product used.\n\n## Installation\n\nInstall-Module -Name EventList -Force\n\n### PowerShell module dependencies\n\nEventList requires the following PowerShell modules to work properly:\n- PSFramework\n- PSSQLite\n- powershell-yaml\n\n## Usage\n\nOnce the module is installed, you can open EventList by calling\n    Open-EventListGUI\nin powershell.exe as an administrator. The EventList GUI opens.\n\nImportant: Do not use powershell_ise.exe to open the GUI, otherwise the resolution might not be at optimum.\n\n## Baselines\n\nThere are already some baselines pre-populated in the database.\n\nYou can choose a baseline from the drop down menu top left. Once a baseline is chosen, the MITRE ATT\u0026CK checkboxes are being populated. Like this, you can easily check which MITRE ATT\u0026CK techniques and areas are being covered by this particular baseline.\n\n### Importing baselines\n\nNevertheless, if there are baselines missing, you can import them by using the “Import Baseline(s)” button. Choose the folder where your baseline(s) is/are located to import them. Imports baselines recursively.\n\nBaselines which were already imported into the database won’t be overwritten.\n\n### Deleting baselines\n\nIf you want to delete one or more particular baseline(s) from the database, “Delete baseline(s)” will help you doing so. You can either decide if you want to delete the baseline which was selected from the drop down menu or if you want to start over and delete all baselines imported.\n\n## YAML Admin\n\nYAML files are needed when it comes to importing and processing Sigma queries.\n\nYou can either import new YAML configuration files or delete them.\n\n### Import YAML configuration files\nYou can import new YAML configuration files. Already existing configurations won’t be overwritten by using this option. To overwrite YAML configurations, you should delete all existing configurations and import them again.\n\n### Delete YAML configuration files\nThis option will delete all YAML configurations, that are stored in the EventList database.\n\n## Configure EventList \n\n### Sigma integration\n\nPrerequisites: Sigma needs to be installed on the client, on which EventList is being used.\n\nTo integrate the Sigma framework into EventList, you can use “Configure EventList” to set the path to the Sigma installation.\n\nTo configure it successfully, choose the path where sigmac is located (tools/sigmac). If sigmac is not present, the configuration will be discarded.\n\n## Generate EventList\n\nThis function provides you with an option to generate a list of the events, that are being generated when either \n\t- Applying a certain baseline \n\t- Selecting several MITRE ATT\u0026CK techniques/areas\n\nIf you check the “generate .csv” checkbox, you can choose an output folder, where your generated file will be located. A .csv Version of the list is being generated.\n\n## Generate Agent configuration \n\nAs you might not want to forward all your generated Event Ids, you can use the “Generate Agent Configuration” to create a configuration snippet that you can just pipe into your agent configuration.\n\nSupported Agents:\n\t- Splunk\n\n## Generate GPOs\n\nIf you want to convert all events, that are being generated for the checked MITRE ATT\u0026CK areas \u0026 techniques, into a GPO, use the button “Generate GPOs”.\n\nHint: if you select an already imported baseline to convert it into a GPO again, there’s a high chance that a different GPO will be generated than the imported. The reason behind that is, that not all events are matched to the MITRE ATT\u0026CK framework, that are being generated by a baseline.\n\n## Generate Queries \n\nUsing the “Generate Queries” button, you can generate hunting queries, matching the selected MITRE ATT\u0026CK areas and techniques.\n\nThere are several options to create such a query.\n\n### Sigma queries \n\nIf you want to use Sigma to convert your query into your preferred query language, you can use the option “Please generate SIGMA queries for”.\n\nA drop down is available to choose from all supported SIEM/Hunting systems:\n\nSupported SIEM/Hunting systems:\n- Azure Log Analytics\n- ArcSight\n- ElasticSearch Query Strings\n- ElasticSearch Query DSL\n- Kibana\n- Elastic X-Pack Watcher\n- Graylog\n- Logpoint\n- Grep\n- RSA NetWitness\n- PowerShell\n- QRadar\n- Qualys\n- Splunk\n- Microsoft Defender ATP\n\n### Converting queries directly \nIf Sigma is installed and configured for EventList, EventList will automatically use Sigma to parse the queries into the SIEM language of your choice.\n\nThree files will be generated in your output folder:\n- EventList-Queries.md\n    - This file contains every query which will be successfully converted by Sigma, ordered by MITRE ATT\u0026CK areas \u0026 techniques. As it’s formatted using markdown, you can easily copy \u0026 paste it into your documentation system of your choice.\n- SigmaLog.txt\n    - In this file you will find the Output which is being generated by Sigma. If a query isn’t supported by Sigma, you can find the name of the query, including the Sigma output, in here. Like this, you have either the option to build the query manually or to participate in the Sigma project to implement the missing functionality.\n- EventList-Queries.txt\n    - All generated queries without any documentation or query titles to copy \u0026 paste it into your SIEM system. Easy as it.\n\nThere will be also a folder generated which is called “yaml”. In this folder you will find all  yaml files, according to the generated queries.\n\n### Converting queries in the backend \n\nIf you have a Sigma backend, there’s also the option to generate the commands to convert the particular yaml files. They are still being sorted by using the MITRE ATT\u0026CK matrix.\n\nIf Sigma is not configured (via Configure EventList), this option will be used as default.\n\nTwo files are being generated:\n- EventList-Queries.md\n    - This file contains every command which will be used to convert your YAML files by your Sigma backend, ordered by MITRE ATT\u0026CK areas \u0026 techniques. As it’s formatted using markdown, you can easily copy \u0026 paste it into your documentation system of your choice.\n- EventList-Queries.txt\n    - All generated commands to convert your YAML files in your Sigma backend without any documentation or query titles to copy \u0026 paste it into your SIEM system.\n\nThere will be also a folder generated which is called “yaml”. In this folder you will find all  yaml files, according to the generated queries.\n\n### Generate YAML\n\nIf you don’t want to use Sigma at all, there’s still an option to only generate a YAML markdown file:\nIt is still ordered by the MITRE ATT\u0026CK areas \u0026 techniques, but it’s still only the YAML configuration in there. Use it as a hint which events to use for your hunting queries.\n\n\nHappy hunting!\n\n# EventList Change Log\n## 2021-03-21\n- Added new event sources: PowerShell Operational Log, WinRM, Windows Defender, Windows PowerShell, PowerShell DSC, Applocker: Packaged app-Deployment, Applocker: MSI and Script, Applocker: EXE and DLL, Applocker: Packaged app-Execution\n- Added new columns in events_source: Full Name, Log Path\n- Added more event ids to the database: PowerShell\n- Changed events_main structure: the PK \"id\" is no longer treated as the event id of each event. Column \"event_id\" was added instead. This should avoid conflicts with matching event ids in different event logs","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmiriamxyra%2FEventList","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fmiriamxyra%2FEventList","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmiriamxyra%2FEventList/lists"}