{"id":13497600,"url":"https://github.com/nsacyber/Event-Forwarding-Guidance","last_synced_at":"2025-03-28T22:31:47.889Z","repository":{"id":25595217,"uuid":"29029905","full_name":"nsacyber/Event-Forwarding-Guidance","owner":"nsacyber","description":"Configuration guidance for implementing collection of security relevant Windows Event Log events by using Windows Event Forwarding. #nsacyber","archived":true,"fork":false,"pushed_at":"2020-11-17T17:25:51.000Z","size":143,"stargazers_count":850,"open_issues_count":9,"forks_count":165,"subscribers_count":98,"default_branch":"master","last_synced_at":"2024-10-31T14:36:29.290Z","etag":null,"topics":["event-log","siem","windows"],"latest_commit_sha":null,"homepage":"","language":"PowerShell","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/nsacyber.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE.md","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2015-01-09T18:40:23.000Z","updated_at":"2024-10-11T03:25:34.000Z","dependencies_parsed_at":"2022-07-07T22:53:15.620Z","dependency_job_id":null,"html_url":"https://github.com/nsacyber/Event-Forwarding-Guidance","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nsacyber%2FEvent-Forwarding-Guidance","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nsacyber%2FEvent-Forwarding-Guidance/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nsacyber%2FEvent-Forwarding-Guidance/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nsacyber%2FEvent-Forwarding-Guidance/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/nsacyber","download_url":"https://codeload.github.com/nsacyber/Event-Forwarding-Guidance/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":246110245,"owners_count":20725021,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["event-log","siem","windows"],"created_at":"2024-07-31T20:00:34.427Z","updated_at":"2025-03-28T22:31:47.612Z","avatar_url":"https://github.com/nsacyber.png","language":"PowerShell","funding_links":[],"categories":["Windows","\u003ca id=\"ac43a3ce5a889d8b18cf22acb6c31a72\"\u003e\u003c/a\u003eETW","Resources"],"sub_categories":["Ubuntu","\u003ca id=\"0af4bd8ca0fd27c9381a2d1fa8b71a1f\"\u003e\u003c/a\u003e工具","Event ID configuration and monitoring suggestions"],"readme":"# Event Forwarding Guidance\r\n\r\nThis repository hosts content for aiding administrators in collecting security relevant Windows event logs using Windows Event Forwarding (WEF). This repository is a companion to [Spotting the Adversary with Windows Event Log Monitoring](https://apps.nsa.gov/iaarchive/library/ia-guidance/security-configuration/applications/assets/public/upload/Spotting-the-Adversary-with-Windows-Event-Log-Monitoring.pdf) paper. The list of events in this repository are more up to date than those in the paper.\r\n\r\nThe repository contains:\r\n\r\n* [Recommended Windows events](./Events/) to collect. Regardless of using WEF or a third party SIEM, the list of recommended events should be useful as a starting point for what to collect. The list of events in this repository are more up to date than those in the paper.\r\n* [Scripts](./scripts/) to create custom Event Log views and create WEF subscriptions.\r\n* [WEF subscriptions](./Subscriptions/) in XML format.\r\n\r\n## Links\r\n\r\n* [Microsoft Windows Event Forwarding resources](https://aka.ms/wef)\r\n* [Use Windows Event Forwarding to help with intrusion detection](https://docs.microsoft.com/en-us/windows/security/threat-protection/use-windows-event-forwarding-to-assist-in-intrusion-detection)\r\n* [Windows 10 and Windows Server 2016 security auditing and monitoring reference](https://www.microsoft.com/en-us/download/details.aspx?id=52630)\r\n* [Microsoft's Threat Protection: Advanced security audit policy settings](https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/advanced-security-audit-policy-settings)\r\n* [Microsoft's Threat Protection: Security auditing](https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/security-auditing-overview)\r\n* [List of important events from Microsoft](https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/plan/appendix-l--events-to-monitor)\r\n* [Microsoft SysInternals Sysmon](https://docs.microsoft.com/en-us/sysinternals/downloads/sysmon)\r\n* [ACSC GitHub Windows Event Logging repository](https://github.com/AustralianCyberSecurityCentre/windows_event_logging)\r\n* [ACSC Windows Event Logging Technical Guidance](https://acsc.gov.au/publications/protect/Windows_Event_Logging_Technical_Guidance.pdf)\r\n* [Creating Custom Windows Event Forwarding Logs](https://blogs.technet.microsoft.com/russellt/2016/05/18/creating-custom-windows-event-forwarding-logs/)\r\n* [Introducing Project Sauron](https://blogs.technet.microsoft.com/russellt/2017/05/09/project-sauron-introduction/)\r\n* [Project Sauron GitHub repository](https://github.com/russelltomkins/project-sauron)\r\n* [Windows Event Forwarding for Network Defense](https://medium.com/palantir/windows-event-forwarding-for-network-defense-cb208d5ff86f)\r\n* [Palantir Windows Event Forwarding GitHub repository](https://github.com/palantir/windows-event-forwarding)\r\n\r\n## License\r\n\r\nSee [LICENSE](./LICENSE.md).\r\n\r\n## Disclaimer\r\n\r\nSee [DISCLAIMER](./DISCLAIMER.md).\r\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fnsacyber%2FEvent-Forwarding-Guidance","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fnsacyber%2FEvent-Forwarding-Guidance","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fnsacyber%2FEvent-Forwarding-Guidance/lists"}