awesome-event-ids
Collection of Event ID ressources useful for Digital Forensics and Incident Response
https://github.com/stuhli/awesome-event-ids
Last synced: about 4 hours ago
JSON representation
-
Contributing
-
Event ID analysis
-
-
Resources
-
Event ID analysis
- EvtxECmd Map Repository - Maps used by Eric Zimmerman's EvtxECmd which provide examples of Event IDs with documentation, lookup tables, and important values within each respective event ID which are parsed by EvtxECmd using the associated Map.
- Event Log Observer - View, analyze and monitor events recorded in Microsoft Windows event logs.
- Antivirus Event Analysis Cheat Sheet - Antivirus Event Analysis Cheat Sheet.
- Attack and Defense Around PowerShell Event Logging - PowerShell logging deep dive from different perspectives by Mina Hao.
- RDP Logon / Logoff events 1 - RDP event chain by Jonathon Poling.
- RDP Logon / Logoff events 2 - RDP deep dive on 1149 by Mike Cary.
- Task Scheduler Event IDs - List of the most common Event IDs for Windows Scheduled Tasks by mnaoumov.
- Traces of Windows remote command execution - Blogpost focused on remote command execution techniques used by attackers and read teamers and detailed logging recommendations.
- EVTX Attack Samples - EVTX samples recorded during attack simulations by sbousseaden.
- EVTX-to-MITRE-Attack - More than 170 EVTX samples matched to MITRE TTPs provided by [mdecrevoisier](https://twitter.com/mdecrevoisier)
- Tool Analysis Result Sheet - Logs analyzed after tool execution by JPCERT.
- Splunk advanced input configuration for Windows - Provides an advanced input.conf file for Windows and 3rd party related software with more than 70 different event log mapped to the MITRE Att&CK.
- Windows Security Event ID Helper - [_Work in progress_] Will allow you to filter on each GPO setting and display all Event IDs produced by it.
- Windows Event ID 4776 [SOLVED - Blogpost explaining the meaning of 4776 by Diego Asturias.
-
Event ID configuration and monitoring suggestions
- Audit Policy Recommendations - Audit Policy Recommendations by Microsoft.
- PowerShell Logging for the Blue Team
- UK NCSC - Logging Made Easy WEC (Windows Event Collection) Configuration File
- Windows Security Monitoring - Policy & Event IDs - Spreadsheet with recommendations sorted by system functions.
- EventID Policy Map - Spreadsheet with policy map as well as reference collection.
- Windows security event log library - Small database with explanations and monitoring suggestions.
- Critical Windows Event ID's to Monitor - Monitoring suggestions.
- SIEM Tactics, Techniques, and Procedures - Comprehensive SIEM resources be TonyPhipps.
- Monitoring Guidance - Event monitoring guidance from JSCU (Joint SIGINT Cyber Unit) from Netherlands. With volume estimates, and WEC/WEF configurations.
- US NSA Event Forwarding Guidance - Companion repository with WEF configurations, scripts to configure WEF, and WEB subscriptions in XML format.
- Yamato Security's Ultimate Windows Event Log Configuration Guide For DFIR And Threat Hunting
- Configuration by SwiftOnSecurity - Configuration file template with default high-quality event tracing.
- Fork of SwiftOnSecurity by Neo23x0 Florian ROTH - Same as above, with all PR.
- Configuration by olafhartong - A repository of Sysmon configuration modules.
- Sysmon Community Guide
- Greater Visibility Through PowerShell Logging
- Windows Auditing Mindmap - Set of Mindmaps providing a detailed overview of the different Windows auditing capacities and event log files.
-
Event ID databases
- EventTracker Knowledgebase - Database
- MyEventlog.com - Database
-
Event ID documentation
- Kaspersky Security for Microsoft Exchange - Official resource.
- Microsoft Windows Security Auditing by Randy Franklin Smith - Better known as _Ultimate Windows Security_.
- Notable Event IDs - Collection of common event IDs with descriptions.
- Symantec Endpoint Protection 14.0.X - Official resource.
- Symantec Endpoint Protection Manager - Official resource.
- Events and Errors - Windows Server 2008 - Collection of event IDs from different windows event source. Applies to Windows Server 2008 and similar. (Official resource)
- Finding Forensic Goodness In Obscure Windows Event Logs - List of lesser-known Event IDs.
-
Programming Languages
Categories
Sub Categories
Keywords
security
6
dfir
5
threat-hunting
5
windows
4
awesome-list
3
siem
3
forensics
3
sysmon
3
mitre-attack
3
forensic-analysis
2
digital-forensics
2
monitoring
2
logging
2
awesome
2
evtx
2
cybersecurity
1
computer-forensics
1
incident-response
1
event-log
1
incident-response-tooling
1
security-tools
1
modular
1
list
1
threatintel
1
dataset
1
sysinternals
1
netsec
1
detection-engineering
1
winlogbeat
1
windows-security
1
metadata
1
investigative-journalism
1
events
1
eventid
1
audit
1
redteam
1
sigma
1
logs
1
hayabusa
1
event
1
auditing
1
triage
1
threat
1
team
1
soc
1
scan
1
response
1
red
1
recon
1
purple
1