Zurück zum Ranking

sbousseaden/EVTX-ATTACK-SAMPLES

HTMLgithub.com/sbousseaden/EVTX-ATTACK-SAMPLES

Windows Events Attack Samples

threat-huntingevtxwindows-securitymitre-attackdetection-engineeringdatasetwinlogbeatdfir
Sterne-Wachstum
Sterne
2.6k
Forks
433
Wochenwachstum
Issues
4
1k2k
März 2019Aug. 2021Feb. 2024Juli 2026
README

Windows EVTX Samples [200 EVTX examples]:

alt text

This is a container for windows events samples associated to specific attack and post-exploitation techniques. Can be useful for:

  • Testing your detection scripts based on EVTX parsing

  • Training on DFIR and threat hunting using event logs

  • Designing detection use cases using Windows and Sysmon event logs

  • Avoid/Bypass the noisy techniques if you are a redteamer

N.B: Mapping has been done to the level of ATT&CK technique (not procedure).

Details of the EVTX content mapped to MITRE tactics can be found here, stats summary:

alt text

alt text

Overview of the covered TTPs using attack-navigator:

alt text

Winlogbeat-Bulk-Read

Included is a PowerShell script that can loop through, parse, and replay evtx files with winlogbeat. This can be useful to replay logs into an ELK stack or to a local file. By default this script will output logs to .\winlogbeat\events.json as configured in the winlogbeat_example.yml file, you can configure any of your own destinations in winlogbeat.yml (excluded from git) and the example config file will be ignored if winlogbeat.yml is found.

Winlogbeat-Bulk-Read Usage:

## Display help along with examples:
.\Winlogbeat-Bulk-Read.ps1 -Help

## Run with defaults (read ./ recursively and look for winlogbeat.exe in your path):
.\Winlogbeat-Bulk-Read.ps1

## If you want to point this script at another directory with evtx files and specify a path to the winlogbeat.exe binary:
.\Winlogbeat-Bulk-Read.ps1 -Exe ~\Downloads\winlogbeat\winlogbeat.exe -Source "..\EVTX-ATTACK-SAMPLES\"

License:

EVTX_ATT&CK's GNU General Public License

Ähnliche Repositories
mukul975/Anthropic-Cybersecurity-Skills

817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0

PythonPyPIApache License 2.0ai-agentsclaude-code
mahipal.engineer/Anthropic-Cybersecurity-Skills/
26.3k3.2k
OISF/suricata

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine developed by the OISF and the Suricata community.

CGNU General Public License v2.0securityids
suricata.io
6.5k1.7k
MISP/MISP

MISP (core software) - Open Source Threat Intelligence and Sharing Platform

PHPPackagistGNU Affero General Public License v3.0mispthreat-sharing
misp-project.org
6.4k1.6k
elceef/dnstwist

Domain name permutation engine for detecting homograph phishing attacks, typo squatting, and brand impersonation

PythonPyPIApache License 2.0phishingtyposquatting
dnstwist.it
5.7k849
SwiftOnSecurity/sysmon-config

Sysmon configuration file template with default high-quality event tracing

sysmonthreatintel
5.6k1.9k
Security-Onion-Solutions/securityonion

Security Onion is a free and open platform for threat hunting, enterprise security monitoring, and log management. It includes our own interfaces for alerting, dashboards, hunting, PCAP, detections, and case management. It also includes other tools such as osquery, CyberChef, Elasticsearch, Logstash, Kibana, Suricata, and Zeek.

ShellOthercase-managementcyber-security
securityonion.net
4.8k666
0x4D31/awesome-threat-detection

✨ A curated list of awesome threat detection and hunting resources 🕵️‍♂️

awesomeawesome-list
0x4d31.github.io/awesome-threat-detection/
4.7k757
intelowlproject/IntelOwl

IntelOwl: manage your Threat Intelligence at scale

PythonPyPIGNU Affero General Public License v3.0security-toolspython
intelowlproject.github.io
4.6k650
OTRF/ThreatHunter-Playbook

A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.

PythonPyPIMIT Licensethreat-huntingsysmon
4.6k855
pedramamini/awesome-yara

A curated list of awesome YARA rules, tools, and people.

Otheryara-rulesyara-signatures
4.3k553
alexandreborges/malwoverview

Malwoverview is a first response tool for threat hunting across VirusTotal, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, Malpedia, Malware Bazaar, ThreatFox, Triage, IPInfo, Shodan, AbuseIPDB, GreyNoise, URLScan.io, Whois/RDAP, NIST, and VulnCheck. Supports LLM enrichment, IOC extraction, YARA scanning, and Android analysis.

PythonPyPIGNU General Public License v3.0malwarevirustotal
github.com/alexandreborges/malwoverview
3.9k535
Cyb3rWard0g/HELK

The Hunting ELK

Jupyter NotebookGNU General Public License v3.0huntingelasticsearch
3.9k690