Skip to content
#

event-log-analysis

Here are 4 public repositories matching this topic...

Language: All
Filter by language

Windows EVTX log analysis for DFIR — fast parsing, ATT&CK mapping, IOC extraction, and Sentinel anomaly detection. Normal + Juggernaut Mode (Arrow/DuckDB) for 10M+ events.

  • Updated May 20, 2026
  • Python

BeCode AD lab on Azure : build, harden, detect. 11 MITRE techniques, 11/11 detection rate. External credential-stuffing capture as real-world validation.

  • Updated May 19, 2026
  • HTML

This project aims to redesign Windows audit policy configurations to reduce log noise and enhance detection clarity within Splunk. The objective is to produce a streamlined, purposeful audit policy that supports effective threat detection, baselining, and investigative workflows in a lab or SOC simulation environment.

  • Updated Jun 30, 2025
  • Jupyter Notebook

Improve this page

Add a description, image, and links to the event-log-analysis topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the event-log-analysis topic, visit your repo's landing page and select "manage topics."

Learn more