Advanced Windows Event Log threat hunter in pure PowerShell — Sigma-subset detection, correlation engine, per-entity risk scoring, self-contained HTML reports. Zero dependencies, air-gap ready.
-
Updated
Jun 5, 2026 - PowerShell
Advanced Windows Event Log threat hunter in pure PowerShell — Sigma-subset detection, correlation engine, per-entity risk scoring, self-contained HTML reports. Zero dependencies, air-gap ready.
This project aims to redesign Windows audit policy configurations to reduce log noise and enhance detection clarity within Splunk. The objective is to produce a streamlined, purposeful audit policy that supports effective threat detection, baselining, and investigative workflows in a lab or SOC simulation environment.
A modern Flet-based UI for PM4PY that enables process mining, discovery, conformance checking, filtering, and analysis of event logs without writing code.
BeCode AD lab on Azure : build, harden, detect. 11 MITRE techniques, 11/11 detection rate. External credential-stuffing capture as real-world validation.
Add a description, image, and links to the event-log-analysis topic page so that developers can more easily learn about it.
To associate your repository with the event-log-analysis topic, visit your repo's landing page and select "manage topics."