Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/jurelou/epagneul
ForensicsLog Analysis
GitHubjurelou/epagneul

epagneul

Graph Visualization for windows event logs

View Repository
2513341 year agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Vue logo

epagneul

Epagneul is a tool to visualize and investigate windows event logs.

layout

Deployment

Requires docker and docker-compose to be installed.

Installing

root@kitploit:~
make

Offline deployment

On a machine connected to internet, build an offline release:

root@kitploit:~
make release

This will create a release folder containing ready to go docker images. Copy the project to your air gapped machine then run:

root@kitploit:~
make load
make

This will install:

  • epagneul web UI (port 8080)
  • epagneul backend (port 8000)
  • neo4j (port 7474)

Utility Tool: Upload Files or Folders to Epagneul

The project includes a Python utility to upload EVTX or JSONL files to Epagneul for analysis.

Features

  • Automatically creates folders in the Epagneul backend.
  • Validates and uploads EVTX or JSONL files.
  • Supports single file or folder uploads.

Usage

Run the following command to use the tool:

root@kitploit:~
python upload.py --input-path <path_to_file_or_folder> --folder-name <folder_name> --console-url <console_url> [--console-port <port>]

Arguments

  • --input-path: Path to the file or folder containing EVTX or JSONL files.
  • --folder-name: Name of the folder to create in Epagneul.
  • --console-url: Base URL of the Epagneul backend (e.g., http://127.0.0.1).
  • --console-port: Port of the Epagneul backend (default: 6327).

todos

  • Better SID corelations
  • add edge tips
  • Label propagation algorithm
  • PageRank
  • Add missing events IDs (sysmon)
  • Proper conversion of known SIDS / security principals, ...
  • hidden markov chains
  • Display a timeline of logons / at least a summary graph
  • check out: https://github.com/ahmedkhlief/APT-Hunter
  • Import data from ELK / splunk
  • detect communities using louvain
  • Document evtx filtering method using filter 3,4648,4624,4625,4672,4768,4769,4771,4776,4728,4732,4756

Known bugs

  • The count value on edges does not update based on the selected timeline

References:

  • https://adsecurity.org/wp-content/uploads/2017/04/2017-BSidesCharm-DetectingtheElusive-ActiveDirectoryThreatHunting-Final.pdf
  • https://github.com/JPCERTCC/LogonTracer

Built With

  • Vue.js - The web framework used
  • Cytoscape.js - Library used for graph visualisation and analysis
  • d3 - Used to display the timeline
  • neo4j - Backend database
  • evtx - Parser for the windows XML EventLog format

Authors

  • jurelou - Initial work - jurelou
Download Tool