
Audits Windows event log settings against best-practice guidelines and Sigma-rule detectability, with automated configuration for DFIR readiness.
A tool for auditing Windows event log settings.
Created by Yamato Security — make sure you are
actually recording the events that matter for DFIR.
WELA (Windows Event Log Analyzer, ゑ羅) is a tool for auditing Windows event log settings. Windows event logs are a vital source of information for Digital Forensics and Incident Response (DFIR) — WELA checks your audit policy and log file sizes against best-practice guidelines and real-world Sigma-rule detectability, and can apply the recommended settings for you.
All documentation now lives on a dedicated, searchable, multi-language site:
👉 yamato-security.github.io/WELA
Grab the latest release from the Releases page.
The previous single-page README is preserved unchanged:
Contributions and bug reports are welcome — see Contributing & Support. WELA is released under the MIT license.
| Section |
|---|
| 🚀 Getting Started | Prerequisites, downloads and running WELA |
| ⌨️ Command Reference | audit-settings, audit-filesize, configure, update-rules |
| ✨ Features | What WELA can do |
| 📦 Resources | Companion projects, changelog, contributing |