
Zircolite
A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs
forensicsincident-responselog-analysis+1

A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs

Active Directory Forensic Toolkit : Detect & reconstruct AD attacks from Windows event logs (EVTX)

High-speed Windows forensic triage platform that orchestrates the Hayabusa engine to transform raw EVTX logs into prioritized threat timelines with…

Evtx Log (xml) Browser