
sysmon-parser
Automatically generated Sysmon parser for Azure Sentinel

Automatically generated Sysmon parser for Azure Sentinel

Chronicle parser for CORELIGHT and related information.

Multi-host UFW firewall dashboard — explains rules in plain English, detects security gaps, and provides connection diagnostics

Digital forensics engine that parses logs, files, and system artifacts to build super timelines, enabling chronological event correlation for…

Parses iOS and iPadOS forensic extractions into HTML, TSV, timeline, KML, and LAVA reports with modular artifact discovery and encrypted iTunes…

Android Logs Events And Protobuf Parser

A Fast (and safe) parser for the Windows XML Event Log (EVTX) format

Collect, parse, normalize, aggregate, store, query, and route security telemetry data at scale using pipeline-based dataflows for threat detection…

Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)

A cross platform parser for Apple UnifiedLogs!

Parser for $LogFile on NTFS

Open-source Windows forensics engine that acquires, parses, and correlates artifacts (MFT, USN, Registry, etc.) to reconstruct timelines with…

Parses Snaffler output file and generate beautified outputs.

Event Trace Log file parser in pure Python

This tool parses log data and allows to define analysis pipelines for anomaly detection. It was designed to run the analysis with limited resources…

Parse, filter, and visualize Suricata eve.json logs with CLI tools for alerts, flows, DNS, and payloads. Includes a tutorial for learning Suricata…

Proof-of-concept telemetry collector for Windows LDAP client activity via ETW, logging structured events to Event Viewer with a Sentinel parser for…

Parses Windows .evtx logs to identify remote connections and public IPs by analyzing EventIDs related to remote logins and sessions.