LogonTracer View LogonTracer
A method for log volume reduction without losing analytical capability.
Security Information and Event Management solutions for log management and security monitoring
A method for log volume reduction without losing analytical capability.
A cloud-native SIEM platform that provides security analytics, intuitive workflow, and simplified incident response to help security teams defend against cyber threats.
Elasticsearch is a versatile platform for centralized data storage, fast search, and scalable analytics.
Python library and command line tools for log visualization with interactive plots.
A tool collection for filtering and visualizing logon events, designed for experienced DFIR specialists in threat hunting and incident response.
A framework for generating log events without the need for infrastructure, allowing for simple, repeatable, and randomized log event creation.
Open source security data lake for AWS with real-time log normalization and Detection-as-Code capabilities.
A collection of free shareable log samples from various systems with evidence of compromise and malicious activity, maintained by Dr. Anton Chuvakin.
A toolset for collecting and processing netflow/ipfix and sflow data from netflow/sflow compatible devices.
AlienVault OSSIM provides an all-in-one security management solution with asset discovery, vulnerability assessment, and SIEM capabilities.
Python application to translate Zeek logs into ElasticSearch's bulk load JSON format with detailed instructions and features.
Graylog offers advanced log management and SIEM capabilities to enhance security and compliance across various industries.
Apache Metron is a centralized tool for security monitoring and analysis that integrates various open-source big data technologies.
Graylog offers advanced log management and SIEM capabilities to enhance security and compliance across various industries.
Investigate malicious logons by visualizing and analyzing Windows Active Directory event logs with LogonTracer.
A compliant audit log tool that provides a searchable, exportable record of read/write events.
HonnyPotter is a WordPress plugin that logs all failed login attempts, with a caution to use it at your own risk.
Sysmon for Linux is a tool that monitors and logs system activity with advanced filtering to identify malicious activity.
A toolset for collecting and processing netflow/ipfix and sflow data from netflow/sflow compatible devices.
A framework for generating log events without the need for infrastructure, allowing for simple, repeatable, and randomized log event creation.