palantir/windows-event-forwarding

A repository for using windows event forwarding for incident detection and response

RoffPowerShellocto-correct-managed
This is stars and forks stats for /palantir/windows-event-forwarding repository. As of 05 May, 2024 this repository has 1172 stars and 269 forks.

Windows Event Forwarding Guidance About This Repository Over the past few years, Palantir has a maintained an internal Windows Event Forwarding (WEF) pipeline for generating and centrally collecting logs of forensic and security value from Microsoft Windows hosts. Once these events are collected and indexed, alerting and detection strategies (ADS) can be constructed not only on high-fidelity security events (e.g. log deletion), but also for deviations from normalcy, such as unusual service account...
Read on GithubGithub Stats Page
repotechsstarsweeklyforksweekly
Fxzzi/.dotsRoffShellScheme79060
RhinoSecurityLabs/CVEsPythonShellHTML68002180
twpayne/chezmoiGoShellPowerShell10.1k04460
dosdude1/macos-catalina-patcherObjective-CRoffRich Text Format3910560
FuzzySecurity/PowerShell-SuitePowerShellCC#2.5k07930
shani5maurya/AWS-RDPBatchfilePowerShell00850
Azure/appservice-landing-zone-acceleratorBicepHCLShell160+373+1
catzsec/ForceAdminC#BatchfilePowerShell2350420
keeganwitt/docker-gradleDockerfileShellPowerShell1330680
accupara/docker-imagesDockerfileMakefileShell19030