{"repo":"JPCERTCC/LogonTracer","free":true,"listed":false,"github":"https://github.com/JPCERTCC/LogonTracer","clone":"git clone https://github.com/JPCERTCC/LogonTracer.git","description":"Investigate malicious Windows logon by visualizing and analyzing Windows event log","language":"Python","stars":3211,"topics":["security","dfir","javascript","visualization","active-directory","event-log","blueteam","python-3"],"license":null,"category":"security-tools","readme_excerpt":"Concept LogonTracer v2 is a tool to investigate malicious logon by visualizing and analyzing Windows Active Directory event logs. This tool associates a host name (or an IP address) and account name found in logon-related events and displays it as a graph. This way, it is possible to see in which account login attempt occurs and which host is used. This tool can visualize the following event IDs related to Windows logon. Event ID Description ---------- ------------- 4624 Successful logon 4625 Logon failure 4662 An operation was performed on an object 4672 Assign special privileges 4719 System audit policy was changed 4720 A user account was created 4726 A user account was deleted 4728 / 4732 / 4756 A member was added to a security-enabled group 4729 / 4733 / 4757 A member was removed from a security-enabled group 4768 Kerberos Authentication (TGT Request) 4769 Kerberos Service Ticket (ST Request) 4776 NTLM Authentication 5137 A directory service object was created 5141 A directory service object was deleted More details are described in the following documents: - Visualise Event Logs to Identify Compromised Accounts - LogonTracer - - イベントログを可視化して不正使用されたアカウントを調査 (Japanese) --- What's New in Version 2.0 AI-Powered Security Analysis LogonTracer v2.0 integrates an AI analysis engine using OpenAI GPT models to provide intelligent threat detection beyond traditional rule-based approaches. - Security Pattern Analysis — Automatically interprets graph query results and generates risk ","default_branch":null,"files":null,"tree":[],"storefront":"/r/JPCERTCC","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/JPCERTCC/LogonTracer/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}