{"repo":"Yamato-Security/EnableWindowsLogSettings","free":true,"listed":false,"github":"https://github.com/Yamato-Security/EnableWindowsLogSettings","clone":"git clone https://github.com/Yamato-Security/EnableWindowsLogSettings.git","description":"Documentation and scripts to properly enable Windows event logs.","language":"Batchfile","stars":718,"topics":["auditing","dfir","event","forensics","hayabusa","logs","monitoring","security","sigma","sysmon"],"license":"GPL-3.0","category":"analytics","readme_excerpt":"Yamato Security's Windows Event Log Configuration Guide For DFIR And Threat Hunting [ English ] [ 日本語 ] This is yet another guide on properly configuring and monitoring Windows event logs with an emphasis on logging for sigma rules. This is a work in progress, so check back please periodically for updates. TLDR You can only use around 10 20% of sigma detection rules with the default Windows audit settings. Even if a Windows log is enabled, by default, the maximum size for logs is between 1 20 MB so there is a good chance that evidence gets quickly overwritten. Enable the proper audit settings with YamatoSecurityConfigureWinEventLogs.bat or WELA (Windows Event Log Auditor) to use up to around 75% of sigma rules and retain logs for as long as you need them. - Warning: make sure you customize the script to your needs and test before using in production! Install sysmon to get full coverage. ( Highly recommended! ) Companion Projects Hayabusa - sigma-based threat hunting and fast forensics timeline generator for Windows event logs. Hayabusa Rules - detection rules for hayabusa. Hayabusa Sample EVTXs - Sample evtx files to use for testing hayabusa/sigma detection rules. Takajo - Analyzer for hayabusa results. WELA (Windows Event Log Auditor) - A tool for auditing Windows event log settings. Table of Contents - TLDR - Companion Projects - Table of Contents - Author - Contributors - Acknowledgements - Problems with the default Windows log settings - Warning: Make changes to your syst","default_branch":null,"files":null,"tree":[],"storefront":"/r/Yamato-Security","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Yamato-Security/EnableWindowsLogSettings/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}