Renzon Profile picture
23 Nov, 8 tweets, 4 min read
1\ #dfirtips #dfir #infosec

Windows Event Logs can be daunting especially if it's a lot. No one can actually sit in front of their computer to check each of those logs one by one thru a manual approach. Here are some of the newest EVTX tools that can really save our lives as IR
2\ #Zircolite can be very useful where you can use your favorite sigma rules to detect bad stuff

github.com/wagga40/Zircol…
3\ #Chainsaw is such a wonderful tool and it's SO FAST! Whatever EVTX logs you have during your engagement, you can literally get a result in a few minutes. Shoutout to @countercept for having this for free to us!

github.com/countercept/ch…
4\ DeepBlueCli from Eric Conrad made my life easier during the early days when chainsaw and zircolite still do not exist. Still a fairly good PowerShell tool to automate your evtx findings

github.com/sans-blue-team…
5\ Event Log Explorer is still useful when doing manual stuff and when combining different evtx channels (Powershell, security, application) combined all together. It's also fast at performing strings search

eventlogxp.com
6\ The great Eric Zimmerman also has his own evtx tool to. Event log (evtx) parser with standardized CSV, XML, and json output! Custom maps, locked file support, and more!

ericzimmerman.github.io/#!index.md
7\ If you want to visualize your EVTX and do all these fancy stuff like graphs, filters and play around with any charts, I highly recommend my friend's project made from ELK and different parsers, all for DFIR folks. Shoutout to my friend @Maboalenen

github.com/Maboalenen/DFIR
8\ anything to add on this thread full of amazing tools? Let me know #dfirtip #infosec

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Renzon

Renzon Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @r3nzsec

20 Nov
Dealing with a bunch of memory #forensics lately so I just dump fairly new tools that are useful to all #dfir #incidentresponse out there:
MemProcFS - convenient and easy to use
BulkExtractor - extracts everything into a text file and grep it
SuperMem - CS tool for quick triage
Read 4 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Thank you for your support!

Follow Us on Twitter!

:(