Simple Windows Event Log Forwarder (SWELF). Its easy to use/simply works Log Forwarder and EVTX Parser. Almost in full release here at https://github.com/ceramicskate0/SWELF/releases/latest.
Feature should be a command in the search config that can be IP or part of domain. Use sysmon by default or if it has a logname in search use search all feature to find if a log has contacted a domain.
Ideas:
possibly use network_connect command and if middle arg is not a number then do this search?
Feature should be a command in the search config that can be IP or part of domain. Use sysmon by default or if it has a logname in search use search all feature to find if a log has contacted a domain.
Ideas: possibly use network_connect command and if middle arg is not a number then do this search?