gwen001 / offsectools_www

A vast collection of security tools and resources curated by the community.
https://offsec.tools
179 stars 21 forks source link

[addtool] LogonTracer #1929

Closed gwen001 closed 1 month ago

gwen001 commented 1 month ago

[tags]authentication,windows,defense[/tags] [short_descr]Investigate malicious Windows logon by visualizing and analyzing Windows event log.[/short_descr] [link] https://github.com/JPCERTCC/LogonTracer [/link] [long_descr] LogonTracer is a tool to investigate malicious logon by visualizing and analyzing Windows Active Directory event logs. This tool associates a host name (or an IP address) and account name found in logon-related events and displays it as a graph. This way, it is possible to see in which account login attempt occurs and which host is used.

This tool can visualize the following event id related to Windows logon:

gwen001 commented 1 month ago

Issue correctly handled, tool is waiting for human validation.

gwen001 commented 1 month ago

Tool has been accepted by the team: https://offsec.tools/tool/logontracer

Thank you for your contribution!