awesome-repositories.com
المدونة
awesome-repositories.com

اكتشف أفضل مستودعات المصادر المفتوحة باستخدام بحث مدعوم بالذكاء الاصطناعي.

استكشفعمليات بحث منسقةبدائل مفتوحة المصدربرمجيات ذاتية الاستضافةالمدونةخريطة الموقع
المشروعحولكيفية ترتيب النتائجالصحافةخادم MCP
قانونيالخصوصيةالشروط
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
JPCERTCC avatar

JPCERTCC/LogonTracer

0
View on GitHub↗
3,136 نجوم·485 تفرعات·Python·other·7 مشاهدات

LogonTracer

LogonTracer is a security auditing tool designed for logon analysis and forensic log auditing. It functions as a dockerized security auditor that utilizes a security event graph database to map account names and network addresses, allowing for the visualization of complex system compromise patterns and authentication paths.

The system features a Sigma detection engine that scans imported event logs against standardized rule sets to identify known malicious activity. It also includes an anomalous behavior detector that applies statistical analysis, graph algorithms, and hidden Markov models to identify suspicious hosts and user accounts.

The tool manages security investigations through case-isolated data storage and independent databases with per-user access controls. Its broader capabilities include security log ingestion, AI-powered threat analysis, and certificate-based network encryption for securing data during transit.

The application is provided as a container image to ensure consistent installation and runtime across different operating systems.

Features

  • Authentication Pattern Analysis - Tracks user authentication patterns within system logs to identify security risks and potential account compromises.
  • Forensic Log Auditors - Provides a dockerized security auditor for managing isolated investigation cases and performing forensic log analysis.
  • Relational Visualizations - Maps account names and network addresses into a graph to visually identify patterns of system compromise.
  • Hidden Markov Model Detection - Utilizes hidden Markov models and statistical algorithms to identify suspicious behavioral patterns across hosts and accounts.
  • Graph Databases - Utilizes a relational graph database to map accounts and network addresses for compromise pattern visualization.
  • Graph-Relational Databases - Maps account and network data into a graph database to analyze complex authentication paths.
  • User Behavior Analysis - Applies statistical analysis, graph algorithms, and Markov models to identify suspicious user and host behavior.
  • Rule-Based Detection Engines - Evaluates imported event data against standardized Sigma rule sets to identify malicious activity.
  • Behavioral Analysis Engines - Applies graph algorithms and hidden Markov models to detect anomalous security behavior among hosts and accounts.
  • User Behavior Anomaly Detection - Uses mathematical models and ranking algorithms to identify suspicious host and user account behavior.
  • Sigma Rule Matching - Evaluates event logs against standardized Sigma rule sets to identify known malicious activity.
  • Threat Relationship Visualizations - Maps account names and network addresses into a graph to visually identify system compromise patterns.
  • Event Logging - Converts raw event logs into searchable graph databases to enable relational analysis and security investigations.
  • Anomaly Detection - Uses mathematical models and ranking algorithms to identify suspicious hosts and accounts within event logs.
  • Log Ingestion - Ingests raw event data into a graph database to enable complex relational security analysis.
  • Threat - Scans imported logs against standardized Sigma rule sets to identify known malicious activity.
  • Case-Isolated Storage - Implements independent data silos for separate security investigation cases to maintain strict access control.
  • AI-Powered Threat Detection - Provides an AI-powered engine that assesses risk against known attack tactics to generate automated detection rules.
  • Investigation Case Management - Provides isolated investigation databases with per-user access controls to maintain separate security audits.
  • Event Log Importing - Converts raw log data into a searchable database using custom timezones and date filters.
  • Log Analysis Tools - Visualizes and analyzes Windows logon events.
  • Windows Artifact Analysis - Visualizes and analyzes Windows logon activity.
  • Forensics and Incident Response - Visualizes and analyzes Windows logon events.
  • Blue Team Tools - Visualizes Windows logon events.
  • Digital Forensics - Tool for visualizing and analyzing Windows logon events.
  • Incident Response Frameworks - Visualizes and analyzes Windows event logs to investigate malicious logons.
  • Security Assessment Tools - Visualization tool for investigating malicious Windows logon events.
  • Windows Artifact Analysis - Tool for visualizing and analyzing Windows logon events.

سجل النجوم

مخطط تاريخ النجوم لـ jpcertcc/logontracerمخطط تاريخ النجوم لـ jpcertcc/logontracer

بحث بالذكاء الاصطناعي

استكشف المزيد من المستودعات الرائعة

صف ما تحتاجه بلغة بسيطة — وسيقوم الذكاء الاصطناعي بترتيب آلاف المشاريع مفتوحة المصدر المنسقة حسب الصلة.

Start searching with AI

بدائل مفتوحة المصدر لـ LogonTracer

مشاريع مفتوحة المصدر مشابهة، مرتبة حسب عدد الميزات المشتركة مع LogonTracer.
  • yamato-security/hayabusaالصورة الرمزية لـ Yamato-Security

    Yamato-Security/hayabusa

    3,027عرض على GitHub↗

    Hayabusa is a Windows event log analyzer, threat hunting tool, and forensic timeline generator. It functions as a detection engine that applies threat patterns to logs to identify suspicious behavior and security threats. The project distinguishes itself through the ability to synchronize detection rules from remote repositories and tune risk levels to prioritize critical alerts. It also provides specialized forensic capabilities, such as extracting event log data into chronological records for incident response investigations. The tool's broader capabilities include security log enrichment

    Rustattackcybersecuritydetection
    عرض على GitHub↗3,027
  • velocidex/velociraptorالصورة الرمزية لـ Velocidex

    Velocidex/velociraptor

    3,769عرض على GitHub↗

    Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and visibility tool. It provides a query engine and remote forensic collector used to hunt for indicators of compromise and perform triage across a fleet of hosts. The system is distinguished by its specialized query language for interrogating host state and parsing binary files. It features a notebook environment that combines markdown documentation with executable query cells to standardize investigative workflows and enable collaborative reporting. The platform covers a wide range o

    Godigital-forensicsendpoint-discoveryendpoint-protection
    عرض على GitHub↗3,769
  • hyperdxio/hyperdxالصورة الرمزية لـ hyperdxio

    hyperdxio/hyperdx

    9,324عرض على GitHub↗

    HyperDX is an OpenTelemetry observability platform that provides centralized log management, distributed tracing, and a self-hosted monitoring stack. It functions as a unified system for collecting, indexing, and visualizing logs, metrics, and traces from cloud and container environments. The platform distinguishes itself with specialized tooling for large language model monitoring and session replay, allowing user interactions in the browser to be linked to backend telemetry. It employs schema-less JSON parsing to index structured logs dynamically and uses source maps to resolve minified sta

    TypeScriptalertinganalyticsapm
    عرض على GitHub↗9,324
  • ahmedkhlief/apt-hunterالصورة الرمزية لـ ahmedkhlief

    ahmedkhlief/APT-Hunter

    1,408عرض على GitHub↗

    APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of windows event logs to decrease the time to uncover suspicious activity

    Python
    عرض على GitHub↗1,408
عرض جميع البدائل الـ 30 لـ LogonTracer→

الأسئلة الشائعة

ما هي وظيفة jpcertcc/logontracer؟

LogonTracer is a security auditing tool designed for logon analysis and forensic log auditing. It functions as a dockerized security auditor that utilizes a security event graph database to map account names and network addresses, allowing for the visualization of complex system compromise patterns and authentication paths.

ما هي الميزات الرئيسية لـ jpcertcc/logontracer؟

الميزات الرئيسية لـ jpcertcc/logontracer هي: Authentication Pattern Analysis, Forensic Log Auditors, Relational Visualizations, Hidden Markov Model Detection, Graph Databases, Graph-Relational Databases, User Behavior Analysis, Rule-Based Detection Engines.

ما هي البدائل مفتوحة المصدر لـ jpcertcc/logontracer؟

تشمل البدائل مفتوحة المصدر لـ jpcertcc/logontracer: yamato-security/hayabusa — Hayabusa is a Windows event log analyzer, threat hunting tool, and forensic timeline generator. It functions as a… velocidex/velociraptor — Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and… hyperdxio/hyperdx — HyperDX is an OpenTelemetry observability platform that provides centralized log management, distributed tracing, and… jpcertcc/sysmonsearch — Investigate suspicious activity by visualizing Sysmon's event log. ahmedkhlief/apt-hunter — APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT… wagga40/zircolite.