awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
JPCERTCC avatar

JPCERTCC/LogonTracer

0
View on GitHub↗
3,136 stars·485 forks·Python·other·10 views

LogonTracer

LogonTracer is a security auditing tool designed for logon analysis and forensic log auditing. It functions as a dockerized security auditor that utilizes a security event graph database to map account names and network addresses, allowing for the visualization of complex system compromise patterns and authentication paths.

The system features a Sigma detection engine that scans imported event logs against standardized rule sets to identify known malicious activity. It also includes an anomalous behavior detector that applies statistical analysis, graph algorithms, and hidden Markov models to identify suspicious hosts and user accounts.

The tool manages security investigations through case-isolated data storage and independent databases with per-user access controls. Its broader capabilities include security log ingestion, AI-powered threat analysis, and certificate-based network encryption for securing data during transit.

The application is provided as a container image to ensure consistent installation and runtime across different operating systems.

Features

  • Authentication Pattern Analysis - Tracks user authentication patterns within system logs to identify security risks and potential account compromises.
  • Forensic Log Auditors - Provides a dockerized security auditor for managing isolated investigation cases and performing forensic log analysis.
  • Relational Visualizations - Maps account names and network addresses into a graph to visually identify patterns of system compromise.
  • Hidden Markov Model Detection - Utilizes hidden Markov models and statistical algorithms to identify suspicious behavioral patterns across hosts and accounts.
  • Graph Databases - Utilizes a relational graph database to map accounts and network addresses for compromise pattern visualization.
  • Graph-Relational Databases - Maps account and network data into a graph database to analyze complex authentication paths.
  • User Behavior Analysis - Applies statistical analysis, graph algorithms, and Markov models to identify suspicious user and host behavior.
  • Rule-Based Detection Engines - Evaluates imported event data against standardized Sigma rule sets to identify malicious activity.
  • Behavioral Analysis Engines - Applies graph algorithms and hidden Markov models to detect anomalous security behavior among hosts and accounts.
  • User Behavior Anomaly Detection - Uses mathematical models and ranking algorithms to identify suspicious host and user account behavior.
  • Sigma Rule Matching - Evaluates event logs against standardized Sigma rule sets to identify known malicious activity.
  • Threat Relationship Visualizations - Maps account names and network addresses into a graph to visually identify system compromise patterns.
  • Event Logging - Converts raw event logs into searchable graph databases to enable relational analysis and security investigations.
  • Anomaly Detection - Uses mathematical models and ranking algorithms to identify suspicious hosts and accounts within event logs.
  • Log Ingestion - Ingests raw event data into a graph database to enable complex relational security analysis.
  • Threat - Scans imported logs against standardized Sigma rule sets to identify known malicious activity.
  • Case-Isolated Storage - Implements independent data silos for separate security investigation cases to maintain strict access control.
  • AI-Powered Threat Detection - Provides an AI-powered engine that assesses risk against known attack tactics to generate automated detection rules.
  • Investigation Case Management - Provides isolated investigation databases with per-user access controls to maintain separate security audits.
  • Event Log Importing - Converts raw log data into a searchable database using custom timezones and date filters.
  • Log Analysis Tools - Visualizes and analyzes Windows logon events.
  • Windows Artifact Analysis - Visualizes and analyzes Windows logon activity.
  • Forensics and Incident Response - Visualizes and analyzes Windows logon events.
  • Blue Team Tools - Visualizes Windows logon events.
  • Digital Forensics - Tool for visualizing and analyzing Windows logon events.
  • Incident Response Frameworks - Visualizes and analyzes Windows event logs to investigate malicious logons.
  • Security Assessment Tools - Visualization tool for investigating malicious Windows logon events.
  • Windows Artifact Analysis - Tool for visualizing and analyzing Windows logon events.

Star history

Star history chart for jpcertcc/logontracerStar history chart for jpcertcc/logontracer

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Open-source alternatives to LogonTracer

Similar open-source projects, ranked by how many features they share with LogonTracer.
  • yamato-security/hayabusaYamato-Security avatar

    Yamato-Security/hayabusa

    3,027View on GitHub↗

    Hayabusa is a Windows event log analyzer, threat hunting tool, and forensic timeline generator. It functions as a detection engine that applies threat patterns to logs to identify suspicious behavior and security threats. The project distinguishes itself through the ability to synchronize detection rules from remote repositories and tune risk levels to prioritize critical alerts. It also provides specialized forensic capabilities, such as extracting event log data into chronological records for incident response investigations. The tool's broader capabilities include security log enrichment

    Rustattackcybersecuritydetection
    View on GitHub↗3,027
  • velocidex/velociraptorVelocidex avatar

    Velocidex/velociraptor

    3,769View on GitHub↗

    Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and visibility tool. It provides a query engine and remote forensic collector used to hunt for indicators of compromise and perform triage across a fleet of hosts. The system is distinguished by its specialized query language for interrogating host state and parsing binary files. It features a notebook environment that combines markdown documentation with executable query cells to standardize investigative workflows and enable collaborative reporting. The platform covers a wide range o

    Godigital-forensicsendpoint-discoveryendpoint-protection
    View on GitHub↗3,769
  • hyperdxio/hyperdxhyperdxio avatar

    hyperdxio/hyperdx

    9,324View on GitHub↗

    HyperDX is an OpenTelemetry observability platform that provides centralized log management, distributed tracing, and a self-hosted monitoring stack. It functions as a unified system for collecting, indexing, and visualizing logs, metrics, and traces from cloud and container environments. The platform distinguishes itself with specialized tooling for large language model monitoring and session replay, allowing user interactions in the browser to be linked to backend telemetry. It employs schema-less JSON parsing to index structured logs dynamically and uses source maps to resolve minified sta

    TypeScriptalertinganalyticsapm
    View on GitHub↗9,324
  • ahmedkhlief/apt-hunterahmedkhlief avatar

    ahmedkhlief/APT-Hunter

    1,408View on GitHub↗

    APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of windows event logs to decrease the time to uncover suspicious activity

    Python
    View on GitHub↗1,408
See all 30 alternatives to LogonTracer→

Frequently asked questions

What does jpcertcc/logontracer do?

LogonTracer is a security auditing tool designed for logon analysis and forensic log auditing. It functions as a dockerized security auditor that utilizes a security event graph database to map account names and network addresses, allowing for the visualization of complex system compromise patterns and authentication paths.

What are the main features of jpcertcc/logontracer?

The main features of jpcertcc/logontracer are: Authentication Pattern Analysis, Forensic Log Auditors, Relational Visualizations, Hidden Markov Model Detection, Graph Databases, Graph-Relational Databases, User Behavior Analysis, Rule-Based Detection Engines.

What are some open-source alternatives to jpcertcc/logontracer?

Open-source alternatives to jpcertcc/logontracer include: yamato-security/hayabusa — Hayabusa is a Windows event log analyzer, threat hunting tool, and forensic timeline generator. It functions as a… velocidex/velociraptor — Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and… hyperdxio/hyperdx — HyperDX is an OpenTelemetry observability platform that provides centralized log management, distributed tracing, and… jpcertcc/sysmonsearch — Investigate suspicious activity by visualizing Sysmon's event log. ahmedkhlief/apt-hunter — APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT… wagga40/zircolite.