Epagneul - Graph Visualization For Windows Event Logs
2022-3-18 12:30:0 Author: www.kitploit.com(查看原文) 阅读量:14 收藏

Epagneul is a tool to visualize and investigate windows event logs.

Deployment

Requires docker and docker-compose to be installed.

Installing

Offline deployment

On a machine connected to internet, build an offline release:

This will create a release folder containing ready to go docker images. Copy the project to your air gapped machine then run:

This will install:

  • epagneul web UI (port 8080)
  • epagneul backend (port 8000)
  • neo4j (port 7474)

todos

  • Better SID corelations
  • add edge tips
  • Label propagation algorithm
  • PageRank
  • Add missing events IDs (sysmon)
  • Proper conversion of known SIDS / security principals, ...
  • hidden markov chains
  • Display a timeline of logons / at least a summary graph
  • check out: https://github.com/ahmedkhlief/APT-Hunter
  • Import data from ELK / splunk
  • detect communities using louvain
  • Document evtx filtering method using filter 3,4648,4624,4625,4672,4768,4769,4771,4776,4728,4732,4756

Known bugs

  • The count value on edges does not update based on the selected timeline

References:

Built With

  • Vue.js - The web framework used
  • Cytoscape.js - Library used for graph visualisation and analysis
  • d3 - Used to display the timeline
  • neo4j - Backend database
  • evtx - Parser for the windows XML EventLog format

Authors

Epagneul - Graph Visualization For Windows Event Logs Epagneul - Graph Visualization For Windows Event Logs Reviewed by Zion3R on 8:30 AM Rating: 5


文章来源: http://www.kitploit.com/2022/03/epagneul-graph-visualization-for.html
如有侵权请联系:admin#unsafe.sh