Skip to content

This repository provide a json file for all Windows security Event IDs with lot of useful informations (Categories, GPO, Volume, Recommandations).

License

Notifications You must be signed in to change notification settings

qbrusa/Windows-Security-Event-ID-Helper

Repository files navigation

Windows Security Event ID Helper

The goal of this project is to gather all Security Event IDs in a JSON file and add connections to GPO settings. The end result allows you to filter on a each GPO setting and display all Event IDs produced by it. Additionally, tags were applied to each event ID per the advice of Microsoft or other security firms (See tags section for more informations).

Files

You can find in the root folder :

Scripts

You can divide or combine Json files using the scripts in the Scripts folder.

Tags

Below the descriptions of each tag and the source of the recommendation :

Sources to build this project

🍰 Contributing

Contributions are what make the open source community such an amazing place to be learn, inspire, and create. Any contributions you make are greatly appreciated.

License

This project is open source and available under the MIT License.

About

This repository provide a json file for all Windows security Event IDs with lot of useful informations (Categories, GPO, Volume, Recommandations).

Topics

Resources

License

Stars

Watchers

Forks