Ross ROSS = Recommend OSS · open-source software intelligence for agents

ahmedkhlief/APT-Hunter

APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of windows event logs to decrease the time to uncover suspicious activity observed · 2026-08-28

github.com/ahmedkhlief/APT-Hunter · homepage · Python · GPL-3.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

23/100

  • Activity 0
  • Release rhythm 8
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 2076
  • days_rel: 664
  • days_push: 664
  • n_releases_24m: 1

Full methodology

Adoption not part of the score

1417 stars · 246 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

APT-Hunter is a Python-based threat hunting tool that analyzes Windows event logs (EVTX) to detect APT activity using predefined detection rules and statistical analysis. It produces timeline reports in formats like CSV and Excel that can be analyzed with tools such as Timeline Explorer or Timesketch.

Use cases

  • hunt for APT activity in windows event logs
  • analyze evtx files for suspicious activity
  • build a timeline of suspicious windows events for incident response
  • perform compromise assessment on collected windows logs
  • detect lateral movement and persistence in event logs
  • triage windows event logs during forensic analysis

When to choose

  • you need to quickly triage large volumes of Windows EVTX logs during incident response
  • you want a purple-team tool with predefined detection rules and statistical anomaly detection
  • you need timeline output compatible with Excel, Timeline Explorer, or Timesketch

When to avoid

  • you need real-time endpoint detection and response rather than offline log analysis
  • you are hunting on non-Windows platforms or log sources other than Windows event logs
  • you need a SIEM with continuous monitoring and alerting

Facets

cli-tool · maturity active

security logging analytics developer-tools security developer-tools windows python windows cli cross-platform threat-hunting incident-response forensics windows-event-logs evtx purple-team apt-detection dfir

1 source

Member repositories

RepositoryRoleHealth v2
ahmedkhlief/APT-Huntermain23

For agents

markdown · JSON · MCP: product_card(name="ahmedkhlief/APT-Hunter")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem