{"adoption": {"forks": 246, "observed_at": "2026-08-28T04:04:39.999651+00:00", "stars": 1417}, "canonical_url": "https://ross.abutalabs.com/products/apt-hunter", "card": {"archived": false, "artifact_type": "cli-tool", "description": "APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of windows event logs to decrease the time to uncover suspicious activity", "domain": ["security", "developer-tools", "windows"], "enriched": true, "function": ["security", "logging", "analytics", "developer-tools"], "health_score": 29, "homepage": "https://shells.systems/introducing-apt-hunter-threat-hunting-tool-via-windows-event-log/", "language": "Python", "license": "GPL-3.0", "license_family": "copyleft", "maturity": "active", "member_repos": ["ahmedkhlief/APT-Hunter"], "name": "ahmedkhlief/APT-Hunter", "platform": ["python", "windows", "cli", "cross-platform"], "pushed_at": "2024-11-07T03:50:25+00:00", "repo": "ahmedkhlief/APT-Hunter", "stars": 1417, "tags": ["threat-hunting", "incident-response", "forensics", "windows-event-logs", "evtx", "purple-team", "apt-detection", "dfir"], "topics": ["threat-hunting", "purpleteam", "python3", "windows-eventlog", "apt-attacks", "incident-response", "forensic-analysis", "windows-event-logs"], "urls": [], "use_cases": ["hunt for APT activity in windows event logs", "analyze evtx files for suspicious activity", "build a timeline of suspicious windows events for incident response", "perform compromise assessment on collected windows logs", "detect lateral movement and persistence in event logs", "triage windows event logs during forensic analysis"], "what_it_is": "APT-Hunter is a Python-based threat hunting tool that analyzes Windows event logs (EVTX) to detect APT activity using predefined detection rules and statistical analysis. It produces timeline reports in formats like CSV and Excel that can be analyzed with tools such as Timeline Explorer or Timesketch.", "when_to_avoid": ["you need real-time endpoint detection and response rather than offline log analysis", "you are hunting on non-Windows platforms or log sources other than Windows event logs", "you need a SIEM with continuous monitoring and alerting"], "when_to_choose": ["you need to quickly triage large volumes of Windows EVTX logs during incident response", "you want a purple-team tool with predefined detection rules and statistical anomaly detection", "you need timeline output compatible with Excel, Timeline Explorer, or Timesketch"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/apt-hunter", "repo": "ahmedkhlief/APT-Hunter", "role": "main", "score": 23}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:04:39.999651+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T04:38:00.086874+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "9f5af1b187fa5c6a84dc49c029275adea0984bf58435007da615b3287e75cce5", "fetched_at": "2026-08-28T04:04:39.999651+00:00", "kind": "readme", "missing": false, "url": "https://github.com/ahmedkhlief/APT-Hunter"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:04:39.999651+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T04:38:00.086874+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "9f5af1b187fa5c6a84dc49c029275adea0984bf58435007da615b3287e75cce5", "fetched_at": "2026-08-28T04:04:39.999651+00:00", "kind": "readme", "missing": false, "url": "https://github.com/ahmedkhlief/APT-Hunter"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T04:38:00.086874+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "9f5af1b187fa5c6a84dc49c029275adea0984bf58435007da615b3287e75cce5", "fetched_at": "2026-08-28T04:04:39.999651+00:00", "kind": "readme", "missing": false, "url": "https://github.com/ahmedkhlief/APT-Hunter"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:04:39.999651+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:04:39.999651+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:04:39.999651+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T04:38:00.086874+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "9f5af1b187fa5c6a84dc49c029275adea0984bf58435007da615b3287e75cce5", "fetched_at": "2026-08-28T04:04:39.999651+00:00", "kind": "readme", "missing": false, "url": "https://github.com/ahmedkhlief/APT-Hunter"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:04:39.999651+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:04:39.999651+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T04:38:00.086874+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "9f5af1b187fa5c6a84dc49c029275adea0984bf58435007da615b3287e75cce5", "fetched_at": "2026-08-28T04:04:39.999651+00:00", "kind": "readme", "missing": false, "url": "https://github.com/ahmedkhlief/APT-Hunter"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:04:39.999651+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:04:39.999651+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:04:39.999651+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T04:38:00.086874+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "9f5af1b187fa5c6a84dc49c029275adea0984bf58435007da615b3287e75cce5", "fetched_at": "2026-08-28T04:04:39.999651+00:00", "kind": "readme", "missing": false, "url": "https://github.com/ahmedkhlief/APT-Hunter"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:04:39.999651+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:04:39.999651+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T04:38:00.086874+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "9f5af1b187fa5c6a84dc49c029275adea0984bf58435007da615b3287e75cce5", "fetched_at": "2026-08-28T04:04:39.999651+00:00", "kind": "readme", "missing": false, "url": "https://github.com/ahmedkhlief/APT-Hunter"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T04:38:00.086874+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "9f5af1b187fa5c6a84dc49c029275adea0984bf58435007da615b3287e75cce5", "fetched_at": "2026-08-28T04:04:39.999651+00:00", "kind": "readme", "missing": false, "url": "https://github.com/ahmedkhlief/APT-Hunter"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T04:38:00.086874+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "9f5af1b187fa5c6a84dc49c029275adea0984bf58435007da615b3287e75cce5", "fetched_at": "2026-08-28T04:04:39.999651+00:00", "kind": "readme", "missing": false, "url": "https://github.com/ahmedkhlief/APT-Hunter"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T04:38:00.086874+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "9f5af1b187fa5c6a84dc49c029275adea0984bf58435007da615b3287e75cce5", "fetched_at": "2026-08-28T04:04:39.999651+00:00", "kind": "readme", "missing": false, "url": "https://github.com/ahmedkhlief/APT-Hunter"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 0, "longevity": 100, "rhythm": 8}, "computed_at": "2026-09-03T02:20:16.233290+00:00", "flags": [], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 2076, "days_push": 664, "days_rel": 664, "gap_med": null, "n_releases_24m": 1}, "score": 23, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}