# ahmedkhlief/APT-Hunter

APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of windows event logs to decrease the time to uncover suspicious activity

Repository: https://github.com/ahmedkhlief/APT-Hunter
Canonical: https://ross.abutalabs.com/products/apt-hunter
Homepage: https://shells.systems/introducing-apt-hunter-threat-hunting-tool-via-windows-event-log/
Language: Python
License: GPL-3.0
License Family: copyleft
Topics: threat-hunting, purpleteam, python3, windows-eventlog, apt-attacks, incident-response, forensic-analysis, windows-event-logs
Last push: 2024-11-07T03:50:25+00:00

## Health v2 (maintenance only)
Score: 23/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 0, release rhythm 8, longevity 100
- inputs: {"age_days": 2076, "days_push": 664, "days_rel": 664, "gap_med": null, "n_releases_24m": 1}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1417, forks 246 (observed 2026-08-28T04:04:39.999651+00:00)

## What it is
APT-Hunter is a Python-based threat hunting tool that analyzes Windows event logs (EVTX) to detect APT activity using predefined detection rules and statistical analysis. It produces timeline reports in formats like CSV and Excel that can be analyzed with tools such as Timeline Explorer or Timesketch.

## Use cases
- hunt for APT activity in windows event logs
- analyze evtx files for suspicious activity
- build a timeline of suspicious windows events for incident response
- perform compromise assessment on collected windows logs
- detect lateral movement and persistence in event logs
- triage windows event logs during forensic analysis

## When to choose
- you need to quickly triage large volumes of Windows EVTX logs during incident response
- you want a purple-team tool with predefined detection rules and statistical anomaly detection
- you need timeline output compatible with Excel, Timeline Explorer, or Timesketch

## When to avoid
- you need real-time endpoint detection and response rather than offline log analysis
- you are hunting on non-Windows platforms or log sources other than Windows event logs
- you need a SIEM with continuous monitoring and alerting

## Facets
- artifact type: cli-tool
- maturity: active
- function: security, logging, analytics, developer-tools
- domain: security, developer-tools, windows
- platform: python, windows, cli, cross-platform
- tags: threat-hunting, incident-response, forensics, windows-event-logs, evtx, purple-team, apt-detection, dfir

## Member repositories
- ahmedkhlief/APT-Hunter (main) score 23

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:39.999651+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:38:00.086874+00:00, confidence not recorded.
  - readme: https://github.com/ahmedkhlief/APT-Hunter (fetched 2026-08-28T04:04:39.999651+00:00, sha 9f5af1b187fa)
- Data as of 2026-08-30T08:39:29.467469+00:00.
