Ross ROSS = Recommend OSS · open-source software intelligence for agents

sans-blue-team/DeepBlueCLI

None observed · 2026-08-28

github.com/sans-blue-team/DeepBlueCLI · PowerShell · GPL-3.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

32/100

  • Activity 0
  • Release rhythm 35
  • Longevity 100

Flags: no_releases

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 3634
  • days_rel: n/a
  • days_push: 1054
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

2428 stars · 376 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

DeepBlueCLI is a PowerShell module for threat hunting that analyzes Windows Event Logs (Security, System, Application, PowerShell, Sysmon) and EVTX files for suspicious activity. It detects malicious behaviors such as user creation, password spraying, obfuscated commands, Mimikatz usage, and event log manipulation.

Use cases

  • hunt for threats in windows event logs
  • analyze evtx files for malicious activity
  • detect password spraying and brute force attempts
  • find obfuscated powershell commands in logs
  • detect mimikatz and event log tampering
  • triage sysmon and security event logs during incident response

When to choose

  • you are a blue teamer or incident responder analyzing Windows event logs offline or on-host
  • you want a free, scriptable alternative to commercial SIEM detection rules for common attack patterns
  • you need to process EVTX files from another machine without a full SIEM

When to avoid

  • you need real-time, centralized, scalable log monitoring across many hosts
  • you require alerting, dashboards, or long-term retention typical of a SIEM
  • your environment is not Windows

Facets

cli-tool · maturity maintenance

security logging monitoring security developer-tools windows cli threat-hunting windows-event-logs evtx powershell blue-team sysmon incident-response command-line

1 source

Member repositories

RepositoryRoleHealth v2
sans-blue-team/DeepBlueCLImain32

For agents

markdown · JSON · MCP: product_card(name="sans-blue-team/DeepBlueCLI")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem