sans-blue-team/DeepBlueCLI
None observed · 2026-08-28
Health v2 · maintenance only
32/100
- Activity 0
- Release rhythm 35
- Longevity 100
Flags: no_releases
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 3634
- days_rel: n/a
- days_push: 1054
- n_releases_24m: 0
Adoption not part of the score
2428 stars · 376 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
DeepBlueCLI is a PowerShell module for threat hunting that analyzes Windows Event Logs (Security, System, Application, PowerShell, Sysmon) and EVTX files for suspicious activity. It detects malicious behaviors such as user creation, password spraying, obfuscated commands, Mimikatz usage, and event log manipulation.
Use cases
- hunt for threats in windows event logs
- analyze evtx files for malicious activity
- detect password spraying and brute force attempts
- find obfuscated powershell commands in logs
- detect mimikatz and event log tampering
- triage sysmon and security event logs during incident response
When to choose
- you are a blue teamer or incident responder analyzing Windows event logs offline or on-host
- you want a free, scriptable alternative to commercial SIEM detection rules for common attack patterns
- you need to process EVTX files from another machine without a full SIEM
When to avoid
- you need real-time, centralized, scalable log monitoring across many hosts
- you require alerting, dashboards, or long-term retention typical of a SIEM
- your environment is not Windows
Facets
cli-tool · maturity maintenance
security logging monitoring security developer-tools windows cli threat-hunting windows-event-logs evtx powershell blue-team sysmon incident-response command-line
1 source
- readme: https://github.com/sans-blue-team/DeepBlueCLI · fetched 2026-08-28 · f81164859114
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| sans-blue-team/DeepBlueCLI | main | 32 |
For agents
markdown · JSON · MCP: product_card(name="sans-blue-team/DeepBlueCLI")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem