# sans-blue-team/DeepBlueCLI

Repository: https://github.com/sans-blue-team/DeepBlueCLI
Canonical: https://ross.abutalabs.com/products/deepbluecli
Language: PowerShell
License: GPL-3.0
License Family: copyleft
Last push: 2023-10-14T17:06:57+00:00

## Health v2 (maintenance only)
Score: 32/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 35, longevity 100
- inputs: {"age_days": 3634, "days_push": 1054, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2428, forks 376 (observed 2026-08-28T04:06:50.932694+00:00)

## What it is
DeepBlueCLI is a PowerShell module for threat hunting that analyzes Windows Event Logs (Security, System, Application, PowerShell, Sysmon) and EVTX files for suspicious activity. It detects malicious behaviors such as user creation, password spraying, obfuscated commands, Mimikatz usage, and event log manipulation.

## Use cases
- hunt for threats in windows event logs
- analyze evtx files for malicious activity
- detect password spraying and brute force attempts
- find obfuscated powershell commands in logs
- detect mimikatz and event log tampering
- triage sysmon and security event logs during incident response

## When to choose
- you are a blue teamer or incident responder analyzing Windows event logs offline or on-host
- you want a free, scriptable alternative to commercial SIEM detection rules for common attack patterns
- you need to process EVTX files from another machine without a full SIEM

## When to avoid
- you need real-time, centralized, scalable log monitoring across many hosts
- you require alerting, dashboards, or long-term retention typical of a SIEM
- your environment is not Windows

## Facets
- artifact type: cli-tool
- maturity: maintenance
- function: security, logging, monitoring
- domain: security, developer-tools
- platform: windows, cli
- tags: threat-hunting, windows-event-logs, evtx, powershell, blue-team, sysmon, incident-response, command-line

## Member repositories
- sans-blue-team/DeepBlueCLI (main) score 32

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:06:50.932694+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T02:31:33.830154+00:00, confidence not recorded.
  - readme: https://github.com/sans-blue-team/DeepBlueCLI (fetched 2026-08-28T04:06:50.932694+00:00, sha f81164859114)
- Data as of 2026-08-30T08:39:29.467469+00:00.
