{"adoption": {"forks": 437, "observed_at": "2026-08-28T04:07:04.562969+00:00", "stars": 2614}, "canonical_url": "https://ross.abutalabs.com/products/evtx-attack-samples", "card": {"archived": false, "artifact_type": "dataset", "description": "Windows Events Attack Samples", "domain": ["security", "developer-tools", "operating-systems"], "enriched": true, "function": ["security", "testing", "data-generation", "logging"], "health_score": 20, "homepage": "https://github.com/sbousseaden/EVTX-ATTACK-SAMPLES", "language": "HTML", "license": "GPL-3.0", "license_family": "copyleft", "maturity": "maintenance", "member_repos": ["sbousseaden/EVTX-ATTACK-SAMPLES"], "name": "sbousseaden/EVTX-ATTACK-SAMPLES", "platform": ["windows", "python", "cli"], "pushed_at": "2023-01-24T12:02:51+00:00", "repo": "sbousseaden/EVTX-ATTACK-SAMPLES", "stars": 2614, "tags": ["evtx", "windows-event-logs", "mitre-attack", "threat-hunting", "dfir", "sysmon", "detection-engineering", "winlogbeat", "sample-data"], "topics": ["threat-hunting", "evtx", "windows-security", "mitre-attack", "detection-engineering", "dataset", "winlogbeat", "dfir"], "urls": [], "use_cases": ["test detection scripts that parse evtx files", "train on dfir and threat hunting with windows event logs", "design detection use cases from windows and sysmon logs", "replay evtx samples into an elk stack with winlogbeat", "find noisy techniques to avoid as a red teamer", "build a labeled dataset for security detection research"], "what_it_is": "A dataset of ~200 Windows EVTX event log samples mapped to MITRE ATT&CK tactics and techniques, covering attack and post-exploitation behaviors including Sysmon logs. It includes helper PowerShell scripts for parsing and replaying EVTX files through Winlogbeat into an ELK stack.", "when_to_avoid": ["you need live attack traffic or network captures rather than event logs", "you need Linux/macOS audit logs instead of Windows EVTX", "you need a continuously updated dataset - the last release was early 2023"], "when_to_choose": ["you are building or validating Windows/Sysmon detection rules", "you need realistic attack event logs for DFIR training or SIEM testing", "you want EVTX samples organized by MITRE ATT&CK technique"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/evtx-attack-samples", "repo": "sbousseaden/EVTX-ATTACK-SAMPLES", "role": "main", "score": 32}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:07:04.562969+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T02:20:35.007254+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "4ce6fb5c33a907a0325ed65dd0c5cb6adccfcbe75354b1be38570d1b11253a97", "fetched_at": "2026-08-28T04:07:04.562969+00:00", "kind": "readme", "missing": false, "url": "https://github.com/sbousseaden/EVTX-ATTACK-SAMPLES"}, {"content_hash": "ff5a27e58c43bf5c21030de25b742a16ef603677ea0423cc32905bc337789e4b", "fetched_at": "2026-08-29T10:03:25.337061+00:00", "kind": "homepage", "missing": false, "url": "https://github.com/sbousseaden/EVTX-ATTACK-SAMPLES"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:07:04.562969+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T02:20:35.007254+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "4ce6fb5c33a907a0325ed65dd0c5cb6adccfcbe75354b1be38570d1b11253a97", "fetched_at": "2026-08-28T04:07:04.562969+00:00", "kind": "readme", "missing": false, "url": "https://github.com/sbousseaden/EVTX-ATTACK-SAMPLES"}, {"content_hash": "ff5a27e58c43bf5c21030de25b742a16ef603677ea0423cc32905bc337789e4b", "fetched_at": "2026-08-29T10:03:25.337061+00:00", "kind": "homepage", "missing": false, "url": "https://github.com/sbousseaden/EVTX-ATTACK-SAMPLES"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T02:20:35.007254+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "4ce6fb5c33a907a0325ed65dd0c5cb6adccfcbe75354b1be38570d1b11253a97", "fetched_at": "2026-08-28T04:07:04.562969+00:00", "kind": "readme", "missing": false, "url": "https://github.com/sbousseaden/EVTX-ATTACK-SAMPLES"}, {"content_hash": "ff5a27e58c43bf5c21030de25b742a16ef603677ea0423cc32905bc337789e4b", "fetched_at": "2026-08-29T10:03:25.337061+00:00", "kind": "homepage", "missing": false, "url": "https://github.com/sbousseaden/EVTX-ATTACK-SAMPLES"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:07:04.562969+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:07:04.562969+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:07:04.562969+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T02:20:35.007254+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "4ce6fb5c33a907a0325ed65dd0c5cb6adccfcbe75354b1be38570d1b11253a97", "fetched_at": "2026-08-28T04:07:04.562969+00:00", "kind": "readme", "missing": false, "url": "https://github.com/sbousseaden/EVTX-ATTACK-SAMPLES"}, {"content_hash": "ff5a27e58c43bf5c21030de25b742a16ef603677ea0423cc32905bc337789e4b", "fetched_at": "2026-08-29T10:03:25.337061+00:00", "kind": "homepage", "missing": false, "url": "https://github.com/sbousseaden/EVTX-ATTACK-SAMPLES"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:07:04.562969+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:07:04.562969+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T02:20:35.007254+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "4ce6fb5c33a907a0325ed65dd0c5cb6adccfcbe75354b1be38570d1b11253a97", "fetched_at": "2026-08-28T04:07:04.562969+00:00", "kind": "readme", "missing": false, "url": "https://github.com/sbousseaden/EVTX-ATTACK-SAMPLES"}, {"content_hash": "ff5a27e58c43bf5c21030de25b742a16ef603677ea0423cc32905bc337789e4b", "fetched_at": "2026-08-29T10:03:25.337061+00:00", "kind": "homepage", "missing": false, "url": "https://github.com/sbousseaden/EVTX-ATTACK-SAMPLES"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:07:04.562969+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:07:04.562969+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:07:04.562969+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T02:20:35.007254+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "4ce6fb5c33a907a0325ed65dd0c5cb6adccfcbe75354b1be38570d1b11253a97", "fetched_at": "2026-08-28T04:07:04.562969+00:00", "kind": "readme", "missing": false, "url": "https://github.com/sbousseaden/EVTX-ATTACK-SAMPLES"}, {"content_hash": "ff5a27e58c43bf5c21030de25b742a16ef603677ea0423cc32905bc337789e4b", "fetched_at": "2026-08-29T10:03:25.337061+00:00", "kind": "homepage", "missing": false, "url": "https://github.com/sbousseaden/EVTX-ATTACK-SAMPLES"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:07:04.562969+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:07:04.562969+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T02:20:35.007254+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "4ce6fb5c33a907a0325ed65dd0c5cb6adccfcbe75354b1be38570d1b11253a97", "fetched_at": "2026-08-28T04:07:04.562969+00:00", "kind": "readme", "missing": false, "url": "https://github.com/sbousseaden/EVTX-ATTACK-SAMPLES"}, {"content_hash": "ff5a27e58c43bf5c21030de25b742a16ef603677ea0423cc32905bc337789e4b", "fetched_at": "2026-08-29T10:03:25.337061+00:00", "kind": "homepage", "missing": false, "url": "https://github.com/sbousseaden/EVTX-ATTACK-SAMPLES"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T02:20:35.007254+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "4ce6fb5c33a907a0325ed65dd0c5cb6adccfcbe75354b1be38570d1b11253a97", "fetched_at": "2026-08-28T04:07:04.562969+00:00", "kind": "readme", "missing": false, "url": "https://github.com/sbousseaden/EVTX-ATTACK-SAMPLES"}, {"content_hash": "ff5a27e58c43bf5c21030de25b742a16ef603677ea0423cc32905bc337789e4b", "fetched_at": "2026-08-29T10:03:25.337061+00:00", "kind": "homepage", "missing": false, "url": "https://github.com/sbousseaden/EVTX-ATTACK-SAMPLES"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T02:20:35.007254+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "4ce6fb5c33a907a0325ed65dd0c5cb6adccfcbe75354b1be38570d1b11253a97", "fetched_at": "2026-08-28T04:07:04.562969+00:00", "kind": "readme", "missing": false, "url": "https://github.com/sbousseaden/EVTX-ATTACK-SAMPLES"}, {"content_hash": "ff5a27e58c43bf5c21030de25b742a16ef603677ea0423cc32905bc337789e4b", "fetched_at": "2026-08-29T10:03:25.337061+00:00", "kind": "homepage", "missing": false, "url": "https://github.com/sbousseaden/EVTX-ATTACK-SAMPLES"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T02:20:35.007254+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "4ce6fb5c33a907a0325ed65dd0c5cb6adccfcbe75354b1be38570d1b11253a97", "fetched_at": "2026-08-28T04:07:04.562969+00:00", "kind": "readme", "missing": false, "url": "https://github.com/sbousseaden/EVTX-ATTACK-SAMPLES"}, {"content_hash": "ff5a27e58c43bf5c21030de25b742a16ef603677ea0423cc32905bc337789e4b", "fetched_at": "2026-08-29T10:03:25.337061+00:00", "kind": "homepage", "missing": false, "url": "https://github.com/sbousseaden/EVTX-ATTACK-SAMPLES"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 0, "longevity": 100, "rhythm": 35}, "computed_at": "2026-09-02T17:46:02.011165+00:00", "flags": ["no_releases"], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 2728, "days_push": 1317, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 32, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}