# sbousseaden/EVTX-ATTACK-SAMPLES

Windows Events Attack Samples

Repository: https://github.com/sbousseaden/EVTX-ATTACK-SAMPLES
Canonical: https://ross.abutalabs.com/products/evtx-attack-samples
Homepage: https://github.com/sbousseaden/EVTX-ATTACK-SAMPLES
Language: HTML
License: GPL-3.0
License Family: copyleft
Topics: threat-hunting, evtx, windows-security, mitre-attack, detection-engineering, dataset, winlogbeat, dfir
Last push: 2023-01-24T12:02:51+00:00

## Health v2 (maintenance only)
Score: 32/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 35, longevity 100
- inputs: {"age_days": 2728, "days_push": 1317, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2614, forks 437 (observed 2026-08-28T04:07:04.562969+00:00)

## What it is
A dataset of ~200 Windows EVTX event log samples mapped to MITRE ATT&CK tactics and techniques, covering attack and post-exploitation behaviors including Sysmon logs. It includes helper PowerShell scripts for parsing and replaying EVTX files through Winlogbeat into an ELK stack.

## Use cases
- test detection scripts that parse evtx files
- train on dfir and threat hunting with windows event logs
- design detection use cases from windows and sysmon logs
- replay evtx samples into an elk stack with winlogbeat
- find noisy techniques to avoid as a red teamer
- build a labeled dataset for security detection research

## When to choose
- you are building or validating Windows/Sysmon detection rules
- you need realistic attack event logs for DFIR training or SIEM testing
- you want EVTX samples organized by MITRE ATT&CK technique

## When to avoid
- you need live attack traffic or network captures rather than event logs
- you need Linux/macOS audit logs instead of Windows EVTX
- you need a continuously updated dataset - the last release was early 2023

## Facets
- artifact type: dataset
- maturity: maintenance
- function: security, testing, data-generation, logging
- domain: security, developer-tools, operating-systems
- platform: windows, python, cli
- tags: evtx, windows-event-logs, mitre-attack, threat-hunting, dfir, sysmon, detection-engineering, winlogbeat, sample-data

## Member repositories
- sbousseaden/EVTX-ATTACK-SAMPLES (main) score 32

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:07:04.562969+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T02:20:35.007254+00:00, confidence not recorded.
  - readme: https://github.com/sbousseaden/EVTX-ATTACK-SAMPLES (fetched 2026-08-28T04:07:04.562969+00:00, sha 4ce6fb5c33a9)
  - homepage: https://github.com/sbousseaden/EVTX-ATTACK-SAMPLES (fetched 2026-08-29T10:03:25.337061+00:00, sha ff5a27e58c43)
- Data as of 2026-08-30T08:39:29.467469+00:00.
