Ross ROSS = Recommend OSS · open-source software intelligence for agents

JPCERTCC/LogonTracer

Investigate malicious Windows logon by visualizing and analyzing Windows event log observed · 2026-08-28

github.com/JPCERTCC/LogonTracer · Python · NOASSERTION (other) observed · 2026-08-28

Health v2 · maintenance only

80/100

  • Activity 95
  • Release rhythm 48
  • Longevity 100

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 3204
  • days_rel: 133
  • days_push: 32
  • n_releases_24m: 1

Full methodology

Adoption not part of the score

3221 stars · 488 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

LogonTracer is a self-hosted DFIR tool that visualizes Windows Active Directory logon-related event logs as a graph of hosts and accounts to investigate malicious logons. Version 2 adds AI-powered analysis with LLM agents, MITRE ATT&CK mapping, and Sigma rule scanning of EVTX files.

Use cases

  • investigate malicious windows logons
  • visualize active directory event logs as a graph
  • identify compromised accounts from event id 4624 and 4625
  • analyze lateral movement in active directory
  • scan evtx files with sigma rules
  • map logon activity to mitre att&ck tactics

When to choose

  • you need to trace which accounts and hosts were involved in suspicious logons
  • you run Windows Active Directory and need DFIR visualization of event logs
  • you want automated Sigma rule scanning of EVTX evidence
  • you want AI-assisted threat assessment of logon graphs

When to avoid

  • you need real-time SIEM alerting rather than post-incident investigation
  • you don't use Windows or Active Directory event logs
  • you want a lightweight CLI without a Neo4j graph database dependency

Facets

application · maturity active

data-visualization security analytics search-engine security analytics developer-tools python self-hosted dfir active-directory windows-event-log neo4j blueteam incident-response sigma-rules llm-analysis docker web-server

1 source

Member repositories

RepositoryRoleHealth v2
JPCERTCC/LogonTracermain80

For agents

markdown · JSON · MCP: product_card(name="JPCERTCC/LogonTracer")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem