{"adoption": {"forks": 180, "observed_at": "2026-08-28T04:03:35.979535+00:00", "stars": 1102}, "canonical_url": "https://ross.abutalabs.com/products/microsoft-eventlog-mindmap", "card": {"archived": false, "artifact_type": "dataset", "description": "Set of Mindmaps providing a detailed overview of the different #Microsoft auditing capacities for Windows, Exchange, Azure,...", "domain": ["security", "windows", "documentation", "developer-tools"], "enriched": true, "function": ["documentation", "monitoring", "security"], "health_score": 51, "homepage": null, "language": null, "license": "BSD-2-Clause", "license_family": "permissive", "maturity": "active", "member_repos": ["mdecrevoisier/Microsoft-eventlog-mindmap"], "name": "mdecrevoisier/Microsoft-eventlog-mindmap", "platform": ["windows", "cross-platform"], "pushed_at": "2025-11-08T14:22:17+00:00", "repo": "mdecrevoisier/Microsoft-eventlog-mindmap", "stars": 1102, "tags": ["mindmap", "event-logs", "incident-response", "threat-hunting", "siem", "active-directory", "exchange", "azure", "forensics", "evtx"], "topics": ["mindmap", "evtx", "windows", "incident-response", "azure", "exchange", "active-directory"], "urls": [], "use_cases": ["plan which Windows event logs to collect into a SIEM", "find Active Directory auditing event IDs for threat hunting", "investigate Exchange email forwarding rules in BEC attacks", "build a Windows Server role auditing baseline", "reference event logs during incident response and forensics"], "what_it_is": "A collection of mindmaps (PDF/PNG/SVG) detailing the auditing capacities and event logs of Microsoft products including Windows, Windows Server roles, Active Directory, Exchange, and Azure. It serves as a reference for defenders to improve log collection and monitoring visibility.", "when_to_avoid": ["you need a tool that parses or analyzes EVTX files programmatically", "you want automated log collection rather than reference documentation", "you need auditing guidance for non-Microsoft platforms"], "when_to_choose": ["you are a defender or SOC engineer mapping Microsoft log sources", "you need a visual reference of Windows/AD/Exchange auditing capabilities", "you are setting up log collection or threat hunting coverage for Microsoft environments"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/microsoft-eventlog-mindmap", "repo": "mdecrevoisier/Microsoft-eventlog-mindmap", "role": "main", "score": 55}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:03:35.979535+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T06:45:39.031002+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "574c812eda6415b970b62417ed7fea5894b9bf657395ca648bb8c25b023dbbdd", "fetched_at": "2026-08-28T04:03:35.979535+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mdecrevoisier/Microsoft-eventlog-mindmap"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:03:35.979535+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T06:45:39.031002+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "574c812eda6415b970b62417ed7fea5894b9bf657395ca648bb8c25b023dbbdd", "fetched_at": "2026-08-28T04:03:35.979535+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mdecrevoisier/Microsoft-eventlog-mindmap"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T06:45:39.031002+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "574c812eda6415b970b62417ed7fea5894b9bf657395ca648bb8c25b023dbbdd", "fetched_at": "2026-08-28T04:03:35.979535+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mdecrevoisier/Microsoft-eventlog-mindmap"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:03:35.979535+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:03:35.979535+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:03:35.979535+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T06:45:39.031002+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "574c812eda6415b970b62417ed7fea5894b9bf657395ca648bb8c25b023dbbdd", "fetched_at": "2026-08-28T04:03:35.979535+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mdecrevoisier/Microsoft-eventlog-mindmap"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:03:35.979535+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:03:35.979535+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T06:45:39.031002+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "574c812eda6415b970b62417ed7fea5894b9bf657395ca648bb8c25b023dbbdd", "fetched_at": "2026-08-28T04:03:35.979535+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mdecrevoisier/Microsoft-eventlog-mindmap"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:03:35.979535+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:03:35.979535+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:03:35.979535+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T06:45:39.031002+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "574c812eda6415b970b62417ed7fea5894b9bf657395ca648bb8c25b023dbbdd", "fetched_at": "2026-08-28T04:03:35.979535+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mdecrevoisier/Microsoft-eventlog-mindmap"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:03:35.979535+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:03:35.979535+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T06:45:39.031002+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "574c812eda6415b970b62417ed7fea5894b9bf657395ca648bb8c25b023dbbdd", "fetched_at": "2026-08-28T04:03:35.979535+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mdecrevoisier/Microsoft-eventlog-mindmap"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T06:45:39.031002+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "574c812eda6415b970b62417ed7fea5894b9bf657395ca648bb8c25b023dbbdd", "fetched_at": "2026-08-28T04:03:35.979535+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mdecrevoisier/Microsoft-eventlog-mindmap"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T06:45:39.031002+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "574c812eda6415b970b62417ed7fea5894b9bf657395ca648bb8c25b023dbbdd", "fetched_at": "2026-08-28T04:03:35.979535+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mdecrevoisier/Microsoft-eventlog-mindmap"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T06:45:39.031002+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "574c812eda6415b970b62417ed7fea5894b9bf657395ca648bb8c25b023dbbdd", "fetched_at": "2026-08-28T04:03:35.979535+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mdecrevoisier/Microsoft-eventlog-mindmap"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 51, "longevity": 100, "rhythm": 35}, "computed_at": "2026-09-02T17:46:02.011165+00:00", "flags": ["no_releases"], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 1832, "days_push": 298, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 55, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}