Collection of Event ID resources useful for Digital Forensics and Incident Response

superior_hosting_service

IR

Awesome Event IDs


In incidents, analysts are often faced with the problem of interpreting unknown event IDs. The event itself does not always contain the desired information. In addition, it is impossible to remember them all, given the huge number of event IDs and log sources.

Contents

Resources

Event ID databases

Event ID documentation

Read about the digital forensics skillset

Event ID configuration and monitoring suggestions

Event ID analysis

Contributing

This repo is dedicated to everything that has an event ID and the knowledge about it. Please ask yourself before submitting a PR if it really fits to this. In particular, please do not contribute tools, as these are already comprehensively summarized in the following great repositories.