Collection of Event ID resources useful for Digital Forensics and Incident Response



Awesome Event IDs

In incidents, analysts are often faced with the problem of interpreting unknown event IDs. The event itself does not always contain the desired information. In addition, it is impossible to remember them all, given the huge number of event IDs and log sources.



Event ID databases

Event ID documentation

Read about the digital forensics skillset

Event ID configuration and monitoring suggestions

Event ID analysis


This repo is dedicated to everything that has an event ID and the knowledge about it. Please ask yourself before submitting a PR if it really fits to this. In particular, please do not contribute tools, as these are already comprehensively summarized in the following great repositories.