Security

Check Windows for Indicators of Compromise – Via Event Logs

Description:

Check_ioc is a script to check for various, selectable indicators of compromise on Windows systems via PowerShell and Event Logs. It was primarily written to be run on a schedule via a Nagios NCPA agent, however, it may also be run from a command-line (for incident response) as well. The script is heavily commented and very readable with numerous usage examples in the script itself. There is an accompanying SANS gold paper in the SANS Reading Room (https://www.sans.org/reading-room/) to learn more about the script and the methodology behind it. There is also an updated version of the gold paper found at the Linux Included (https://www.linuxincluded.com) website. If you have any issues or you would like to see other event IDs added, please let me know and I will make changes as necessary. Enjoy!

Current Version

1.4

Last Release Date

2016-11-06

Compatible With

  • Nagios 4.x
  • Nagios XI

Owner

License

GPL


Project Notes
Reviews (0) Add a Review
Add a Review

You must be logged in to submit a review.

Thank you for your review!

Your review has been submitted and is pending approval.

Recommend

To:


From:


Thank you for your recommendation!

Your recommendation has been sent.

Project Stats
Rating
5 (1)
Favorites
0
Views
10,344