TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Black Hills InfoSec

Wrangling Windows Event Logs with Hayabusa & SOF-ELK (Part 2)

BHIS · 2025-10-01 · Read original ↗

ATT&CK techniques detected

1 predictions
T1654Log Enumeration
83%
“wrangling windows event logs with hayabusa & sof - elk ( part 2 ) wrangling windows event logs with hayabusa & sof - elk ( part 2 ) in part 1, we used hayabusa to reduce / refine windows event logs from a single endpoint. then we ingested that output into sof - elk for further an…”

Summary

But what if we need to wrangle Windows Event Logs for more than one system? In part 2, we’ll wrangle EVTX logs at scale by incorporating Hayabusa and SOF-ELK into my rapid endpoint investigation workflow (“REIW”)! 

The post Wrangling Windows Event Logs with Hayabusa & SOF-ELK (Part 2) appeared first on Black Hills Information Security, Inc..