Home Directory Plugins Security Check Windows for Indicators of Compromise - Via Event Logs

Search Exchange

Search All Sites

Nagios Live Webinars

Let our experts show you how Nagios can help your organization.

Contact Us

Phone: 1-888-NAGIOS-1
Email: sales@nagios.com

Login

Remember Me

Directory Tree

Check Windows for Indicators of Compromise - Via Event Logs

Current Version
1.4
Last Release Date
2016-11-06
Compatible With
  • Nagios 4.x
  • Nagios XI
Twitter Handle
@oneoffdallas
License
GPL
Hits
10297
Nagios CSP

Meet The New Nagios Core Services Platform

Built on over 25 years of monitoring experience, the Nagios Core Services Platform provides insightful monitoring dashboards, time-saving monitoring wizards, and unmatched ease of use. Use it for free indefinitely.

Monitoring Made Magically Better

  • Nagios Core on Overdrive
  • Powerful Monitoring Dashboards
  • Time-Saving Configuration Wizards
  • Open Source Powered Monitoring On Steroids
  • And So Much More!
Check_ioc is a script to check for various, selectable indicators of compromise on Windows systems via PowerShell and Event Logs. It was primarily written to be run on a schedule via a Nagios NCPA agent, however, it may also be run from a command-line (for incident response) as well. The script is heavily commented and very readable with numerous usage examples in the script itself. There is an accompanying SANS gold paper in the SANS Reading Room (https://www.sans.org/reading-room/) to learn more about the script and the methodology behind it. There is also an updated version of the gold paper found at the Linux Included (https://www.linuxincluded.com) website. If you have any issues or you would like to see other event IDs added, please let me know and I will make changes as necessary. Enjoy!