Skip to content

DeepBlueCLI

PowerShell module from SANS for threat hunting in Windows event logs.

When I Use It

  • Quick triage of event logs from a single host or a set of exported .evtx files, with no SIEM involved
  • A first pass that flags suspicious events (new accounts, log clearing, password spraying, suspicious command lines) before reviewing logs by hand

Installation

Common Tasks

Task Command
Process the local Security log (run as Administrator) .\DeepBlue.ps1 or .\DeepBlue.ps1 -log security
Process the local System log .\DeepBlue.ps1 -log system
Process an exported .evtx file .\DeepBlue.ps1 .\evtx\new-user-security.evtx
Process a folder of logs and save the output .\DeepBlue.ps1 .\evtx\* > output.txt

Reading the Output

  • Each finding includes a message explaining what was detected, the command line or account involved, and a decoded version of obfuscated commands where possible
  • Findings are leads, not verdicts; I confirm each one against the raw events in Windows Event Logs

Resources