mirror of
https://github.com/Yamato-Security/WELA.git
synced 2025-12-06 09:12:46 +01:00
bf78a26d47fb52718b633dc4833ea3805555d469
About WELA
Windows Event Log Auditor
Companion Projects
- EnableWindowsLogSettings A guide for Windows Event Log settings.
- EventLog-Baseline-Guide A guide to creating a baseline of Windows Event Logs Audit Settings.
- WELA-RulesGenerator A tool for generating Sigma rules from Windows Event Log settings.
Table of Contents
- About WELA
- Companion Projects
- Table of Contents
- Screenshots
- Features
- Downloads
- Command List
- Contribution
- Bug Submission
- License
- Contributors
- Acknowledgements
Screenshots
Startup
audit-settings (stdout)
audit-settings (gui)
audit-settings (table)
audit-filesize
Features
Prerequisites
- PowerShell 5.1+
- Run PowerShell with Administrator privileges
Downloads
Please download the latest stable version of WELA from the Releases page.
Running WELA
- Unzip the release zip file.
- Open PowerShell with Administrator privileges.
./WELA.ps1 helpto run WELA.
Command List
audit-settings: Audit Windows Event Log settingsaudit-filesize: Audit Windows Event Log file sizesupdate-rules: Update Sigma contents in config directory
Command Usage
audit-settings
audit-filesize
update-rules
Other Windows Event Log Audit Related Resources
- Audit Policy Recommendations
- Windows event logging and forwarding
- A Data-Driven Approach to Windows Advanced Audit Policy – What to Enable and Why
Contribution
We would love any form of contribution. Pull requests, rule creation and sample logs are the best, but feature requests notifying us of bugs, etc... are also very welcome.
At the least, if you like our tools and resources, then please give us a star on GitHub and show your support!
Bug Submission
- Please submit any bugs you find here.
- This project is currently actively maintained, and we are happy to fix any bugs reported.
License
- WELA is released under MIT License
Contributors
- Fukusuke Takahashi (core developer)
- Zach Mathis (project leader, tool design, testing, etc...) (@yamatosecurity)
You can receive the latest news about WELA, rule updates, other Yamato Security tools, etc... by following us on Twitter at @SecurityYamato.
Languages
PowerShell
100%





