Skip to content

v5.0.2 - Initial Release: Windows Security Events Analyzer by IP Address

Latest

Choose a tag to compare

@paulmann paulmann released this 27 Nov 02:46
ffe4913

πŸ›‘οΈ Get-Windows-Security-Events-By-IP v5.0.2

Security Events Analyzer

πŸ“‹ Overview

Professional PowerShell script for analyzing Windows Security Event Logs by IP addresses. Designed for system administrators, security specialists, and IT professionals who need to monitor and investigate security events related to specific IP addresses in Windows environments.

✨ Key Features

  • IP-based Security Event Analysis - Filter and analyze Windows Security logs by specific IP addresses
  • Flexible Time Range Filtering - Search events by custom date ranges or last N hours/days
  • Multiple Output Formats - Export results to console, CSV, JSON, or HTML formats
  • CIDR Notation Support - Analyze entire network ranges using CIDR notation (e.g., 192.168.1.0/24)
  • Event Type Filtering - Focus on specific event IDs (failed logons 4625, successful logons 4624, etc.)
  • Detailed Event Information - Extract comprehensive event details including timestamps, computers, messages
  • Remote Computer Support - Query security logs from remote Windows systems
  • Administrative Privileges Required - Ensures proper access to Security event logs

πŸš€ Quick Start

Basic Usage



# Analyze events for a single IP address

.\Get-SecurityEventsByIP.ps1 -IPAddress "192.168.1.100"

# Search events from the last 24 hours

.\Get-SecurityEventsByIP.ps1 -IPAddress "10.0.0.5" -LastHours 24

# Analyze network range

.\Get-SecurityEventsByIP.ps1 -IPAddress "192.168.1.0/24" -LastDays 7

# Export to CSV

.\Get-SecurityEventsByIP.ps1 -IPAddress "203.0.113.45" -OutputFormat CSV -OutputPath "C:\Reports\events.csv"

πŸ“Š Use Cases

  • Brute Force Detection - Monitor failed logon attempts from suspicious IPs
  • Incident Response - Investigate security incidents by tracking IP-related events
  • Compliance Auditing - Generate reports for PCI-DSS, GDPR, and other compliance requirements
  • Network Security Monitoring - Track unauthorized access attempts across your infrastructure
  • User Activity Tracking - Analyze logon patterns for specific IP addresses or ranges

πŸ”§ Requirements

  • Windows Server 2012+ or Windows 8.1+ with PowerShell 5.1+
  • Administrative privileges to access Security event logs
  • Enabled Windows Security auditing (Event IDs 4624, 4625, 4648, 4672, etc.)

πŸ“– Documentation

Comprehensive documentation and advanced usage scenarios are available in the README.md

πŸ‘€ Author

Pavel Deynekin

πŸ“„ License

This project is licensed under the MIT License - see the LICENSE file for details.

🀝 Contributing

Contributions, issues, and feature requests are welcome! Feel free to check the issues page.

⭐ Support

If you find this script useful, please consider giving it a star on GitHub!


Tags: powershell windows-security event-logs security-audit incident-response sysadmin cybersecurity monitoring ip-analysis brute-force-detection


**Full Changelog**: https://github.com/paulmann/Get-Windows-Security-Events-By-IP/commits/v5.0.2