Repository navigation
π‘οΈ Get-Windows-Security-Events-By-IP v5.0.2
π Overview
Professional PowerShell script for analyzing Windows Security Event Logs by IP addresses. Designed for system administrators, security specialists, and IT professionals who need to monitor and investigate security events related to specific IP addresses in Windows environments.
β¨ Key Features
- IP-based Security Event Analysis - Filter and analyze Windows Security logs by specific IP addresses
- Flexible Time Range Filtering - Search events by custom date ranges or last N hours/days
- Multiple Output Formats - Export results to console, CSV, JSON, or HTML formats
- CIDR Notation Support - Analyze entire network ranges using CIDR notation (e.g., 192.168.1.0/24)
- Event Type Filtering - Focus on specific event IDs (failed logons 4625, successful logons 4624, etc.)
- Detailed Event Information - Extract comprehensive event details including timestamps, computers, messages
- Remote Computer Support - Query security logs from remote Windows systems
- Administrative Privileges Required - Ensures proper access to Security event logs
π Quick Start
Basic Usage
# Analyze events for a single IP address
.\Get-SecurityEventsByIP.ps1 -IPAddress "192.168.1.100"
# Search events from the last 24 hours
.\Get-SecurityEventsByIP.ps1 -IPAddress "10.0.0.5" -LastHours 24
# Analyze network range
.\Get-SecurityEventsByIP.ps1 -IPAddress "192.168.1.0/24" -LastDays 7
# Export to CSV
.\Get-SecurityEventsByIP.ps1 -IPAddress "203.0.113.45" -OutputFormat CSV -OutputPath "C:\Reports\events.csv"
π Use Cases
- Brute Force Detection - Monitor failed logon attempts from suspicious IPs
- Incident Response - Investigate security incidents by tracking IP-related events
- Compliance Auditing - Generate reports for PCI-DSS, GDPR, and other compliance requirements
- Network Security Monitoring - Track unauthorized access attempts across your infrastructure
- User Activity Tracking - Analyze logon patterns for specific IP addresses or ranges
π§ Requirements
- Windows Server 2012+ or Windows 8.1+ with PowerShell 5.1+
- Administrative privileges to access Security event logs
- Enabled Windows Security auditing (Event IDs 4624, 4625, 4648, 4672, etc.)
π Documentation
Comprehensive documentation and advanced usage scenarios are available in the README.md
π€ Author
Pavel Deynekin
- Website: https://deynekin.com
- Email: mid1977@gmail.com
π License
This project is licensed under the MIT License - see the LICENSE file for details.
π€ Contributing
Contributions, issues, and feature requests are welcome! Feel free to check the issues page.
β Support
If you find this script useful, please consider giving it a star on GitHub!
Tags: powershell windows-security event-logs security-audit incident-response sysadmin cybersecurity monitoring ip-analysis brute-force-detection
**Full Changelog**: https://github.com/paulmann/Get-Windows-Security-Events-By-IP/commits/v5.0.2
