Credits¶
WinLogKit is built on other people's published work. This page lists what the kit is built from, what it points you to, and the tools used to make it. Licences are as published by each project; check the project itself for the current terms.
Built from¶
These sources shaped the settings table, the presets and the coverage data.
| Source | What WinLogKit takes from it | Licence |
|---|---|---|
| Yamato Security: EnableWindowsLogSettings | The core of the settings table: which event channels to enable and how large to make them, which audit subcategories to turn on, and the PowerShell logging policies. Setting values were taken in August 2026; the descriptions in the kit are its own wording. Deliberate differences are in the deviations table. | GPL-3.0 |
| Yamato Security: WELA | A second source for settings (the values its configure command uses, such as NTLM and AD CS auditing), and this site's stylesheet, adapted with WELA's MIT copyright and permission notice kept in docs/stylesheets/extra.css. |
MIT |
| Yamato Security: EventLog-Baseline-Guide | The ASD, Microsoft client and Microsoft server baselines: the ASD preset and the Refs column on the Reference page. |
MIT |
| Australian Signals Directorate (ASD) | The ASD baseline, taken from Yamato's EventLog-Baseline-Guide scripts rather than ASD's own publication. | - |
| Microsoft Learn | The documentation behind individual settings and their values: advanced audit policy, NTLM auditing, SMB signing and encryption auditing on Windows Server 2025, PowerShell logging, Windows Event Forwarding, the Intune Settings catalog and Policy CSPs. Linked where each setting is described. | Microsoft terms |
| MITRE ATT&CK (attack-stix-data) | ATT&CK Enterprise v19.2, flattened into data/attack/windows_analytics.csv for the Coverage numbers. MITRE ATT&CKĀ® is a registered trademark of The MITRE Corporation; used per the ATT&CK Terms of Use. |
ATT&CK Terms of Use |
WinLogKit is not affiliated with or endorsed by Yamato Security, the ASD, Microsoft or MITRE.
Pointed to, not included¶
The docs mention these for jobs the kit deliberately doesn't do. None of them ships with the kit or is downloaded by it.
| Project | Why it's mentioned |
|---|---|
| Yamato Security: WELA | An independent, by-hand cross-check of your audit settings (Commands). |
| Yamato Security: Hayabusa | Its eid-metrics command measures event volume per event ID during a pilot (Safety). |
| Microsoft Sysinternals: Autoruns | Inventories registry autostart entries, a gap native logging can't close (Safety). |
| Palantir: AutorunsToWinEventLog | One way to write the Autoruns inventory to an event log for collection. |
| Microsoft Security Compliance Toolkit: LGPO.exe | Applies the generated GPO pack (Deploy). |
Built with¶
| Tool | Used for |
|---|---|
| MkDocs and Material for MkDocs | This site |
| GitHub Actions | Continuous integration, the docs site and release packaging |
| PSScriptAnalyzer | Linting every script |
| Microsoft DevSkim | Security scanning, reported through GitHub code scanning |