Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Windows Event Log Observable Schema

Open
#142 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
35/100
Issue type
Feature
Clarity
Mostly clear
Activity status
Stale
Tech stack
python
Domain
security

Research direction

Start by reviewing the proposed schema changes in the linked cti-stix2-json-schemas pull request and compare them with the existing MISP object definitions. Define a Windows Event Log object distinct from the default EVTX object produced by the Python parser, then verify that the new schema and relationships match the referenced proposal.

Written by the indexing model from the issue text.

Description

As proposed by @acabrol - create a new Windows Event log (different than the default EVTX from the Python parser) object:

https://github.com/oasis-open/cti-stix2-json-schemas/pull/75/files#diff-0

Dominant language
Python
Stars
111
Forks
140
Avg merge
9h 2m
Merged PRs (30d)
5

Getting set up

This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from MISP/misp-objects

All issues in MISP/misp-objects

Similar issues

More Python issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.