> For the complete documentation index, see [llms.txt](https://seymour.hackstreetboys.ph/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://seymour.hackstreetboys.ph/projects/blue-team.md).

# Blue Team

- [elastalert.py](https://seymour.hackstreetboys.ph/projects/blue-team/elastalert.py.md)
- [Windows Event Fowarder](https://seymour.hackstreetboys.ph/projects/blue-team/windows-event-fowarder.md): This lays out how to create a sbuscription (both source and collector initiated) that collects selected forwarded .evtx event logs from a workstation to a domain controller.
- [Custom EVTX Logs](https://seymour.hackstreetboys.ph/projects/blue-team/custom-evtx-logs.md)
- [Flags](https://seymour.hackstreetboys.ph/projects/blue-team/flags.md)
- [Tempest](https://seymour.hackstreetboys.ph/projects/blue-team/flags/tempest.md): Flags
