The invention discloses a host behavior
data analysis method and device, equipment and a storage medium. In the scheme, the behavior data of a host is collected through a preset
event monitoring module; the
event monitoring module comprises a kernel monitoring acquisition module, an ETW event acquisition module and a user mode hook event acquisition module; and performing
standardization processing on the behavior data to generate a host behavior event, sending the host behavior event to a
data analysis system, and performing analysis
processing on the host behavior event through the
data analysis system to obtain a corresponding analysis result. According to the scheme, it can be seen that in order to effectively obtain the behavior data of the host, the behavior data of the host are jointly collected through the kernel monitoring collection module, the ETW event collection module and the user mode hook event collection module in the
event monitoring module, and more comprehensive and more effective host behavior data can be obtained through the mode; therefore, the
data analysis system can timely and accurately detect the abnormal condition of the host by using the behavior data.