sysmon
Here are 77 public repositories matching this topic...
Sysmon configuration file template with default high-quality event tracing
-
Updated
Oct 18, 2021
Automate the creation of a lab environment complete with security tooling and logging best practices
-
Updated
Jan 24, 2022 - HTML
A Threat hunter's playbook to aid the development of techniques and hypothesis for hunting campaigns.
-
Updated
Jan 17, 2022 - Python
I was wondering the benefit of using Modular File Management vs Single Config File Management? Why do you consider it easier to use multiple files and then compile? Trying to figure out what the best case is for my use case. Thanks. #
Utilities for Sysmon
-
Updated
Aug 11, 2021
Tools to rapidly deploy a threat hunting capability on Azure Sentinel that leverages Sysmon and MITRE ATT&CK
-
Updated
Apr 27, 2021 - HCL
Sources, configuration and how to detect evil things utilizing Microsoft Sysmon.
-
Updated
Feb 7, 2020
Advanced Sysmon configuration, Installer & Auto Updater with high-quality event tracing
-
Updated
Feb 20, 2019 - Batchfile
Test Blue Team detections without running any attack.
-
Updated
Oct 11, 2021 - C#
Endpoint detection & Malware analysis software
-
Updated
Dec 20, 2019 - Python
Signature Engine for Windows Event Logs
-
Updated
Jan 4, 2022 - Go
系统监控开发套件(sysmon、promon、edr、终端安全、主机安全、零信任、上网行为管理)
-
Updated
Jan 14, 2022 - C++
Consolidation of various resources related to Microsoft Sysmon & sample data/log
-
Updated
Sep 20, 2021 - Python
Sysmon and wazuh integration with Sigma sysmon rules [updated]
-
Updated
Jul 21, 2021
Deploy and maintain Symon through the Splunk Deployment Sever
-
Updated
Jul 30, 2020 - Batchfile
Simple Windows Event Log Forwarder (SWELF). Its easy to use/simply works Log Forwarder and EVTX Parser. Almost in full release here at https://github.com/ceramicskate0/SWELF/releases/latest.
-
Updated
Jul 21, 2021 - C#
incident response scripts
-
Updated
Mar 4, 2019 - PowerShell
A PowerShell script to prevent Sysmon from writing its events
-
Updated
Apr 23, 2020 - PowerShell
System Processes Correlation Engine
-
Updated
Feb 23, 2021 - Python
Improve this page
Add a description, image, and links to the sysmon topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with the sysmon topic, visit your repo's landing page and select "manage topics."


The generic Windows audit log config lacks many event ids, e.g.