sysmon
Here are 76 public repositories matching this topic...
Automate the creation of a lab environment complete with security tooling and logging best practices
-
Updated
Mar 18, 2022 - HTML
Sysmon configuration file template with default high-quality event tracing
-
Updated
Feb 21, 2022
A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.
-
Updated
Feb 19, 2022 - Python
I was wondering the benefit of using Modular File Management vs Single Config File Management? Why do you consider it easier to use multiple files and then compile? Trying to figure out what the best case is for my use case. Thanks. #
Utilities for Sysmon
-
Updated
Aug 11, 2021
Tools to rapidly deploy a threat hunting capability on Azure Sentinel that leverages Sysmon and MITRE ATT&CK
-
Updated
Apr 27, 2021 - HCL
Sources, configuration and how to detect evil things utilizing Microsoft Sysmon.
-
Updated
Feb 7, 2020
Advanced Sysmon configuration, Installer & Auto Updater with high-quality event tracing
-
Updated
Feb 20, 2019 - Batchfile
Test Blue Team detections without running any attack.
-
Updated
Oct 11, 2021 - C#
Endpoint detection & Malware analysis software
-
Updated
Dec 20, 2019 - Python
系统监控开发套件(sysmon、promon、edr、终端安全、主机安全、零信任、上网行为管理)
-
Updated
Feb 9, 2022 - C++
Signature Engine for Windows Event Logs
-
Updated
Mar 7, 2022 - Go
Consolidation of various resources related to Microsoft Sysmon & sample data/log
-
Updated
Sep 20, 2021 - Python
Sysmon and wazuh integration with Sigma sysmon rules [updated]
-
Updated
Jul 21, 2021
Deploy and maintain Symon through the Splunk Deployment Sever
-
Updated
Jul 30, 2020 - Batchfile
Simple Windows Event Log Forwarder (SWELF). Its easy to use/simply works Log Forwarder and EVTX Parser. Almost in full release here at https://github.com/ceramicskate0/SWELF/releases/latest.
-
Updated
Jul 21, 2021 - C#
A PowerShell script to prevent Sysmon from writing its events
-
Updated
Apr 23, 2020 - PowerShell
Universal Winlogbeat configuration
-
Updated
Mar 18, 2022
System Processes Correlation Engine
-
Updated
Feb 16, 2022 - Python
Improve this page
Add a description, image, and links to the sysmon topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with the sysmon topic, visit your repo's landing page and select "manage topics."


The generic Windows audit log config lacks many event ids, e.g.