Here are
60 public repositories
matching this topic...
Generic Signature Format for SIEM Systems
Updated
Aug 11, 2020
Python
Sysmon configuration file template with default high-quality event tracing
A Threat hunter's playbook to aid the development of techniques and hypothesis for hunting campaigns.
Updated
Jun 22, 2020
Python
🛡 Block spying and tracking on Windows
A repository of sysmon configuration modules
Updated
Jul 31, 2020
PowerShell
Sources, configuration and how to detect evil things utilizing Microsoft Sysmon.
Tools to rapidly deploy a threat hunting capability on Azure Sentinel that leverages Sysmon and MITRE ATT&CK
Advanced Sysmon configuration, Installer & Auto Updater with high-quality event tracing
Updated
Feb 20, 2019
Batchfile
Investigate suspicious activity by visualizing Sysmon's event log
Updated
Apr 30, 2020
JavaScript
Test Blue Team detections without running any attack.
Open Source Endpoint Detection System for Windows
Endpoint detection & Malware analysis software
Updated
Dec 20, 2019
Python
Neutering Sysmon via driver unload
Windows Event Forwarding subscriptions, configuration files and scripts that assist with implementing ACSC's protect publication, Technical Guidance for Windows Event Logging.
Updated
Aug 6, 2019
PowerShell
Signature Engine for Windows Event Logs
Splunk App to assist Sysmon Threat Hunting
A Ruleset to enhance detection capabilities of Ossec using Sysmon
Updated
Jul 10, 2020
PowerShell
Consolidation of various resources related to Microsoft Sysmon & sample data/log
Updated
Mar 8, 2019
Python
Deploy and maintain Symon through the Splunk Deployment Sever
Updated
Jul 30, 2020
Batchfile
incident response scripts
Updated
Mar 4, 2019
PowerShell
Qt based replacement for gnome system monitor
Sysmon and wazuh integration with Sigma sysmon rules [updated]
A PowerShell script to prevent Sysmon from writing its events
Updated
Apr 23, 2020
PowerShell
Updated
Nov 4, 2018
PowerShell
Burnham Forensics ELK Deployment Files
This repository is for integrating HELK capabilities into Security Onion instances. This will be an evolving extension to both products and as such this not contributed directly to either the HELK or SecurityOnion. Please both use at your own risk and enjoy.
Updated
Apr 4, 2019
Shell
Improve this page
Add a description, image, and links to the
sysmon
topic page so that developers can more easily learn about it.
Curate this topic
Add this topic to your repo
To associate your repository with the
sysmon
topic, visit your repo's landing page and select "manage topics."
Learn more
You can’t perform that action at this time.
You signed in with another tab or window. Reload to refresh your session.
You signed out in another tab or window. Reload to refresh your session.