sysmon-dfir

Sysmon toolkit

A curated collection of resources and tools for learning and implementing Microsoft Sysmon for incident detection, threat hunting, and endpoint security monitoring.

Sources, configuration and how to detect evil things utilizing Microsoft Sysmon.

GitHub

901 stars
114 watching
184 forks
last commit: almost 3 years ago
Linked from 1 awesome list

sysmon

Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
olafhartong/sysmon-modularA repository of customizable Sysmon configuration modules for security analysis and threat hunting.2,678
ion-storm/sysmon-configA configuration package for advanced system monitoring using Sysmon, designed to detect and alert on various threat activities and provide forensic visibility.780
nshalabi/sysmontoolsUtilities for analyzing and visualizing Windows event logs from Sysmon, helping users track and monitor system activity.1,492
swiftonsecurity/sysmon-configA template configuration file for Microsoft Sysinternals' Sysmon to monitor system changes with high-quality event tracing.4,828
ion-storm/sysmon-edrA PowerShell-based EDR system with Sysmon integration to detect and respond to security threats.218
mhaggis/hunt-detect-preventA collection of resources and tools for detecting and preventing malicious activity on Windows systems.162
trustedsec/sysmoncommunityguideA community-driven guide to configuring and using the Sysmon security monitoring tool1,156
sbousseaden/slidesCollection of resources and concepts for threat hunting and detection engineering.372
sannykim/solsecA collection of resources to study Solana smart contract security, auditing, and exploits.624
neo23x0/sysmon-configA comprehensive Sysmon configuration file template with default high-quality event tracing457
jpcertcc/sysmonsearchAnalyzes Sysmon event logs to detect suspicious activity and visualize process and network correlations.419
gridhead/sysmonA remotely-accessible system performance monitoring and task management tool for servers and Raspberry Pi setups191
scarredmonk/sysmonsimulatorA utility to simulate Windows event logs for testing EDR detections and correlation rules836
gistairc/hs-sodProvides a dataset and tools for testing salient object detection models on hyperspectral images55
dynetics/malfunctionTools for analyzing and comparing malware at a function level using fuzzy hashing algorithms192