sysmon-edr
EDR solution
A PowerShell-based EDR system with Sysmon integration to detect and respond to security threats.
Sysmon EDR POC Build within Powershell to prove ability.
218 stars
11 watching
27 forks
Language: PowerShell
last commit: almost 4 years ago
Linked from 1 awesome list
edrsysmonsysmon-edr
Related projects:
Repository | Description | Stars |
---|---|---|
| A configuration package for advanced system monitoring using Sysmon, designed to detect and alert on various threat activities and provide forensic visibility. | 780 |
| An open source EDR solution designed to provide real-time incident response capabilities by detecting potential security threats on Windows systems. | 1,157 |
| A curated collection of resources and tools for learning and implementing Microsoft Sysmon for incident detection, threat hunting, and endpoint security monitoring. | 901 |
| A repository of customizable Sysmon configuration modules for security analysis and threat hunting. | 2,678 |
| A utility to simulate Windows event logs for testing EDR detections and correlation rules | 836 |
| A template configuration file for Microsoft Sysinternals' Sysmon to monitor system changes with high-quality event tracing. | 4,828 |
| A remotely-accessible system performance monitoring and task management tool for servers and Raspberry Pi setups | 191 |
| A fast and extensible system for processing JSON events from security monitoring tools | 51 |
| Automates evidence collection and analysis from Windows machines using PowerShell. | 149 |
| A repository for collecting and sharing SIEM rules in STIX format for automated translation to Sigma syntax | 90 |
| A PowerShell-based tool to gather information on O365 intrusions and potential breaches. | 722 |
| An AOC CLI tool that automates puzzle solving and installation | 6 |
| Utilities for analyzing and visualizing Windows event logs from Sysmon, helping users track and monitor system activity. | 1,492 |
| A PowerShell repository to simulate and train threat hunting skills without malicious files. | 134 |