sysmon-edr

EDR solution

A PowerShell-based EDR system with Sysmon integration to detect and respond to security threats.

Sysmon EDR POC Build within Powershell to prove ability.

GitHub

218 stars
11 watching
27 forks
Language: PowerShell
last commit: over 5 years ago
Linked from 1 awesome list

edrsysmonsysmon-edr

Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
ion-storm/sysmon-configA configuration package for advanced system monitoring using Sysmon, designed to detect and alert on various threat activities and provide forensic visibility.780
0xrawsec/whidsAn open source EDR solution designed to provide real-time incident response capabilities by detecting potential security threats on Windows systems.1,157
mhaggis/sysmon-dfirA curated collection of resources and tools for learning and implementing Microsoft Sysmon for incident detection, threat hunting, and endpoint security monitoring.901
olafhartong/sysmon-modularA repository of customizable Sysmon configuration modules for security analysis and threat hunting.2,678
scarredmonk/sysmonsimulatorA utility to simulate Windows event logs for testing EDR detections and correlation rules836
swiftonsecurity/sysmon-configA template configuration file for Microsoft Sysinternals' Sysmon to monitor system changes with high-quality event tracing.4,828
gridhead/sysmonA remotely-accessible system performance monitoring and task management tool for servers and Raspberry Pi setups191
dcso/feverA fast and extensible system for processing JSON events from security monitoring tools51
securityjoes/forensicminerAutomates evidence collection and analysis from Windows machines using PowerShell.149
securityriskadvisors/talrA repository for collecting and sharing SIEM rules in STIX format for automated translation to Sigma syntax90
t0pcyber/hawkA PowerShell-based tool to gather information on O365 intrusions and potential breaches.722
yspreen/aocAn AOC CLI tool that automates puzzle solving and installation6
nshalabi/sysmontoolsUtilities for analyzing and visualizing Windows event logs from Sysmon, helping users track and monitor system activity.1,492
miladaslaner/threathuntA PowerShell repository to simulate and train threat hunting skills without malicious files.134